{"id":4599,"name":"fast-uri","ecosystem":"npm","repository_url":"https://github.com/fastify/fast-uri","issues_count":3159,"created_at":"2025-06-06T16:30:31.333Z","updated_at":"2025-06-06T16:30:31.333Z","purl":"pkg:npm/fast-uri","metadata":{"id":1707485,"name":"fast-uri","ecosystem":"npm","description":"Dependency-free RFC 3986 URI toolbox","homepage":"https://github.com/fastify/fast-uri","licenses":"BSD-3-Clause","normalized_licenses":["BSD-3-Clause"],"repository_url":"https://github.com/fastify/fast-uri","keywords_array":[],"namespace":null,"versions_count":17,"first_release_published_at":"2021-12-12T10:42:04.514Z","latest_release_published_at":"2025-01-20T20:22:54.617Z","latest_release_number":"3.0.6","last_synced_at":"2025-06-04T21:02:22.254Z","created_at":"2022-04-09T15:27:02.208Z","updated_at":"2025-06-04T21:05:40.241Z","registry_url":"https://www.npmjs.com/package/fast-uri","install_command":"npm install fast-uri","documentation_url":null,"metadata":{"funding":[{"type":"github","url":"https://github.com/sponsors/fastify"},{"type":"opencollective","url":"https://opencollective.com/fastify"}],"dist-tags":{"latest":"3.0.6"}},"repo_metadata":{"id":37012714,"uuid":"419317518","full_name":"fastify/fast-uri","owner":"fastify","description":"Dependency-free RFC 3986 URI toolbox","archived":false,"fork":false,"pushed_at":"2025-05-08T16:44:35.000Z","size":150,"stargazers_count":95,"open_issues_count":8,"forks_count":8,"subscribers_count":10,"default_branch":"main","last_synced_at":"2025-05-29T10:26:30.692Z","etag":null,"topics":["fastify-library","uri","uri-parser"],"latest_commit_sha":null,"homepage":"https://npmjs.com/package/fast-uri","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/fastify.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null},"funding":{"github":"fastify","open_collective":"fastify"}},"created_at":"2021-10-20T12:20:22.000Z","updated_at":"2025-05-08T16:44:36.000Z","dependencies_parsed_at":"2023-12-18T13:30:38.504Z","dependency_job_id":"10809c4d-2daa-42e8-aa29-d52138cc2397","html_url":"https://github.com/fastify/fast-uri","commit_stats":{"total_commits":92,"total_committers":12,"mean_commits":7.666666666666667,"dds":0.7391304347826086,"last_synced_commit":"a79e2061bc3d3e8e6d06ee091be02d66d2a7f3e2"},"previous_names":[],"tags_count":17,"template":false,"template_full_name":"fastify/skeleton","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/fastify","download_url":"https://codeload.github.com/fastify/fast-uri/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":258036953,"owners_count":22640641,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"fastify","name":"Fastify","uuid":"24939410","kind":"organization","description":"Fast and low overhead web framework, for Node.js","email":"hello@fastify.dev","website":"https://fastify.dev","location":"United States of America","twitter":"fastifyjs","company":null,"icon_url":"https://avatars.githubusercontent.com/u/24939410?v=4","repositories_count":135,"last_synced_at":"2025-06-01T04:19:11.326Z","metadata":{"has_sponsors_listing":true,"funding":{"github":"fastify","open_collective":"fastify"}},"html_url":"https://github.com/fastify","funding_links":["https://github.com/sponsors/fastify","https://opencollective.com/fastify"],"total_stars":58774,"followers":1004,"following":0,"created_at":"2022-11-02T16:30:46.974Z","updated_at":"2025-06-01T04:19:11.326Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/fastify","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/fastify/repositories"},"tags":[{"name":"v3.0.6","sha":"d40b400b0d13c3716ca5612cc61e380722f4dbd0","kind":"commit","published_at":"2025-01-20T20:22:04.000Z","download_url":"https://codeload.github.com/fastify/fast-uri/tar.gz/v3.0.6","html_url":"https://github.com/fastify/fast-uri/releases/tag/v3.0.6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v3.0.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v3.0.6/manifests"},{"name":"v3.0.5","sha":"a0451454d05f37fefd8a7a2ce53a0ee49e063789","kind":"tag","published_at":"2025-01-06T10:09:13.000Z","download_url":"https://codeload.github.com/fastify/fast-uri/tar.gz/v3.0.5","html_url":"https://github.com/fastify/fast-uri/releases/tag/v3.0.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v3.0.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v3.0.5/manifests"},{"name":"v3.0.4","sha":"4f6922a4903d410d4a3d26e846ac4262ebb0957b","kind":"tag","published_at":"2025-01-05T15:08:20.000Z","download_url":"https://codeload.github.com/fastify/fast-uri/tar.gz/v3.0.4","html_url":"https://github.com/fastify/fast-uri/releases/tag/v3.0.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v3.0.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v3.0.4/manifests"},{"name":"v3.0.3","sha":"a79e2061bc3d3e8e6d06ee091be02d66d2a7f3e2","kind":"commit","published_at":"2024-10-15T17:17:04.000Z","download_url":"https://codeload.github.com/fastify/fast-uri/tar.gz/v3.0.3","html_url":"https://github.com/fastify/fast-uri/releases/tag/v3.0.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v3.0.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v3.0.3/manifests"},{"name":"v3.0.2","sha":"a81bfb8ca4298d0b857bbab48f15c2abc6a8232f","kind":"commit","published_at":"2024-09-26T16:45:28.000Z","download_url":"https://codeload.github.com/fastify/fast-uri/tar.gz/v3.0.2","html_url":"https://github.com/fastify/fast-uri/releases/tag/v3.0.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v3.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v3.0.2/manifests"},{"name":"v3.0.1","sha":"986abce97b2303c69011da82805285a59e5967de","kind":"commit","published_at":"2024-06-27T07:37:09.000Z","download_url":"https://codeload.github.com/fastify/fast-uri/tar.gz/v3.0.1","html_url":"https://github.com/fastify/fast-uri/releases/tag/v3.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v3.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v3.0.1/manifests"},{"name":"v3.0.0","sha":"5964558737eab37fffed66987be5b6a4d550f528","kind":"commit","published_at":"2024-06-23T15:59:01.000Z","download_url":"https://codeload.github.com/fastify/fast-uri/tar.gz/v3.0.0","html_url":"https://github.com/fastify/fast-uri/releases/tag/v3.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v3.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v3.0.0/manifests"},{"name":"v2.4.0","sha":"856e241efa1e042eced4938e7e59883729178174","kind":"commit","published_at":"2024-06-10T12:35:48.000Z","download_url":"https://codeload.github.com/fastify/fast-uri/tar.gz/v2.4.0","html_url":"https://github.com/fastify/fast-uri/releases/tag/v2.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v2.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v2.4.0/manifests"},{"name":"v2.3.1","sha":"7ffca1e67b7d6d34cfbc3f91a1adc9a8c07728d5","kind":"commit","published_at":"2024-06-05T08:13:01.000Z","download_url":"https://codeload.github.com/fastify/fast-uri/tar.gz/v2.3.1","html_url":"https://github.com/fastify/fast-uri/releases/tag/v2.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v2.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v2.3.1/manifests"},{"name":"v2.3.0","sha":"388711e20a5ec7b7821c984325d7c1dd6cdf09b8","kind":"commit","published_at":"2023-10-30T19:33:00.000Z","download_url":"https://codeload.github.com/fastify/fast-uri/tar.gz/v2.3.0","html_url":"https://github.com/fastify/fast-uri/releases/tag/v2.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v2.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v2.3.0/manifests"},{"name":"v2.2.0","sha":"2394025b8ab51f6962204b2cd38e2909b5e1bbe3","kind":"commit","published_at":"2022-12-05T09:27:15.000Z","download_url":"https://codeload.github.com/fastify/fast-uri/tar.gz/v2.2.0","html_url":"https://github.com/fastify/fast-uri/releases/tag/v2.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v2.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v2.2.0/manifests"},{"name":"v2.1.0","sha":"b4bfd4ea22cd9c9b7f0dd2be1b71b31f292e69ce","kind":"commit","published_at":"2022-06-10T16:00:04.000Z","download_url":"https://codeload.github.com/fastify/fast-uri/tar.gz/v2.1.0","html_url":"https://github.com/fastify/fast-uri/releases/tag/v2.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v2.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v2.1.0/manifests"},{"name":"v2.0.0","sha":"e1387f63fd835872d4659f1ef81e4d8d546e04a5","kind":"commit","published_at":"2022-05-25T09:20:23.000Z","download_url":"https://codeload.github.com/fastify/fast-uri/tar.gz/v2.0.0","html_url":"https://github.com/fastify/fast-uri/releases/tag/v2.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v2.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v2.0.0/manifests"},{"name":"v1.0.1","sha":"171af3fd5889f38edbf43eb364f1fc180bb35313","kind":"commit","published_at":"2022-02-05T12:31:13.000Z","download_url":"https://codeload.github.com/fastify/fast-uri/tar.gz/v1.0.1","html_url":"https://github.com/fastify/fast-uri/releases/tag/v1.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v1.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v1.0.1/manifests"},{"name":"v1.0.0","sha":"c1913a5c9aa54c735b0cc08badf1d002461ebb47","kind":"commit","published_at":"2022-01-21T17:14:59.000Z","download_url":"https://codeload.github.com/fastify/fast-uri/tar.gz/v1.0.0","html_url":"https://github.com/fastify/fast-uri/releases/tag/v1.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v1.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v1.0.0/manifests"},{"name":"v0.0.2","sha":"25aa5527b617910f4bae4f41a8d6566ea23e6b8a","kind":"commit","published_at":"2022-01-21T08:57:29.000Z","download_url":"https://codeload.github.com/fastify/fast-uri/tar.gz/v0.0.2","html_url":"https://github.com/fastify/fast-uri/releases/tag/v0.0.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v0.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v0.0.2/manifests"},{"name":"v0.0.1","sha":"7ec8e5d71cc464168e2831c7fc494388d27a283b","kind":"commit","published_at":"2021-12-12T10:41:22.000Z","download_url":"https://codeload.github.com/fastify/fast-uri/tar.gz/v0.0.1","html_url":"https://github.com/fastify/fast-uri/releases/tag/v0.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v0.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fastify%2Ffast-uri/tags/v0.0.1/manifests"}]},"repo_metadata_updated_at":"2025-06-04T21:05:40.241Z","dependent_packages_count":20,"downloads":117821419,"downloads_period":"last-month","dependent_repos_count":8302,"rankings":{"downloads":0.12944102587136183,"dependent_repos_count":0.268651185770751,"dependent_packages_count":1.1886659303671867,"stargazers_count":5.358919639374289,"forks_count":8.206374254274259,"docker_downloads_count":0.14224196011498383,"average":2.5490489992954717},"purl":"pkg:npm/fast-uri","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/npm/fast-uri","docker_dependents_count":647,"docker_downloads_count":161841118,"usage_url":"https://repos.ecosyste.ms/usage/npm/fast-uri","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/npm/fast-uri/dependencies","status":null,"funding_links":["https://github.com/sponsors/fastify","https://opencollective.com/fastify"],"critical":true,"versions_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/fast-uri/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/fast-uri/version_numbers","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/fast-uri/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/fast-uri/related_packages","maintainers":[{"uuid":"matteo.collina","login":"matteo.collina","name":null,"email":"hello@matteocollina.com","url":null,"packages_count":604,"html_url":"https://www.npmjs.com/~matteo.collina","role":null,"created_at":"2022-11-12T08:07:43.091Z","updated_at":"2022-11-12T08:07:43.091Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/matteo.collina/packages"},{"uuid":"ivan-tymoshenko","login":"ivan-tymoshenko","name":null,"email":"ivan@tymoshenko.me","url":null,"packages_count":130,"html_url":"https://www.npmjs.com/~ivan-tymoshenko","role":null,"created_at":"2022-11-12T08:07:43.123Z","updated_at":"2022-11-12T08:07:43.123Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/ivan-tymoshenko/packages"},{"uuid":"delvedor","login":"delvedor","name":null,"email":"tommydelved@gmail.com","url":null,"packages_count":304,"html_url":"https://www.npmjs.com/~delvedor","role":null,"created_at":"2022-11-12T08:07:43.075Z","updated_at":"2022-11-12T08:07:43.075Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/delvedor/packages"},{"uuid":"jsumners","login":"jsumners","name":null,"email":"james.sumners@gmail.com","url":null,"packages_count":261,"html_url":"https://www.npmjs.com/~jsumners","role":null,"created_at":"2022-11-12T08:07:43.068Z","updated_at":"2022-11-12T08:07:43.068Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/jsumners/packages"},{"uuid":"simoneb","login":"simoneb","name":null,"email":"simone.busoli@gmail.com","url":null,"packages_count":303,"html_url":"https://www.npmjs.com/~simoneb","role":null,"created_at":"2022-11-12T08:07:43.109Z","updated_at":"2022-11-12T08:07:43.109Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/simoneb/packages"},{"uuid":"zekth","login":"zekth","name":null,"email":"vince.legoff@gmail.com","url":null,"packages_count":153,"html_url":"https://www.npmjs.com/~zekth","role":null,"created_at":"2022-11-12T08:07:43.172Z","updated_at":"2022-11-12T08:07:43.172Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/zekth/packages"},{"uuid":"eomm","login":"eomm","name":null,"email":"behemoth89@gmail.com","url":null,"packages_count":195,"html_url":"https://www.npmjs.com/~eomm","role":null,"created_at":"2022-11-12T08:07:43.157Z","updated_at":"2022-11-12T08:07:43.157Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/eomm/packages"},{"uuid":"climba03003","login":"climba03003","name":null,"email":"kaka@kakawebsitedemo.com","url":null,"packages_count":192,"html_url":"https://www.npmjs.com/~climba03003","role":null,"created_at":"2024-04-11T22:12:08.070Z","updated_at":"2024-04-11T22:12:08.070Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/climba03003/packages"},{"uuid":"fdawgs","login":"fdawgs","name":null,"email":"frazer.dev@icloud.com","url":null,"packages_count":83,"html_url":"https://www.npmjs.com/~fdawgs","role":null,"created_at":"2024-11-29T16:34:51.725Z","updated_at":"2024-11-29T16:34:51.725Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/fdawgs/packages"},{"uuid":"metcoder95","login":"metcoder95","name":null,"email":"me@metcoder.dev","url":null,"packages_count":163,"html_url":"https://www.npmjs.com/~metcoder95","role":null,"created_at":"2025-01-08T19:28:04.514Z","updated_at":"2025-01-08T19:28:04.514Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/metcoder95/packages"},{"uuid":"gurgunday","login":"gurgunday","name":null,"email":"hey@gurgun.day","url":null,"packages_count":161,"html_url":"https://www.npmjs.com/~gurgunday","role":null,"created_at":"2023-10-28T16:35:19.678Z","updated_at":"2023-10-28T16:35:19.678Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/gurgunday/packages"}],"registry":{"name":"npmjs.org","url":"https://registry.npmjs.org","ecosystem":"npm","default":true,"packages_count":5003427,"maintainers_count":1012257,"namespaces_count":295147,"keywords_count":699473,"github":"npm","metadata":{"funded_packages_count":150164},"icon_url":"https://github.com/npm.png","created_at":"2022-04-04T15:19:23.081Z","updated_at":"2025-06-04T06:01:37.253Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/namespaces"}},"unique_repositories_count":2744,"unique_repositories_count_past_30_days":761,"recent_issues":[{"uuid":"5441053985","node_id":"PR_kwDOR7hZzM8AAAABDWHsmw","number":1,"state":"closed","title":"build(deps): bump the npm_and_yarn group across 5 directories with 18 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-13T15:46:45.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-13T15:46:34.000Z","updated_at":"2026-09-13T15:46:47.000Z","time_to_close":11,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"npm_and_yarn","update_count":18,"packages":[{"name":"vitest","old_version":"4.0.18","new_version":"4.1.0","repository_url":"https://github.com/vitest-dev/vitest"},{"name":"yaml","old_version":"2.8.2","new_version":"2.9.1","repository_url":"https://github.com/eemeli/yaml"},{"name":"@hono/node-server","old_version":"1.19.9","new_version":"1.19.17","repository_url":"https://github.com/honojs/node-server"},{"name":"esbuild","old_version":"0.27.2","new_version":"0.28.2","repository_url":"https://github.com/evanw/esbuild"},{"name":"fast-uri","old_version":"3.1.0","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"hono","old_version":"4.12.3","new_version":"4.13.7","repository_url":"https://github.com/honojs/hono"},{"name":"ip-address","old_version":"10.0.1","new_version":"10.7.0","repository_url":"https://github.com/beaugunderson/ip-address"},{"name":"qs","old_version":"6.15.0","new_version":"6.16.0","repository_url":"https://github.com/ljharb/qs"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 8 updates in the /test/harness directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.0.18` | `4.1.0` |\n| [yaml](https://github.com/eemeli/yaml) | `2.8.2` | `2.9.1` |\n| [@hono/node-server](https://github.com/honojs/node-server) | `1.19.9` | `1.19.17` |\n| [esbuild](https://github.com/evanw/esbuild) | `0.27.2` | `0.28.2` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.0` | `3.1.7` |\n| [hono](https://github.com/honojs/hono) | `4.12.3` | `4.13.7` |\n| [ip-address](https://github.com/beaugunderson/ip-address) | `10.0.1` | `10.7.0` |\n| [qs](https://github.com/ljharb/qs) | `6.15.0` | `6.16.0` |\n\nBumps the npm_and_yarn group with 2 updates in the /scripts/docs-validation directory: [esbuild](https://github.com/evanw/esbuild) and [brace-expansion](https://github.com/juliangruber/brace-expansion).\nBumps the npm_and_yarn group with 6 updates in the /scripts/corrections directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `3.2.4` | `3.2.6` |\n| [esbuild](https://github.com/evanw/esbuild) | `0.27.4` | `0.28.2` |\n| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `7.3.1` | `7.3.6` |\n| [nanoid](https://github.com/ai/nanoid) | `3.3.11` | `3.3.19` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.8` | `8.5.28` |\n| [undici](https://github.com/nodejs/undici) | `6.24.1` | `6.28.1` |\n\nBumps the npm_and_yarn group with 5 updates in the /scripts/codegen directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [yaml](https://github.com/eemeli/yaml) | `2.8.2` | `2.9.1` |\n| [esbuild](https://github.com/evanw/esbuild) | `0.27.3` | `0.28.2` |\n| [picomatch](https://github.com/micromatch/picomatch) | `4.0.3` | `4.0.7` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.1` | `4.3.2` |\n| [lodash](https://github.com/lodash/lodash) | `4.17.23` | `4.18.1` |\n\nBumps the npm_and_yarn group with 7 updates in the /nodejs directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.0.18` | `4.1.0` |\n| [yaml](https://github.com/eemeli/yaml) | `2.8.2` | `2.9.1` |\n| [esbuild](https://github.com/evanw/esbuild) | `0.27.2` | `0.28.2` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.12` | `1.1.18` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.1` | `4.3.2` |\n| [lodash](https://github.com/lodash/lodash) | `4.17.21` | `4.18.1` |\n| [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node) | `0.16.7` | `0.16.8` |\n\n\nUpdates `vitest` from 4.0.18 to 4.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitest-dev/vitest/releases\"\u003evitest's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.1.0\u003c/h2\u003e\n\u003cp\u003eVitest 4.1 is out!\u003c/p\u003e\n\u003cp\u003eThis release page lists all changes made to the project during the 4.1 beta. To get a review of all the new features, read our \u003ca href=\"https://vitest.dev/blog/vitest-4-1\"\u003eblog post\u003c/a\u003e.\u003c/p\u003e\n\u003ch3\u003e   🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReturn a disposable from doMock()  -  by \u003ca href=\"https://github.com/kirkwaiblinger\"\u003e\u003ccode\u003e@​kirkwaiblinger\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9332\"\u003evitest-dev/vitest#9332\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/e3e659a96\"\u003e\u003c!-- raw HTML omitted --\u003e(e3e65)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded chai style assertions  -  by \u003ca href=\"https://github.com/ronnakamoto\"\u003e\u003ccode\u003e@​ronnakamoto\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/8842\"\u003evitest-dev/vitest#8842\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/841df9ac5\"\u003e\u003c!-- raw HTML omitted --\u003e(841df)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate to sinon/fake-timers v15 and add \u003ccode\u003esetTickMode\u003c/code\u003e to timer controls  -  by \u003ca href=\"https://github.com/atscott\"\u003e\u003ccode\u003e@​atscott\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/8726\"\u003evitest-dev/vitest#8726\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/4b480aaed\"\u003e\u003c!-- raw HTML omitted --\u003e(4b480)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExpose matcher types  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9448\"\u003evitest-dev/vitest#9448\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/3e4b913b1\"\u003e\u003c!-- raw HTML omitted --\u003e(3e4b9)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003etoTestSpecification\u003c/code\u003e to reported tasks  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9464\"\u003evitest-dev/vitest#9464\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/1a4705da9\"\u003e\u003c!-- raw HTML omitted --\u003e(1a470)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eShow a warning if \u003ccode\u003evi.mock\u003c/code\u003e or \u003ccode\u003evi.hoisted\u003c/code\u003e are declared outside of top level of the module  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9387\"\u003evitest-dev/vitest#9387\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/5db54a468\"\u003e\u003c!-- raw HTML omitted --\u003e(5db54)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTrack and display expectedly failed tests (.fails) in UI and CLI  -  by \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003esheremet-va\u003c/strong\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9476\"\u003evitest-dev/vitest#9476\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/77d75fd34\"\u003e\u003c!-- raw HTML omitted --\u003e(77d75)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport tags  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9478\"\u003evitest-dev/vitest#9478\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/de7c8a521\"\u003e\u003c!-- raw HTML omitted --\u003e(de7c8)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplement \u003ccode\u003earoundEach\u003c/code\u003e and \u003ccode\u003earoundAll\u003c/code\u003e hooks  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9450\"\u003evitest-dev/vitest#9450\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/2a8cb9dc2\"\u003e\u003c!-- raw HTML omitted --\u003e(2a8cb)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eStabilize experimental features  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9529\"\u003evitest-dev/vitest#9529\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/b5fd2a16a\"\u003e\u003c!-- raw HTML omitted --\u003e(b5fd2)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAccept \u003ccode\u003enew\u003c/code\u003e or \u003ccode\u003eall\u003c/code\u003e in \u003ccode\u003e--update\u003c/code\u003e flag  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9543\"\u003evitest-dev/vitest#9543\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/a5acf28a5\"\u003e\u003c!-- raw HTML omitted --\u003e(a5acf)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport \u003ccode\u003emeta\u003c/code\u003e in test options  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9535\"\u003evitest-dev/vitest#9535\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/7d622e3d1\"\u003e\u003c!-- raw HTML omitted --\u003e(7d622)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport type inference with a new \u003ccode\u003etest.extend\u003c/code\u003e syntax  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9550\"\u003evitest-dev/vitest#9550\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/e53854fcc\"\u003e\u003c!-- raw HTML omitted --\u003e(e5385)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport vite 8 beta, fix type issues in the config with different vite versions  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9587\"\u003evitest-dev/vitest#9587\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/990281dfd\"\u003e\u003c!-- raw HTML omitted --\u003e(99028)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd assertion helper to hide internal stack traces  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e and \u003cstrong\u003eClaude Opus 4.6\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9594\"\u003evitest-dev/vitest#9594\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/eeb0ae2f8\"\u003e\u003c!-- raw HTML omitted --\u003e(eeb0a)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eStore failure screenshots using artifacts API  -  by \u003ca href=\"https://github.com/macarie\"\u003e\u003ccode\u003e@​macarie\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9588\"\u003evitest-dev/vitest#9588\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/24603e3c4\"\u003e\u003c!-- raw HTML omitted --\u003e(24603)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAllow \u003ccode\u003evitest list\u003c/code\u003e to statically collect tests instead of running files to collect them  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9630\"\u003evitest-dev/vitest#9630\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/7a8e7fc20\"\u003e\u003c!-- raw HTML omitted --\u003e(7a8e7)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003e--detect-async-leaks\u003c/code\u003e  -  by \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9528\"\u003evitest-dev/vitest#9528\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/c594d4af3\"\u003e\u003c!-- raw HTML omitted --\u003e(c594d)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplement \u003ccode\u003emockThrow\u003c/code\u003e and \u003ccode\u003emockThrowOnce\u003c/code\u003e  -  by \u003ca href=\"https://github.com/thor-juhasz\"\u003e\u003ccode\u003e@​thor-juhasz\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9512\"\u003evitest-dev/vitest#9512\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/619179fb7\"\u003e\u003c!-- raw HTML omitted --\u003e(61917)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport \u003ccode\u003eupdate: \u0026quot;none\u0026quot;\u003c/code\u003e and add docs about snapshots behavior on CI  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9700\"\u003evitest-dev/vitest#9700\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/05f1854e2\"\u003e\u003c!-- raw HTML omitted --\u003e(05f18)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport playwright \u003ccode\u003elaunchOptions\u003c/code\u003e with \u003ccode\u003econnectOptions\u003c/code\u003e  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9702\"\u003evitest-dev/vitest#9702\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/f0ff1b2a0\"\u003e\u003c!-- raw HTML omitted --\u003e(f0ff1)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003epage/locator.mark\u003c/code\u003e API to enhance playwright trace  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9652\"\u003evitest-dev/vitest#9652\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/d0ee546fe\"\u003e\u003c!-- raw HTML omitted --\u003e(d0ee5)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eapi\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eSupport tests starting or ending with \u003ccode\u003etest\u003c/code\u003e in \u003ccode\u003eexperimental_parseSpecification\u003c/code\u003e  -  by \u003ca href=\"https://github.com/jgillick\"\u003e\u003ccode\u003e@​jgillick\u003c/code\u003e\u003c/a\u003e and \u003cstrong\u003eJeremy Gillick\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9235\"\u003evitest-dev/vitest#9235\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/2f367fad3\"\u003e\u003c!-- raw HTML omitted --\u003e(2f367)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd filters to \u003ccode\u003ecreateSpecification\u003c/code\u003e  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9336\"\u003evitest-dev/vitest#9336\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/c8e6c7fbf\"\u003e\u003c!-- raw HTML omitted --\u003e(c8e6c)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExpose \u003ccode\u003erunTestFiles\u003c/code\u003e as alternative to \u003ccode\u003erunTestSpecifications\u003c/code\u003e  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9443\"\u003evitest-dev/vitest#9443\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/43d761821\"\u003e\u003c!-- raw HTML omitted --\u003e(43d76)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eallowWrite\u003c/code\u003e and \u003ccode\u003eallowExec\u003c/code\u003e options to \u003ccode\u003eapi\u003c/code\u003e  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9350\"\u003evitest-dev/vitest#9350\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/20e00ef78\"\u003e\u003c!-- raw HTML omitted --\u003e(20e00)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAllow passing down test cases to \u003ccode\u003etoTestSpecification\u003c/code\u003e  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9627\"\u003evitest-dev/vitest#9627\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/6f17d5ddf\"\u003e\u003c!-- raw HTML omitted --\u003e(6f17d)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebrowser\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003euserEvent.wheel\u003c/code\u003e API  -  by \u003ca href=\"https://github.com/macarie\"\u003e\u003ccode\u003e@​macarie\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9188\"\u003evitest-dev/vitest#9188\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/660801979\"\u003e\u003c!-- raw HTML omitted --\u003e(66080)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003efilterNode\u003c/code\u003e option to prettyDOM for filtering browser assertion error output  -  by \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003esheremet-va\u003c/strong\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9475\"\u003evitest-dev/vitest#9475\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/d3220fcd8\"\u003e\u003c!-- raw HTML omitted --\u003e(d3220)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport playwright persistent context  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eClaude Opus 4.6\u003c/strong\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9229\"\u003evitest-dev/vitest#9229\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/f865d2ba4\"\u003e\u003c!-- raw HTML omitted --\u003e(f865d)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003edetailsPanelPosition\u003c/code\u003e option and button  -  by \u003ca href=\"https://github.com/shairez\"\u003e\u003ccode\u003e@​shairez\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9525\"\u003evitest-dev/vitest#9525\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/c8a31147c\"\u003e\u003c!-- raw HTML omitted --\u003e(c8a31)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse BlazeDiff instead of pixelmatch  -  by \u003ca href=\"https://github.com/macarie\"\u003e\u003ccode\u003e@​macarie\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9514\"\u003evitest-dev/vitest#9514\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/309362089\"\u003e\u003c!-- raw HTML omitted --\u003e(30936)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003efindElement\u003c/code\u003e and enable strict mode in webdriverio and preview  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9677\"\u003evitest-dev/vitest#9677\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/c3f37721c\"\u003e\u003c!-- raw HTML omitted --\u003e(c3f37)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecli\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eAdd \u003ca href=\"https://github.com/bomb\"\u003e\u003ccode\u003e@​bomb\u003c/code\u003e\u003c/a\u003e.sh/tab completions  -  by \u003ca href=\"https://github.com/AmirSa12\"\u003e\u003ccode\u003e@​AmirSa12\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/8639\"\u003evitest-dev/vitest#8639\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/200f31704\"\u003e\u003c!-- raw HTML omitted --\u003e(200f3)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecoverage\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003eignore start/stop\u003c/code\u003e ignore hints  -  by \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9204\"\u003evitest-dev/vitest#9204\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/e59c94ba6\"\u003e\u003c!-- raw HTML omitted --\u003e(e59c9)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003ecoverage.changed\u003c/code\u003e option to report only changed files  -  by \u003ca href=\"https://github.com/kykim00\"\u003e\u003ccode\u003e@​kykim00\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9521\"\u003evitest-dev/vitest#9521\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/1d9392c67\"\u003e\u003c!-- raw HTML omitted --\u003e(1d939)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexperimental\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003eonModuleRunner\u003c/code\u003e hook to \u003ccode\u003eworker.init\u003c/code\u003e  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9286\"\u003evitest-dev/vitest#9286\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/e977f3deb\"\u003e\u003c!-- raw HTML omitted --\u003e(e977f)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eOption to disable the module runner  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9210\"\u003evitest-dev/vitest#9210\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/9be6121ee\"\u003e\u003c!-- raw HTML omitted --\u003e(9be61)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/4150b913171bda3971a4a4c47c633c26d0c6ae45\"\u003e\u003ccode\u003e4150b91\u003c/code\u003e\u003c/a\u003e chore: release v4.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/1de0aa22dd6311a93546a75a3c58a6be519c1baf\"\u003e\u003ccode\u003e1de0aa2\u003c/code\u003e\u003c/a\u003e fix: correctly identify concurrent test during static analysis (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9846\"\u003e#9846\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/c3cac1c1b5a91d921942e9391fbd94841717363f\"\u003e\u003ccode\u003ec3cac1c\u003c/code\u003e\u003c/a\u003e fix: use isAgent check, not just TTY, for watch mode (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9841\"\u003e#9841\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/eab68ba2b8ea6f89717c0b885c573579659d7c3b\"\u003e\u003ccode\u003eeab68ba\u003c/code\u003e\u003c/a\u003e chore(deps): update all non-major dependencies (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9824\"\u003e#9824\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/031f02a89be34491c441b4da9c4e2bacb7db71df\"\u003e\u003ccode\u003e031f02a\u003c/code\u003e\u003c/a\u003e fix: allow catch/finally for async assertion (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9827\"\u003e#9827\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/3e9e096a231fa0ec6475da82e36cbd6fcc9bc8f9\"\u003e\u003ccode\u003e3e9e096\u003c/code\u003e\u003c/a\u003e feat(reporters): add \u003ccode\u003eagent\u003c/code\u003e reporter to reduce ai agent token usage (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9779\"\u003e#9779\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/0c2c01361a95dd26d0d7fd7bc38bcca8dbc6e5d2\"\u003e\u003ccode\u003e0c2c013\u003c/code\u003e\u003c/a\u003e chore: release v4.1.0-beta.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/8181e06e765f4d043818b244c76795022fa78ff6\"\u003e\u003ccode\u003e8181e06\u003c/code\u003e\u003c/a\u003e fix: \u003ccode\u003ehideSkippedTests\u003c/code\u003e should not hide \u003ccode\u003etest.todo\u003c/code\u003e (fix \u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9562\"\u003e#9562\u003c/a\u003e) (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9781\"\u003e#9781\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/a8216b0014b83612e40ef49f919d5293b68717b3\"\u003e\u003ccode\u003ea8216b0\u003c/code\u003e\u003c/a\u003e fix: manual and redirect mock shouldn't \u003ccode\u003eload\u003c/code\u003e or \u003ccode\u003etransform\u003c/code\u003e original module...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/689a22a1b8c79595f6f4ae82d2b43c895d7f1c50\"\u003e\u003ccode\u003e689a22a\u003c/code\u003e\u003c/a\u003e fix(browser): types of \u003ccode\u003egetCDPSession\u003c/code\u003e and \u003ccode\u003ecdp()\u003c/code\u003e (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9716\"\u003e#9716\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vitest-dev/vitest/commits/v4.1.0/packages/vitest\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `yaml` from 2.8.2 to 2.9.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/eemeli/yaml/releases\"\u003eyaml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.9.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eLimit recursive merge aliases (\u003ca href=\"https://redirect.github.com/eemeli/yaml/issues/685\"\u003e#685\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/eemeli/yaml/issues/713\"\u003e#713\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSimplify line unfolding during quoted string parsing (\u003ca href=\"https://redirect.github.com/eemeli/yaml/issues/714\"\u003e#714\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.9.0\u003c/h2\u003e\n\u003cp\u003eThe changes here are really only patches, but I'm releasing this as a minor version to note a small change to the documentation of \u003ccode\u003eparseDocument()\u003c/code\u003e and \u003ccode\u003eparseAllDocuments()\u003c/code\u003e: I've removed the claim that they'll \u0026quot;never throw\u0026quot;.\u003c/p\u003e\n\u003cp\u003eIt remains the case that practically all non-malicious inputs will be handled without emitting an error, but there is a decent chance that code paths remain where e.g. a RangeError due to call stack exhaustion can be triggered by malicious inputs. Up to now, I've considered these as security vulnerabilities, and in fact it's the only category of error for which \u003ccode\u003eyaml\u003c/code\u003e CVEs have been issued so far.\u003c/p\u003e\n\u003cp\u003eStarting from this release, I'll be considering such errors as bugs, but not vulnerabilities. I do welcome people and/or LLMs looking for them, but please report them as normal issues rather than suspected security vulnerabilities. This also applies to previously undiscovered bugs in earlier releases.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efix: Avoid calling \u003ccode\u003eArray.prototype.push.apply()\u003c/code\u003e with large source array\u003c/li\u003e\n\u003cli\u003efix(lexer): Avoid recursive calls that may exhaust the call stack\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.8.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDisable alias resolution with \u003ccode\u003emaxAliasCount:0\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/eemeli/yaml/issues/677\"\u003e#677\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHandle invalid unicode escapes (e1a1a77)\u003c/li\u003e\n\u003cli\u003eApply \u003ccode\u003eminFractionDigits\u003c/code\u003e only to decimal strings (\u003ca href=\"https://redirect.github.com/eemeli/yaml/issues/676\"\u003e#676\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.8.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003etrailingComma\u003c/code\u003e ToString option for multiline flow formatting (\u003ca href=\"https://redirect.github.com/eemeli/yaml/issues/670\"\u003e#670\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCatch stack overflow during node composition (1e84ebb)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eemeli/yaml/commit/1440ecd3d1bff41e4ac399f8f6839e810328bd16\"\u003e\u003ccode\u003e1440ecd\u003c/code\u003e\u003c/a\u003e 2.9.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eemeli/yaml/commit/c699bc575b46e1dd3c05f1ffcf3f20f14085f8d8\"\u003e\u003ccode\u003ec699bc5\u003c/code\u003e\u003c/a\u003e fix: Simplify line unfolding during quoted string parsing (\u003ca href=\"https://redirect.github.com/eemeli/yaml/issues/714\"\u003e#714\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eemeli/yaml/commit/d11ce77c1adf022e9637f4d27b90fe9c96fe9743\"\u003e\u003ccode\u003ed11ce77\u003c/code\u003e\u003c/a\u003e fix: Limit recursive merge aliases (\u003ca href=\"https://redirect.github.com/eemeli/yaml/issues/713\"\u003e#713\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eemeli/yaml/commit/c5f49f4c616ea49239f010d5c9d8023e9667438a\"\u003e\u003ccode\u003ec5f49f4\u003c/code\u003e\u003c/a\u003e chore: Update docs-slate\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eemeli/yaml/commit/ddb21b04cb889722cec8f89dc1b67f19d62d7f7d\"\u003e\u003ccode\u003eddb21b0\u003c/code\u003e\u003c/a\u003e 2.9.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eemeli/yaml/commit/167365befdae1f03d53d47a8c6533140a9d48a75\"\u003e\u003ccode\u003e167365b\u003c/code\u003e\u003c/a\u003e docs: Clarify that not all errors can be avoided\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eemeli/yaml/commit/6eca2a7087548f86c4edb6a7cf2cdfe548759f06\"\u003e\u003ccode\u003e6eca2a7\u003c/code\u003e\u003c/a\u003e fix: Avoid calling Array.prototype.push.apply() with large source array\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eemeli/yaml/commit/0543cd57fd61ea15a58e9f0ec2064b8b408177d8\"\u003e\u003ccode\u003e0543cd5\u003c/code\u003e\u003c/a\u003e fix(lexer): Avoid recursive calls that may exhaust the call stack\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eemeli/yaml/commit/ccdf7439587544f64223429498a1d9ec514eaac1\"\u003e\u003ccode\u003eccdf743\u003c/code\u003e\u003c/a\u003e 2.8.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eemeli/yaml/commit/f625789dbd971c936ff66fe5c49e368062ae7b41\"\u003e\u003ccode\u003ef625789\u003c/code\u003e\u003c/a\u003e fix: Disable alias resolution with maxAliasCount:0 (\u003ca href=\"https://redirect.github.com/eemeli/yaml/issues/677\"\u003e#677\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/eemeli/yaml/compare/v2.8.2...v2.9.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@hono/node-server` from 1.19.9 to 1.19.17\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/honojs/node-server/releases\"\u003e@​hono/node-server's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.19.17\u003c/h2\u003e\n\u003cp\u003eNo release notes provided.\u003c/p\u003e\n\u003ch2\u003ev1.19.14\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: add custom inspect to lightweight Request/Response to prevent TypeError on console.log by \u003ca href=\"https://github.com/usualoma\"\u003e\u003ccode\u003e@​usualoma\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/340\"\u003ehonojs/node-server#340\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/node-server/compare/v1.19.13...v1.19.14\"\u003ehttps://github.com/honojs/node-server/compare/v1.19.13...v1.19.14\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.19.13\u003c/h2\u003e\n\u003ch2\u003eSecurity Fix\u003c/h2\u003e\n\u003cp\u003eFixed an issue in Serve Static Middleware where inconsistent handling of repeated slashes (\u003ccode\u003e//\u003c/code\u003e) between the router and static file resolution could allow middleware to be bypassed. Users of Serve Static Middleware are encouraged to upgrade to this version.\u003c/p\u003e\n\u003cp\u003eSee GHSA-92pp-h63x-v22m for details.\u003c/p\u003e\n\u003ch2\u003ev1.19.12\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore: ignore claude setting by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/314\"\u003ehonojs/node-server#314\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: request draining for early 413 responses by \u003ca href=\"https://github.com/usualoma\"\u003e\u003ccode\u003e@​usualoma\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/329\"\u003ehonojs/node-server#329\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/node-server/compare/v1.19.11...v1.19.12\"\u003ehttps://github.com/honojs/node-server/compare/v1.19.11...v1.19.12\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.19.11\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: do not overwrite Content-Length in the fast path pattern if Content-Length already exists. by \u003ca href=\"https://github.com/usualoma\"\u003e\u003ccode\u003e@​usualoma\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/309\"\u003ehonojs/node-server#309\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/node-server/compare/v1.19.10...v1.19.11\"\u003ehttps://github.com/honojs/node-server/compare/v1.19.10...v1.19.11\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.19.10\u003c/h2\u003e\n\u003ch2\u003eSecurity Fix\u003c/h2\u003e\n\u003cp\u003eFixed an authorization bypass in Serve Static Middleware caused by inconsistent URL decoding (\u003ccode\u003e%2F\u003c/code\u003e handling) between the router and static file resolution. Users of Serve Static Middleware are encouraged to upgrade to this version.\u003c/p\u003e\n\u003cp\u003eSee GHSA-wc8c-qw6v-h7f6 for details.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/71941daede982571f18d2774951f37c475cccefc\"\u003e\u003ccode\u003e71941da\u003c/code\u003e\u003c/a\u003e 1.19.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/0208500d8f11b33dd03b50c86df8e132307adf1e\"\u003e\u003ccode\u003e0208500\u003c/code\u003e\u003c/a\u003e ci: add \u003ccode\u003estage\u003c/code\u003e option for publishing (\u003ca href=\"https://redirect.github.com/honojs/node-server/issues/386\"\u003e#386\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/cbdf713a67ef38f6a5304488e294381230a52e46\"\u003e\u003ccode\u003ecbdf713\u003c/code\u003e\u003c/a\u003e 1.19.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/86e96c24045411b3e3c4a9b61a4c1e755c398a44\"\u003e\u003ccode\u003e86e96c2\u003c/code\u003e\u003c/a\u003e ci: add an action for trusted publisher (\u003ca href=\"https://redirect.github.com/honojs/node-server/issues/385\"\u003e#385\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/99c1a1abd702132302f3da72600d383a25eba32c\"\u003e\u003ccode\u003e99c1a1a\u003c/code\u003e\u003c/a\u003e ci: run on v1.x branch pushes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/84cb2ee25f567d812b76e0cff4c36899acb157eb\"\u003e\u003ccode\u003e84cb2ee\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/b5e63a366d9b0ef62ac65fcafd7f69b383b03ff5\"\u003e\u003ccode\u003eb5e63a3\u003c/code\u003e\u003c/a\u003e 1.19.14\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/c02d7770a2d29ea473403211bef0a60639885a28\"\u003e\u003ccode\u003ec02d777\u003c/code\u003e\u003c/a\u003e fix: add custom inspect to lightweight Request/Response to prevent TypeError ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/fd64e659a34ec661fd9ccda00d1b9dff88dfaf90\"\u003e\u003ccode\u003efd64e65\u003c/code\u003e\u003c/a\u003e 1.19.13\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/025c30f55d589ddbe6048b151d77e904f67a8cc2\"\u003e\u003ccode\u003e025c30f\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/honojs/node-server/compare/v1.19.9...v1.19.17\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​hono/node-server\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@vitest/mocker` from 4.0.18 to 4.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitest-dev/vitest/releases\"\u003e@​vitest/mocker's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.1.0\u003c/h2\u003e\n\u003cp\u003eVitest 4.1 is out!\u003c/p\u003e\n\u003cp\u003eThis release page lists all changes made to the project during the 4.1 beta. To get a review of all the new features, read our \u003ca href=\"https://vitest.dev/blog/vitest-4-1\"\u003eblog post\u003c/a\u003e.\u003c/p\u003e\n\u003ch3\u003e   🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReturn a disposable from doMock()  -  by \u003ca href=\"https://github.com/kirkwaiblinger\"\u003e\u003ccode\u003e@​kirkwaiblinger\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9332\"\u003evitest-dev/vitest#9332\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/e3e659a96\"\u003e\u003c!-- raw HTML omitted --\u003e(e3e65)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded chai style assertions  -  by \u003ca href=\"https://github.com/ronnakamoto\"\u003e\u003ccode\u003e@​ronnakamoto\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/8842\"\u003evitest-dev/vitest#8842\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/841df9ac5\"\u003e\u003c!-- raw HTML omitted --\u003e(841df)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate to sinon/fake-timers v15 and add \u003ccode\u003esetTickMode\u003c/code\u003e to timer controls  -  by \u003ca href=\"https://github.com/atscott\"\u003e\u003ccode\u003e@​atscott\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/8726\"\u003evitest-dev/vitest#8726\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/4b480aaed\"\u003e\u003c!-- raw HTML omitted --\u003e(4b480)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExpose matcher types  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9448\"\u003evitest-dev/vitest#9448\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/3e4b913b1\"\u003e\u003c!-- raw HTML omitted --\u003e(3e4b9)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003etoTestSpecification\u003c/code\u003e to reported tasks  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9464\"\u003evitest-dev/vitest#9464\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/1a4705da9\"\u003e\u003c!-- raw HTML omitted --\u003e(1a470)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eShow a warning if \u003ccode\u003evi.mock\u003c/code\u003e or \u003ccode\u003evi.hoisted\u003c/code\u003e are declared outside of top level of the module  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9387\"\u003evitest-dev/vitest#9387\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/5db54a468\"\u003e\u003c!-- raw HTML omitted --\u003e(5db54)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTrack and display expectedly failed tests (.fails) in UI and CLI  -  by \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003esheremet-va\u003c/strong\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9476\"\u003evitest-dev/vitest#9476\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/77d75fd34\"\u003e\u003c!-- raw HTML omitted --\u003e(77d75)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport tags  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9478\"\u003evitest-dev/vitest#9478\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/de7c8a521\"\u003e\u003c!-- raw HTML omitted --\u003e(de7c8)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplement \u003ccode\u003earoundEach\u003c/code\u003e and \u003ccode\u003earoundAll\u003c/code\u003e hooks  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9450\"\u003evitest-dev/vitest#9450\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/2a8cb9dc2\"\u003e\u003c!-- raw HTML omitted --\u003e(2a8cb)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eStabilize experimental features  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9529\"\u003evitest-dev/vitest#9529\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/b5fd2a16a\"\u003e\u003c!-- raw HTML omitted --\u003e(b5fd2)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAccept \u003ccode\u003enew\u003c/code\u003e or \u003ccode\u003eall\u003c/code\u003e in \u003ccode\u003e--update\u003c/code\u003e flag  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9543\"\u003evitest-dev/vitest#9543\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/a5acf28a5\"\u003e\u003c!-- raw HTML omitted --\u003e(a5acf)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport \u003ccode\u003emeta\u003c/code\u003e in test options  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9535\"\u003evitest-dev/vitest#9535\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/7d622e3d1\"\u003e\u003c!-- raw HTML omitted --\u003e(7d622)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport type inference with a new \u003ccode\u003etest.extend\u003c/code\u003e syntax  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9550\"\u003evitest-dev/vitest#9550\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/e53854fcc\"\u003e\u003c!-- raw HTML omitted --\u003e(e5385)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport vite 8 beta, fix type issues in the config with different vite versions  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9587\"\u003evitest-dev/vitest#9587\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/990281dfd\"\u003e\u003c!-- raw HTML omitted --\u003e(99028)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd assertion helper to hide internal stack traces  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e and \u003cstrong\u003eClaude Opus 4.6\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9594\"\u003evitest-dev/vitest#9594\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/eeb0ae2f8\"\u003e\u003c!-- raw HTML omitted --\u003e(eeb0a)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eStore failure screenshots using artifacts API  -  by \u003ca href=\"https://github.com/macarie\"\u003e\u003ccode\u003e@​macarie\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9588\"\u003evitest-dev/vitest#9588\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/24603e3c4\"\u003e\u003c!-- raw HTML omitted --\u003e(24603)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAllow \u003ccode\u003evitest list\u003c/code\u003e to statically collect tests instead of running files to collect them  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9630\"\u003evitest-dev/vitest#9630\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/7a8e7fc20\"\u003e\u003c!-- raw HTML omitted --\u003e(7a8e7)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003e--detect-async-leaks\u003c/code\u003e  -  by \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9528\"\u003evitest-dev/vitest#9528\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/c594d4af3\"\u003e\u003c!-- raw HTML omitted --\u003e(c594d)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplement \u003ccode\u003emockThrow\u003c/code\u003e and \u003ccode\u003emockThrowOnce\u003c/code\u003e  -  by \u003ca href=\"https://github.com/thor-juhasz\"\u003e\u003ccode\u003e@​thor-juhasz\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9512\"\u003evitest-dev/vitest#9512\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/619179fb7\"\u003e\u003c!-- raw HTML omitted --\u003e(61917)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport \u003ccode\u003eupdate: \u0026quot;none\u0026quot;\u003c/code\u003e and add docs about snapshots behavior on CI  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9700\"\u003evitest-dev/vitest#9700\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/05f1854e2\"\u003e\u003c!-- raw HTML omitted --\u003e(05f18)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport playwright \u003ccode\u003elaunchOptions\u003c/code\u003e with \u003ccode\u003econnectOptions\u003c/code\u003e  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9702\"\u003evitest-dev/vitest#9702\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/f0ff1b2a0\"\u003e\u003c!-- raw HTML omitted --\u003e(f0ff1)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003epage/locator.mark\u003c/code\u003e API to enhance playwright trace  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9652\"\u003evitest-dev/vitest#9652\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/d0ee546fe\"\u003e\u003c!-- raw HTML omitted --\u003e(d0ee5)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eapi\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eSupport tests starting or ending with \u003ccode\u003etest\u003c/code\u003e in \u003ccode\u003eexperimental_parseSpecification\u003c/code\u003e  -  by \u003ca href=\"https://github.com/jgillick\"\u003e\u003ccode\u003e@​jgillick\u003c/code\u003e\u003c/a\u003e and \u003cstrong\u003eJeremy Gillick\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9235\"\u003evitest-dev/vitest#9235\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/2f367fad3\"\u003e\u003c!-- raw HTML omitted --\u003e(2f367)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd filters to \u003ccode\u003ecreateSpecification\u003c/code\u003e  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9336\"\u003evitest-dev/vitest#9336\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/c8e6c7fbf\"\u003e\u003c!-- raw HTML omitted --\u003e(c8e6c)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExpose \u003ccode\u003erunTestFiles\u003c/code\u003e as alternative to \u003ccode\u003erunTestSpecifications\u003c/code\u003e  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9443\"\u003evitest-dev/vitest#9443\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/43d761821\"\u003e\u003c!-- raw HTML omitted --\u003e(43d76)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eallowWrite\u003c/code\u003e and \u003ccode\u003eallowExec\u003c/code\u003e options to \u003ccode\u003eapi\u003c/code\u003e  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9350\"\u003evitest-dev/vitest#9350\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/20e00ef78\"\u003e\u003c!-- raw HTML omitted --\u003e(20e00)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAllow passing down test cases to \u003ccode\u003etoTestSpecification\u003c/code\u003e  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9627\"\u003evitest-dev/vitest#9627\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/6f17d5ddf\"\u003e\u003c!-- raw HTML omitted --\u003e(6f17d)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebrowser\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003euserEvent.wheel\u003c/code\u003e API  -  by \u003ca href=\"https://github.com/macarie\"\u003e\u003ccode\u003e@​macarie\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9188\"\u003evitest-dev/vitest#9188\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/660801979\"\u003e\u003c!-- raw HTML omitted --\u003e(66080)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003efilterNode\u003c/code\u003e option to prettyDOM for filtering browser assertion error output  -  by \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003esheremet-va\u003c/strong\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9475\"\u003evitest-dev/vitest#9475\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/d3220fcd8\"\u003e\u003c!-- raw HTML omitted --\u003e(d3220)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport playwright persistent context  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eClaude Opus 4.6\u003c/strong\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9229\"\u003evitest-dev/vitest#9229\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/f865d2ba4\"\u003e\u003c!-- raw HTML omitted --\u003e(f865d)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003edetailsPanelPosition\u003c/code\u003e option and button  -  by \u003ca href=\"https://github.com/shairez\"\u003e\u003ccode\u003e@​shairez\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9525\"\u003evitest-dev/vitest#9525\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/c8a31147c\"\u003e\u003c!-- raw HTML omitted --\u003e(c8a31)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse BlazeDiff instead of pixelmatch  -  by \u003ca href=\"https://github.com/macarie\"\u003e\u003ccode\u003e@​macarie\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9514\"\u003evitest-dev/vitest#9514\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/309362089\"\u003e\u003c!-- raw HTML omitted --\u003e(30936)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003efindElement\u003c/code\u003e and enable strict mode in webdriverio and preview  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9677\"\u003evitest-dev/vitest#9677\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/c3f37721c\"\u003e\u003c!-- raw HTML omitted --\u003e(c3f37)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecli\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eAdd \u003ca href=\"https://github.com/bomb\"\u003e\u003ccode\u003e@​bomb\u003c/code\u003e\u003c/a\u003e.sh/tab completions  -  by \u003ca href=\"https://github.com/AmirSa12\"\u003e\u003ccode\u003e@​AmirSa12\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/8639\"\u003evitest-dev/vitest#8639\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/200f31704\"\u003e\u003c!-- raw HTML omitted --\u003e(200f3)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecoverage\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003eignore start/stop\u003c/code\u003e ignore hints  -  by \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9204\"\u003evitest-dev/vitest#9204\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/e59c94ba6\"\u003e\u003c!-- raw HTML omitted --\u003e(e59c9)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003ecoverage.changed\u003c/code\u003e option to report only changed files  -  by \u003ca href=\"https://github.com/kykim00\"\u003e\u003ccode\u003e@​kykim00\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9521\"\u003evitest-dev/vitest#9521\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/1d9392c67\"\u003e\u003c!-- raw HTML omitted --\u003e(1d939)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexperimental\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003eonModuleRunner\u003c/code\u003e hook to \u003ccode\u003eworker.init\u003c/code\u003e  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9286\"\u003evitest-dev/vitest#9286\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/e977f3deb\"\u003e\u003c!-- raw HTML omitted --\u003e(e977f)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eOption to disable the module runner  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9210\"\u003evitest-dev/vitest#9210\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/9be6121ee\"\u003e\u003c!-- raw HTML omitted --\u003e(9be61)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/4150b913171bda3971a4a4c47c633c26d0c6ae45\"\u003e\u003ccode\u003e4150b91\u003c/code\u003e\u003c/a\u003e chore: release v4.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/36f9a81a2b6406bac601f42019215a4637cad943\"\u003e\u003ccode\u003e36f9a81\u003c/code\u003e\u003c/a\u003e fix(mocker): update vite's peer dependency range (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/mocker/issues/9808\"\u003e#9808\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/0c2c01361a95dd26d0d7fd7bc38bcca8dbc6e5d2\"\u003e\u003ccode\u003e0c2c013\u003c/code\u003e\u003c/a\u003e chore: release v4.1.0-beta.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/94eb73b519cb5ecd06c9aa178a3f0e161c96236f\"\u003e\u003ccode\u003e94eb73b\u003c/code\u003e\u003c/a\u003e chore(deps): update eslint packages (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/mocker/issues/9615\"\u003e#9615\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/8c96bb0023f551c78a81461d5c9aaedee634fe99\"\u003e\u003ccode\u003e8c96bb0\u003c/code\u003e\u003c/a\u003e refator: update links to npmx (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/mocker/issues/9783\"\u003e#9783\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/aaf775896af2356f5c710c54ec6e624fe8e4eef9\"\u003e\u003ccode\u003eaaf7758\u003c/code\u003e\u003c/a\u003e chore: standardize packages README (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/mocker/issues/9776\"\u003e#9776\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/79672d7e1586981f04dce7619cbd8c3a31eff284\"\u003e\u003ccode\u003e79672d7\u003c/code\u003e\u003c/a\u003e chore: release v4.1.0-beta.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/84c69497ff7841c9ddeeaf1641e17a85b5cf4c6a\"\u003e\u003ccode\u003e84c6949\u003c/code\u003e\u003c/a\u003e fix: make \u003ccode\u003emockObject\u003c/code\u003e change backwards compatible (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/mocker/issues/9744\"\u003e#9744\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/695a86b41ef01c60f3574ab1bbddfe38c74c402b\"\u003e\u003ccode\u003e695a86b\u003c/code\u003e\u003c/a\u003e fix: recursively autospy module object (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/mocker/issues/9687\"\u003e#9687\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/1d9e3b3315024e3443a5a72fa8387508f4223528\"\u003e\u003ccode\u003e1d9e3b3\u003c/code\u003e\u003c/a\u003e chore: release v4.1.0-beta.4\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vitest-dev/vitest/commits/v4.1.0/packages/mocker\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `esbuild` from 0.27.2 to 0.28.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/evanw/esbuild/releases\"\u003eesbuild's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.28.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix tree shaking bug due to TypeScript import alias (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4507\"\u003e#4507\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific \u003ccode\u003eimport\u003c/code\u003e assignment and looks something like this:\u003c/p\u003e\n\u003cpre lang=\"ts\"\u003e\u003ccode\u003eimport Base from './dep.js';\r\nimport Alias = Base.SomeType;\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix CSS minification bug involving \u003ccode\u003e\u0026amp;\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4497\"\u003e#4497\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug where esbuild's CSS minifier incorrectly removed a \u003ccode\u003e\u0026amp;\u003c/code\u003e when it was unsafe to do so. Here is an example:\u003c/p\u003e\n\u003cpre lang=\"css\"\u003e\u003ccode\u003e/* Original code */\r\n.a .b {\r\n  \u0026amp; .b:not(\u0026amp; .c) {\r\n    color: red;\r\n  }\r\n}\r\n\u003cp\u003e/* Old output (with --minify) */\u003cbr /\u003e\n.a .b{.b:not(\u0026amp; .c){color:red}}\u003c/p\u003e\n\u003cp\u003e/* New output (with --minify) */\u003cbr /\u003e\n.a .b{\u0026amp; .b:not(\u0026amp; .c){color:red}}\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eThis should match \u003ccode\u003e\u0026lt;span class=\u0026quot;a\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;yes\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u003c/code\u003e but not \u003ccode\u003e\u0026lt;span class=\u0026quot;a\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;no\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u003c/code\u003e. The old output incorrectly matched both.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAvoid overwriting input files without \u003ccode\u003e--allow-overwrite\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4484\"\u003e#4484\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eFor example: \u003ccode\u003eesbuild input.js --outfile=input.js\u003c/code\u003e tells esbuild to overwrite \u003ccode\u003einput.js\u003c/code\u003e with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.\u003c/p\u003e\n\u003cp\u003eThis release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless \u003ccode\u003e--allow-overwrite\u003c/code\u003e is explicitly present. This is done by not writing out any files when a build error is encountered.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix incorrect code generated when using top-level await (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4498\"\u003e#4498\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003ePreviously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing \u003ccode\u003easync\u003c/code\u003e on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an \u003ccode\u003easync\u003c/code\u003e module wrapper.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix a minification bug with lowered logical assignment operators (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4508\"\u003e#4508\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Original code\r\nfunction foo() {\r\n  let x\r\n  bar(x ||= {})\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/evanw/esbuild/blob/main/CHANGELOG-2025.md\"\u003eesbuild's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog: 2025\u003c/h1\u003e\n\u003cp\u003eThis changelog documents all esbuild versions published in the year 2025 (versions 0.25.0 through 0.27.2).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/609683d892977362a0f99026cb74b96263d728a9\"\u003e\u003ccode\u003e609683d\u003c/code\u003e\u003c/a\u003e publish 0.28.2 to npm\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/11b1fe48df6859393d9469f323b5ebd17baaf989\"\u003e\u003ccode\u003e11b1fe4\u003c/code\u003e\u003c/a\u003e add to release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/ab50d91559a27e54cd0a27a403389130ea10d97d\"\u003e\u003ccode\u003eab50d91\u003c/code\u003e\u003c/a\u003e css: fix green/blue channel swap in oklch gamut mapping (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4488\"\u003e#4488\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/04627b6cf99b4a7491bebb0268173a7c77a85030\"\u003e\u003ccode\u003e04627b6\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4498\"\u003e#4498\u003c/a\u003e: \u003ccode\u003easync\u003c/code\u003e TLA checks need a worklist\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/5c15177a308c7224604058a769c4abf0a66b0a36\"\u003e\u003ccode\u003e5c15177\u003c/code\u003e\u003c/a\u003e disable \u003ccode\u003egopls\u003c/code\u003e in the \u003ccode\u003ego\u003c/code\u003e folder\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/fc2ee9babc5a2e8ea7ec7c10dd5850b71f7cec7e\"\u003e\u003ccode\u003efc2ee9b\u003c/code\u003e\u003c/a\u003e css: adjust parser to allow \u003ccode\u003e--foo: {...}\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/209db54371e62ad1c50e12e56bb93c74c53b0408\"\u003e\u003ccode\u003e209db54\u003c/code\u003e\u003c/a\u003e release notes for css nesting bugfix\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/c625d31bf08a0647ec724bf76c7115f7aec55971\"\u003e\u003ccode\u003ec625d31\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4497\"\u003e#4497\u003c/a\u003e: preserve nested ampersands during minification (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4500\"\u003e#4500\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/34474e278528a60f58c959c0f422d2bfa6f6886d\"\u003e\u003ccode\u003e34474e2\u003c/code\u003e\u003c/a\u003e better isolation of current part in js parser\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/07f6e8c50677e0b41e5ed726c08b0ea200b14e5b\"\u003e\u003ccode\u003e07f6e8c\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4507\"\u003e#4507\u003c/a\u003e: \u003ccode\u003eimport\u003c/code\u003e assignment tree-shaking bug\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/evanw/esbuild/compare/v0.27.2...v0.28.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-uri` from 3.1.0 to 3.1.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.0...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `hono` from 4.12.3 to 4.13.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/honojs/hono/releases\"\u003ehono's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.13.7\u003c/h2\u003e\n\u003ch2\u003eSecurity fixes\u003c/h2\u003e\n\u003cp\u003eThis release includes a fix for the following security issue:\u003c/p\u003e\n\u003ch3\u003e\u003ccode\u003ehono/jsx\u003c/code\u003e renders plain strings unescaped in boundary components, leading to XSS\u003c/h3\u003e\n\u003cp\u003eAffects: \u003ccode\u003eSuspense\u003c/code\u003e, \u003ccode\u003eErrorBoundary\u003c/code\u003e, and \u003ccode\u003eContext.Provider\u003c/code\u003e in \u003ccode\u003ehono/jsx\u003c/code\u003e, and \u003ccode\u003erenderToString()\u003c/code\u003e / \u003ccode\u003erenderToReadableStream()\u003c/code\u003e in \u003ccode\u003ehono/jsx/dom/server\u003c/code\u003e. Fixes missing HTML escaping for a plain string placed directly as a child or \u003ccode\u003efallback\u003c/code\u003e of these components, or as the root value of the server rendering functions, so untrusted strings could be emitted as markup. GHSA-hxh3-vqpv-xpqv\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003eUsers who render untrusted strings inside \u003ccode\u003eSuspense\u003c/code\u003e, \u003ccode\u003eErrorBoundary\u003c/code\u003e, or \u003ccode\u003eContext.Provider\u003c/code\u003e, or pass them directly to \u003ccode\u003ehono/jsx/dom/server\u003c/code\u003e, are strongly encouraged to upgrade to this version.\u003c/p\u003e\n\u003ch2\u003ev4.13.6\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(client): keep a param value of \u0026quot;index\u0026quot; in $url() and $path() in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5297\"\u003ehonojs/hono#5297\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(client): normalize root WebSocket URLs in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5291\"\u003ehonojs/hono#5291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(types): allow symbol keys in Context\u003c!-- raw HTML omitted --\u003e get and set fallbacks in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5300\"\u003ehonojs/hono#5300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump \u003ccode\u003eeditorconfig-checker\u003c/code\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5336\"\u003ehonojs/hono#5336\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor(on-handler): use forEach for consistent handler iteration in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5326\"\u003ehonojs/hono#5326\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/hono/compare/v4.13.5...v4.13.6\"\u003ehttps://github.com/honojs/hono/compare/v4.13.5...v4.13.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.13.5\u003c/h2\u003e\n\u003ch2\u003eSecurity fixes\u003c/h2\u003e\n\u003cp\u003eThis release includes fixes for the following security issues:\u003c/p\u003e\n\u003ch3\u003eQuery parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials\u003c/h3\u003e\n\u003cp\u003eAffects: Cache Middleware and applications behind a proxy, WAF, or logging layer that inspects query strings. Fixes query parsing that did not stop at the URL fragment, so a \u003ccode\u003e?\u003c/code\u003e after a \u003ccode\u003e#\u003c/code\u003e was treated as the start of a query string and the application could read parameters that the other component never saw. GHSA-crvj-82cr-hjcx\u003c/p\u003e\n\u003ch3\u003eIncomplete fix for CVE-2026-39408: \u003ccode\u003etoSSG()\u003c/code\u003e still writes files outside the output directory\u003c/h3\u003e\n\u003cp\u003eAffects: \u003ccode\u003etoSSG()\u003c/code\u003e for Static Site Generation. Fixes a path normalization gap where consecutive parent-directory segments in \u003ccode\u003essgParams\u003c/code\u003e values were not fully collapsed, bypassing the containment check added in 4.12.12. GHSA-gqvv-2mrq-wpjv\u003c/p\u003e\n\u003ch3\u003eUnbounded dot-notation nesting in \u003ccode\u003eparseBody()\u003c/code\u003e can cause memory exhaustion\u003c/h3\u003e\n\u003cp\u003eAffects: \u003ccode\u003eparseBody()\u003c/code\u003e when dot-notation parsing is enabled. Fixes unbounded expansion of dot-separated field names, where a small request body could allocate a disproportionately large object graph and concurrent requests could exhaust the heap. GHSA-g6gw-c38x-mqfc\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003eUsers who use Cache Middleware, deploy behind a proxy or WAF that inspects query strings, use Static Site Generation, or use \u003ccode\u003eparseBody({ dot: true })\u003c/code\u003e are strongly encouraged to upgrade to this version.\u003c/p\u003e\n\u003ch2\u003ev4.13.4\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(request): handle params on unmatched requests in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5268\"\u003ehonojs/hono#5268\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(jsx/dom): execute previous ref cleanup when ref prop changes on re-render  in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5264\"\u003ehonojs/hono#5264\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(reg-exp-router): associate wildcard middleware with matching routes in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5266\"\u003ehonojs/hono#5266\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf(router): share null object creation in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5267\"\u003ehonojs/hono#5267\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/hono/commit/eebdf7be39abf0a872671835ccce0c4f03ea497a\"\u003e\u003ccode\u003eeebdf7b\u003c/code\u003e\u003c/a\u003e 4.13.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/hono/commit/2b8ed402cdab6dfc5e829b480806dcd8db94161e\"\u003e\u003ccode\u003e2b8ed40\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/hono/commit/cac0c4d3fe29aca4e426031067cbbb3b9131e30c\"\u003e\u003ccode\u003ecac0c4d\u003c/code\u003e\u003c/a\u003e 4.13.6\u003c/li\u003e\n...\n\n_Description has been truncated_","html_url":"https://github.com/justshhhhhhh-au/copilot-sdk/pull/1","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/justshhhhhhh-au%2Fcopilot-sdk/issues/1","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1/packages"},{"uuid":"5440272467","node_id":"PR_kwDOTIbqCs8AAAABDVhaIA","number":4,"state":"closed","title":"build(deps): bump fast-uri from 3.1.2 to 3.1.7","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-13T13:27:01.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-13T13:17:53.000Z","updated_at":"2026-09-13T13:27:02.000Z","time_to_close":548,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps)","packages":[{"name":"fast-uri","old_version":"3.1.2","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"}],"path":null,"ecosystem":"npm"},"body":"Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.2 to 3.1.7.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=fast-uri\u0026package-manager=npm_and_yarn\u0026previous-version=3.1.2\u0026new-version=3.1.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/CedricConday/xe-mcp/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/CedricConday/xe-mcp/pull/4","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/CedricConday%2Fxe-mcp/issues/4","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/4/packages"},{"uuid":"5439925042","node_id":"PR_kwDOPmcHEM8AAAABDVQnVg","number":248,"state":"open","title":"build(deps): bump the npm_and_yarn group across 1 directory with 2 updates","user":"dependabot[bot]","labels":["dependencies","javascript","size/XS"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-13T12:03:05.000Z","updated_at":"2026-09-13T12:03:11.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"npm_and_yarn","update_count":2,"packages":[{"name":"fast-uri","old_version":"3.1.5","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"js-yaml","old_version":"4.3.1","new_version":"4.3.2"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 1 update in the / directory: [fast-uri](https://github.com/fastify/fast-uri).\n\nUpdates `fast-uri` from 3.1.5 to 3.1.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `js-yaml` from 4.3.1 to 4.3.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md\"\u003ejs-yaml's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.3.2 - 2026-08-26\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Hard-limit merge sequence size to 100.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Count empty mappings in merge sequences toward \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e\nto limit CPU usage, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/797\"\u003e#797\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/79ca68d90f333fbe6d9e42827527e62636200191\"\u003e\u003ccode\u003e79ca68d\u003c/code\u003e\u003c/a\u003e 4.3.2 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/d90b6612a5a84385bdcb556c44578eac76dc0f6b\"\u003e\u003ccode\u003ed90b661\u003c/code\u003e\u003c/a\u003e Backport merge limits from v5.4.1\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodeca/js-yaml/compare/4.3.1...4.3.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/LarsArtmann/typespec-asyncapi/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/LarsArtmann/typespec-asyncapi/pull/248","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/LarsArtmann%2Ftypespec-asyncapi/issues/248","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/248/packages"},{"uuid":"5439815033","node_id":"PR_kwDOQxPRE88AAAABDVLNwA","number":6,"state":"open","title":"Bump the npm_and_yarn group across 1 directory with 13 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":5,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-13T11:39:46.000Z","updated_at":"2026-09-13T11:40:10.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"npm_and_yarn","update_count":13,"packages":[{"name":"@modelcontextprotocol/sdk","old_version":"1.25.1","new_version":"1.26.0","repository_url":"https://github.com/modelcontextprotocol/typescript-sdk"},{"name":"uuid","old_version":"9.0.1","new_version":"14.0.0","repository_url":"https://github.com/uuidjs/uuid"},{"name":"brace-expansion","old_version":"1.1.12","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"ajv","old_version":"6.12.6","new_version":"6.15.0","repository_url":"https://github.com/ajv-validator/ajv"},{"name":"body-parser","old_version":"2.2.1","new_version":"2.3.0","repository_url":"https://github.com/expressjs/body-parser"},{"name":"body-parser","old_version":"1.20.4","new_version":"1.20.8","repository_url":"https://github.com/expressjs/body-parser"},{"name":"fast-uri","old_version":"3.1.0","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"flatted","old_version":"3.3.3","new_version":"3.4.4","repository_url":"https://github.com/WebReflection/flatted"},{"name":"js-yaml","old_version":"4.1.1","new_version":"4.3.2","repository_url":"https://github.com/nodeca/js-yaml"},{"name":"path-to-regexp","old_version":"8.3.0","new_version":"8.4.2","repository_url":"https://github.com/pillarjs/path-to-regexp"},{"name":"path-to-regexp","old_version":"0.1.12","new_version":"0.1.13","repository_url":"https://github.com/pillarjs/path-to-regexp"},{"name":"picomatch","old_version":"2.3.1","new_version":"2.3.2","repository_url":"https://github.com/micromatch/picomatch"},{"name":"qs","old_version":"6.14.1","new_version":"6.16.0","repository_url":"https://github.com/ljharb/qs"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 11 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.25.1` | `1.26.0` |\n| [uuid](https://github.com/uuidjs/uuid) | `9.0.1` | `14.0.0` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.12` | `1.1.18` |\n| [ajv](https://github.com/ajv-validator/ajv) | `6.12.6` | `6.15.0` |\n| [body-parser](https://github.com/expressjs/body-parser) | `2.2.1` | `2.3.0` |\n| [body-parser](https://github.com/expressjs/body-parser) | `1.20.4` | `1.20.8` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.0` | `3.1.7` |\n| [flatted](https://github.com/WebReflection/flatted) | `3.3.3` | `3.4.4` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.1` | `4.3.2` |\n| [path-to-regexp](https://github.com/pillarjs/path-to-regexp) | `8.3.0` | `8.4.2` |\n| [path-to-regexp](https://github.com/pillarjs/path-to-regexp) | `0.1.12` | `0.1.13` |\n| [picomatch](https://github.com/micromatch/picomatch) | `2.3.1` | `2.3.2` |\n| [qs](https://github.com/ljharb/qs) | `6.14.1` | `6.16.0` |\n\n\nUpdates `@modelcontextprotocol/sdk` from 1.25.1 to 1.26.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/releases\"\u003e@​modelcontextprotocol/sdk's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.26.0\u003c/h2\u003e\n\u003cp\u003eAddresses \u0026quot;Sharing server/transport instances can leak cross-client response data\u0026quot; in this GHSA \u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/security/advisories/GHSA-345p-7cg4-v4c7\"\u003ehttps://github.com/modelcontextprotocol/typescript-sdk/security/advisories/GHSA-345p-7cg4-v4c7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore: bump v1.25.3 for backport fixes by \u003ca href=\"https://github.com/pcarleton\"\u003e\u003ccode\u003e@​pcarleton\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1412\"\u003emodelcontextprotocol/typescript-sdk#1412\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(deps): resolve npm audit vulnerabilities and bump dependencies (v1.x backport) by \u003ca href=\"https://github.com/samuv\"\u003e\u003ccode\u003e@​samuv\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1382\"\u003emodelcontextprotocol/typescript-sdk#1382\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1430\"\u003e#1430\u003c/a\u003e: Client Credentials providers scopes support (backported) by \u003ca href=\"https://github.com/NSeydoux\"\u003e\u003ccode\u003e@​NSeydoux\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1442\"\u003emodelcontextprotocol/typescript-sdk#1442\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump version to 1.26.0 by \u003ca href=\"https://github.com/pcarleton\"\u003e\u003ccode\u003e@​pcarleton\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1479\"\u003emodelcontextprotocol/typescript-sdk#1479\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/samuv\"\u003e\u003ccode\u003e@​samuv\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1382\"\u003emodelcontextprotocol/typescript-sdk#1382\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NSeydoux\"\u003e\u003ccode\u003e@​NSeydoux\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1442\"\u003emodelcontextprotocol/typescript-sdk#1442\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/compare/v1.25.3...v1.26.0\"\u003ehttps://github.com/modelcontextprotocol/typescript-sdk/compare/v1.25.3...v1.26.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.25.3\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[v1.x backport] Use correct schema for client sampling validation when tools are present by \u003ca href=\"https://github.com/olaservo\"\u003e\u003ccode\u003e@​olaservo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1407\"\u003emodelcontextprotocol/typescript-sdk#1407\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: prevent Hono from overriding global Response object (v1.x) by \u003ca href=\"https://github.com/mattzcarey\"\u003e\u003ccode\u003e@​mattzcarey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1411\"\u003emodelcontextprotocol/typescript-sdk#1411\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/compare/v1.25.2...v1.25.3\"\u003ehttps://github.com/modelcontextprotocol/typescript-sdk/compare/v1.25.2...v1.25.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.25.2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eci: trigger workflow on v1.x branch by \u003ca href=\"https://github.com/felixweinberger\"\u003e\u003ccode\u003e@​felixweinberger\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1319\"\u003emodelcontextprotocol/typescript-sdk#1319\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: README badges links destinations by \u003ca href=\"https://github.com/antonpk1\"\u003e\u003ccode\u003e@​antonpk1\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/907\"\u003emodelcontextprotocol/typescript-sdk#907\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: prevent ReDoS in UriTemplate regex patterns (v1.x backport) by \u003ca href=\"https://github.com/pcarleton\"\u003e\u003ccode\u003e@​pcarleton\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1365\"\u003emodelcontextprotocol/typescript-sdk#1365\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/antonpk1\"\u003e\u003ccode\u003e@​antonpk1\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/907\"\u003emodelcontextprotocol/typescript-sdk#907\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/compare/1.25.1...v1.25.2\"\u003ehttps://github.com/modelcontextprotocol/typescript-sdk/compare/1.25.1...v1.25.2\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/fe9c07b465871394c7069207c86513df9c1194a4\"\u003e\u003ccode\u003efe9c07b\u003c/code\u003e\u003c/a\u003e chore: bump version to 1.26.0 (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1479\"\u003e#1479\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/4f01e7e0708e1a85ccc7dbf39e850005f2d9ff03\"\u003e\u003ccode\u003e4f01e7e\u003c/code\u003e\u003c/a\u003e fix: add non-null assertions for optional setupServer fields in stateful test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/a05be176cabeae1f933b676e3ce024bf02e2314d\"\u003e\u003ccode\u003ea05be17\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/50d9fa3cd12e807e7963bcb9e1548786d3d5d941\"\u003e\u003ccode\u003e50d9fa3\u003c/code\u003e\u003c/a\u003e Fix \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1430\"\u003e#1430\u003c/a\u003e: Client Credentials providers scopes support (backported) (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1442\"\u003e#1442\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/aa81a66556fb4434d8a6d1b70f7ac9fc40b5d325\"\u003e\u003ccode\u003eaa81a66\u003c/code\u003e\u003c/a\u003e fix(deps): resolve npm audit vulnerabilities and bump dependencies (v1.x back...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/6aba0659654e1ff0699844524595922a61e44cb9\"\u003e\u003ccode\u003e6aba065\u003c/code\u003e\u003c/a\u003e chore: bump v1.25.3 for backport fixes (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1412\"\u003e#1412\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/6e8f7e1a43a819ae230373c62b82228dafd892c6\"\u003e\u003ccode\u003e6e8f7e1\u003c/code\u003e\u003c/a\u003e fix: prevent Hono from overriding global Response object (v1.x) (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1411\"\u003e#1411\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/12ae856cee6ca58499cce24e80f650e78a0c7610\"\u003e\u003ccode\u003e12ae856\u003c/code\u003e\u003c/a\u003e [v1.x backport] Use correct schema for client sampling validation when tools ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/b392f02ffcf37c088dbd114fedf25026ec3913d3\"\u003e\u003ccode\u003eb392f02\u003c/code\u003e\u003c/a\u003e fix: prevent ReDoS in UriTemplate regex patterns (v1.x backport) (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1365\"\u003e#1365\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/a0c9b13484748acab9e5dc8317a7e89c06b52e37\"\u003e\u003ccode\u003ea0c9b13\u003c/code\u003e\u003c/a\u003e fix: README badges links destinations (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/907\"\u003e#907\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/compare/1.25.1...v1.26.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `uuid` from 9.0.1 to 14.0.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/uuidjs/uuid/releases\"\u003euuid's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev14.0.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/uuidjs/uuid/compare/v13.0.0...v14.0.0\"\u003e14.0.0\u003c/a\u003e (2026-04-19)\u003c/h2\u003e\n\u003ch3\u003e⚠ BREAKING CHANGES\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eexpect \u003ccode\u003ecrypto\u003c/code\u003e to be global everywhere (requires node@20+) (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/935\"\u003e#935\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edrop node@18 support (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/934\"\u003e#934\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003edrop node@18 support (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/934\"\u003e#934\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/dc4ddb87272ed2843faccd130bcc41d492688bd3\"\u003edc4ddb8\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eexpect \u003ccode\u003ecrypto\u003c/code\u003e to be global everywhere (requires node@20+) (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/935\"\u003e#935\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/f2c235f93059325fa43e1106e624b5291bb523c4\"\u003ef2c235f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUse GITHUB_TOKEN for release-please and enable npm provenance (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/925\"\u003e#925\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/ffa31383e8e4e1f0b4e22e504561272041b8738c\"\u003effa3138\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev13.0.2\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/uuidjs/uuid/compare/v13.0.1...v13.0.2\"\u003e13.0.2\u003c/a\u003e (2026-05-04)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ererelease to fix provenance. (\u003ca href=\"https://github.com/uuidjs/uuid/commit/49ccb35f78c0c4ce1409dd2f1d89f83caadba10b\"\u003e49ccb35\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev13.0.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/uuidjs/uuid/compare/v13.0.0...v13.0.1\"\u003e13.0.1\u003c/a\u003e (2026-04-27)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ebackport fix for GHSA-w5hq-g745-h8pq (\u003ca href=\"https://github.com/uuidjs/uuid/commit/9d27ddf7046ce496ef39569ff84d948eeff9cb2a\"\u003e9d27ddf\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev13.0.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/uuidjs/uuid/compare/v12.0.0...v13.0.0\"\u003e13.0.0\u003c/a\u003e (2025-09-08)\u003c/h2\u003e\n\u003ch3\u003e⚠ BREAKING CHANGES\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003emake browser exports the default (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/901\"\u003e#901\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003emake browser exports the default (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/901\"\u003e#901\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/bce9d72a3ae5b9a3dcd8eb21ef6d1820288a427a\"\u003ebce9d72\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev12.0.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/uuidjs/uuid/compare/v12.0.0...v12.0.1\"\u003e12.0.1\u003c/a\u003e (2026-04-29)\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md\"\u003euuid's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/uuidjs/uuid/compare/v13.0.0...v14.0.0\"\u003e14.0.0\u003c/a\u003e (2026-04-19)\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixes \u003ca href=\"https://github.com/uuidjs/uuid/security/advisories/GHSA-w5hq-g745-h8pq\"\u003eGHSA-w5hq-g745-h8pq\u003c/a\u003e: \u003ccode\u003ev3()\u003c/code\u003e, \u003ccode\u003ev5()\u003c/code\u003e, and \u003ccode\u003ev6()\u003c/code\u003e did not validate that writes would remain within the bounds of a caller-supplied buffer, allowing out-of-bounds writes when an invalid \u003ccode\u003eoffset\u003c/code\u003e was provided. A \u003ccode\u003eRangeError\u003c/code\u003e is now thrown if \u003ccode\u003eoffset \u0026lt; 0\u003c/code\u003e or \u003ccode\u003eoffset + 16 \u0026gt; buf.length\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e⚠ BREAKING CHANGES\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ecrypto\u003c/code\u003e is now expected to be globally defined (requires node@20+) (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/935\"\u003e#935\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edrop node@18 support (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/934\"\u003e#934\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupgrade minimum supported TypeScript version to 5.4.3, in keeping with the project's policy of supporting TypeScript versions released within the last two years\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/uuidjs/uuid/compare/v12.0.0...v13.0.0\"\u003e13.0.0\u003c/a\u003e (2025-09-08)\u003c/h2\u003e\n\u003ch3\u003e⚠ BREAKING CHANGES\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003emake browser exports the default (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/901\"\u003e#901\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003emake browser exports the default (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/901\"\u003e#901\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/bce9d72a3ae5b9a3dcd8eb21ef6d1820288a427a\"\u003ebce9d72\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/uuidjs/uuid/compare/v11.1.0...v12.0.0\"\u003e12.0.0\u003c/a\u003e (2025-09-05)\u003c/h2\u003e\n\u003ch3\u003e⚠ BREAKING CHANGES\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eupdate to typescript@5.2 (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/887\"\u003e#887\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eremove CommonJS support (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/886\"\u003e#886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edrop node@16 support (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/883\"\u003e#883\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eadd node@24 to ci matrix (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/879\"\u003e#879\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/42b6178aa21a593257f0a72abacd220f0b7b8a92\"\u003e42b6178\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edrop node@16 support (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/883\"\u003e#883\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/0f38cf10366ab074f9328ae2021eea04d5f2e530\"\u003e0f38cf1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eremove CommonJS support (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/886\"\u003e#886\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/ae786e27265f50bcf7cead196c29f1869297c42f\"\u003eae786e2\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate to typescript@5.2 (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/887\"\u003e#887\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/c7ee40598ed78584d81ab78dffded9fe5ff20b01\"\u003ec7ee405\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eimprove v4() performance (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/894\"\u003e#894\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/5fd974c12718c8848035650b69b8948f12ace197\"\u003e5fd974c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erestore node: prefix (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/889\"\u003e#889\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/e1f42a354593093ba0479f0b4047dae82d28c507\"\u003ee1f42a3\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/uuidjs/uuid/compare/v11.0.5...v11.1.0\"\u003e11.1.0\u003c/a\u003e (2025-02-19)\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uuidjs/uuid/commit/7c1ea087a8149b57380fc8bb7f68c3a215cb6e4b\"\u003e\u003ccode\u003e7c1ea08\u003c/code\u003e\u003c/a\u003e chore(main): release 14.0.0 (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/926\"\u003e#926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uuidjs/uuid/commit/3d2c5b0342f0fcb52a5ac681c3d47c13e7444b34\"\u003e\u003ccode\u003e3d2c5b0\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uuidjs/uuid/commit/f2c235f93059325fa43e1106e624b5291bb523c4\"\u003e\u003ccode\u003ef2c235f\u003c/code\u003e\u003c/a\u003e fix!: expect \u003ccode\u003ecrypto\u003c/code\u003e to be global everywhere (requires node@20+) (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/935\"\u003e#935\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uuidjs/uuid/commit/529ef0899f5dd503d2ee90d690585d63d78bc212\"\u003e\u003ccode\u003e529ef08\u003c/code\u003e\u003c/a\u003e chore: upgrade TypeScript and fixup types (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/927\"\u003e#927\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uuidjs/uuid/commit/086fd7976f11433edf9ac80be876b3ad243fe087\"\u003e\u003ccode\u003e086fd79\u003c/code\u003e\u003c/a\u003e chore: update dependencies (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/933\"\u003e#933\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uuidjs/uuid/commit/dc4ddb87272ed2843faccd130bcc41d492688bd3\"\u003e\u003ccode\u003edc4ddb8\u003c/code\u003e\u003c/a\u003e feat!: drop node@18 support (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/934\"\u003e#934\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uuidjs/uuid/commit/0f1f9c9c9cedbae5a1d363d5406c5dfbabe81404\"\u003e\u003ccode\u003e0f1f9c9\u003c/code\u003e\u003c/a\u003e chore: switch to Biome for parsing and linting (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/932\"\u003e#932\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uuidjs/uuid/commit/e2879e64bf125add903c1eff6e0860542c605013\"\u003e\u003ccode\u003ee2879e6\u003c/code\u003e\u003c/a\u003e chore: use maintained version of npm-run-all (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/930\"\u003e#930\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uuidjs/uuid/commit/ffa31383e8e4e1f0b4e22e504561272041b8738c\"\u003e\u003ccode\u003effa3138\u003c/code\u003e\u003c/a\u003e fix: Use GITHUB_TOKEN for release-please and enable npm provenance (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/925\"\u003e#925\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uuidjs/uuid/commit/0423d49df2dc8efc300c804731d25f4d7e0fccc4\"\u003e\u003ccode\u003e0423d49\u003c/code\u003e\u003c/a\u003e docs: remove obsolete v1 option notes (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/915\"\u003e#915\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/uuidjs/uuid/compare/v9.0.1...v14.0.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for uuid since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eInstall script changes\u003c/summary\u003e\n\u003cp\u003eThis version adds \u003ccode\u003eprepare\u003c/code\u003e script that runs during installation. Review the package contents before updating.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.12 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24\"\u003e\u003ccode\u003e2203f4f\u003c/code\u003e\u003c/a\u003e 1.1.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd\"\u003e\u003ccode\u003e0b09384\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/10c05fcf3699b1a29ef5e611c011af3d3c97e6e3\"\u003e\u003ccode\u003e10c05fc\u003c/code\u003e\u003c/a\u003e 1.1.14\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.12...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@hono/node-server` from 1.19.7 to 1.19.17\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/honojs/node-server/releases\"\u003e@​hono/node-server's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.19.17\u003c/h2\u003e\n\u003cp\u003eNo release notes provided.\u003c/p\u003e\n\u003ch2\u003ev1.19.14\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: add custom inspect to lightweight Request/Response to prevent TypeError on console.log by \u003ca href=\"https://github.com/usualoma\"\u003e\u003ccode\u003e@​usualoma\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/340\"\u003ehonojs/node-server#340\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/node-server/compare/v1.19.13...v1.19.14\"\u003ehttps://github.com/honojs/node-server/compare/v1.19.13...v1.19.14\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.19.13\u003c/h2\u003e\n\u003ch2\u003eSecurity Fix\u003c/h2\u003e\n\u003cp\u003eFixed an issue in Serve Static Middleware where inconsistent handling of repeated slashes (\u003ccode\u003e//\u003c/code\u003e) between the router and static file resolution could allow middleware to be bypassed. Users of Serve Static Middleware are encouraged to upgrade to this version.\u003c/p\u003e\n\u003cp\u003eSee GHSA-92pp-h63x-v22m for details.\u003c/p\u003e\n\u003ch2\u003ev1.19.12\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore: ignore claude setting by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/314\"\u003ehonojs/node-server#314\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: request draining for early 413 responses by \u003ca href=\"https://github.com/usualoma\"\u003e\u003ccode\u003e@​usualoma\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/329\"\u003ehonojs/node-server#329\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/node-server/compare/v1.19.11...v1.19.12\"\u003ehttps://github.com/honojs/node-server/compare/v1.19.11...v1.19.12\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.19.11\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: do not overwrite Content-Length in the fast path pattern if Content-Length already exists. by \u003ca href=\"https://github.com/usualoma\"\u003e\u003ccode\u003e@​usualoma\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/309\"\u003ehonojs/node-server#309\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/node-server/compare/v1.19.10...v1.19.11\"\u003ehttps://github.com/honojs/node-server/compare/v1.19.10...v1.19.11\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.19.10\u003c/h2\u003e\n\u003ch2\u003eSecurity Fix\u003c/h2\u003e\n\u003cp\u003eFixed an authorization bypass in Serve Static Middleware caused by inconsistent URL decoding (\u003ccode\u003e%2F\u003c/code\u003e handling) between the router and static file resolution. Users of Serve Static Middleware are encouraged to upgrade to this version.\u003c/p\u003e\n\u003cp\u003eSee GHSA-wc8c-qw6v-h7f6 for details.\u003c/p\u003e\n\u003ch2\u003ev1.19.9\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(globals): Stop overwriting global.fetch by \u003ca href=\"https://github.com/usualoma\"\u003e\u003ccode\u003e@​usualoma\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/295\"\u003ehonojs/node-server#295\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/node-server/compare/v1.19.8...v1.19.9\"\u003ehttps://github.com/honojs/node-server/compare/v1.19.8...v1.19.9\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.19.8\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocs: add guide for listening to UNIX domain socket by \u003ca href=\"https://github.com/TransparentLC\"\u003e\u003ccode\u003e@​TransparentLC\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/292\"\u003ehonojs/node-server#292\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(serve-static): Use Readable.toWeb in serveStatic by \u003ca href=\"https://github.com/otya128\"\u003e\u003ccode\u003e@​otya128\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/293\"\u003ehonojs/node-server#293\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/71941daede982571f18d2774951f37c475cccefc\"\u003e\u003ccode\u003e71941da\u003c/code\u003e\u003c/a\u003e 1.19.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/0208500d8f11b33dd03b50c86df8e132307adf1e\"\u003e\u003ccode\u003e0208500\u003c/code\u003e\u003c/a\u003e ci: add \u003ccode\u003estage\u003c/code\u003e option for publishing (\u003ca href=\"https://redirect.github.com/honojs/node-server/issues/386\"\u003e#386\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/cbdf713a67ef38f6a5304488e294381230a52e46\"\u003e\u003ccode\u003ecbdf713\u003c/code\u003e\u003c/a\u003e 1.19.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/86e96c24045411b3e3c4a9b61a4c1e755c398a44\"\u003e\u003ccode\u003e86e96c2\u003c/code\u003e\u003c/a\u003e ci: add an action for trusted publisher (\u003ca href=\"https://redirect.github.com/honojs/node-server/issues/385\"\u003e#385\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/99c1a1abd702132302f3da72600d383a25eba32c\"\u003e\u003ccode\u003e99c1a1a\u003c/code\u003e\u003c/a\u003e ci: run on v1.x branch pushes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/84cb2ee25f567d812b76e0cff4c36899acb157eb\"\u003e\u003ccode\u003e84cb2ee\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/b5e63a366d9b0ef62ac65fcafd7f69b383b03ff5\"\u003e\u003ccode\u003eb5e63a3\u003c/code\u003e\u003c/a\u003e 1.19.14\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/c02d7770a2d29ea473403211bef0a60639885a28\"\u003e\u003ccode\u003ec02d777\u003c/code\u003e\u003c/a\u003e fix: add custom inspect to lightweight Request/Response to prevent TypeError ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/fd64e659a34ec661fd9ccda00d1b9dff88dfaf90\"\u003e\u003ccode\u003efd64e65\u003c/code\u003e\u003c/a\u003e 1.19.13\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/025c30f55d589ddbe6048b151d77e904f67a8cc2\"\u003e\u003ccode\u003e025c30f\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/honojs/node-server/compare/v1.19.7...v1.19.17\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​hono/node-server\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ajv` from 6.12.6 to 6.15.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ajv-validator/ajv/commit/184bc32745d9d33b2322949b9f3cb5f7609bf5ec\"\u003e\u003ccode\u003e184bc32\u003c/code\u003e\u003c/a\u003e 6.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ajv-validator/ajv/commit/fea46afd1a76b12ff89493f6dc1bc46730c6d379\"\u003e\u003ccode\u003efea46af\u003c/code\u003e\u003c/a\u003e test/fix prototype pollution via $data ref with format keyword (\u003ca href=\"https://redirect.github.com/ajv-validator/ajv/issues/2606\"\u003e#2606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ajv-validator/ajv/commit/e3af0a723b4b7ad86eff43be355c706d31e0e915\"\u003e\u003ccode\u003ee3af0a7\u003c/code\u003e\u003c/a\u003e 6.14.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ajv-validator/ajv/commit/b552ed66191eb338498df3196065c777e3bb71f2\"\u003e\u003ccode\u003eb552ed6\u003c/code\u003e\u003c/a\u003e add regExp option to address $data exploit via a regular expression (CVE-2025...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ajv-validator/ajv/commit/72f228665859eed5e2be3a66f8c4a7aff6b34dcf\"\u003e\u003ccode\u003e72f2286\u003c/code\u003e\u003c/a\u003e docs: update v7 info\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ajv-validator/ajv/commit/231e52b3bca62559202b95e5fb5cee02145b226a\"\u003e\u003ccode\u003e231e52b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/ajv-validator/ajv/issues/1320\"\u003e#1320\u003c/a\u003e from philsturgeon/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ajv-validator/ajv/commit/d3475fc20416c33fe030c8aa3b09fa411f325bbd\"\u003e\u003ccode\u003ed3475fc\u003c/code\u003e\u003c/a\u003e Add spectral, an AJV util from a sponsor\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ajv-validator/ajv/commit/413afe01f518ea74d1740a7cb211df787c585544\"\u003e\u003ccode\u003e413afe0\u003c/code\u003e\u003c/a\u003e docs: v7.0.0-beta.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ajv-validator/ajv/commit/11e997bda2f3eecb445c1e5a07d96ef7e81c5f5d\"\u003e\u003ccode\u003e11e997b\u003c/code\u003e\u003c/a\u003e update readme for v7\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/ajv-validator/ajv/compare/v6.12.6...v6.15.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `body-parser` from 2.2.1 to 2.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/body-parser/releases\"\u003ebody-parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.3.0\u003c/h2\u003e\n\u003ch2\u003eImportant: Security\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity fix for \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2025-13466\"\u003eCVE-2026-12590\u003c/a\u003e (\u003ca href=\"https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6\"\u003eGHSA-v422-hmwv-36x6\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps): bump actions/download-artifact from 6.0.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/681\"\u003eexpressjs/body-parser#681\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/checkout from 5.0.0 to 6.0.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/682\"\u003eexpressjs/body-parser#682\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.0.0 to 6.1.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/683\"\u003eexpressjs/body-parser#683\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/685\"\u003eexpressjs/body-parser#685\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.31.2 to 4.31.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/684\"\u003eexpressjs/body-parser#684\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf(urlencoded): move empty-body guard to avoid extra function closure by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/647\"\u003eexpressjs/body-parser#647\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove ESM compatibility by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/697\"\u003eexpressjs/body-parser#697\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: add recommendations for configuring payload limits by \u003ca href=\"https://github.com/bjohansebas\"\u003e\u003ccode\u003e@​bjohansebas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/699\"\u003eexpressjs/body-parser#699\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.1.0 to 6.2.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/701\"\u003eexpressjs/body-parser#701\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.31.10 to 4.32.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/702\"\u003eexpressjs/body-parser#702\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/checkout from 6.0.1 to 6.0.2 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/700\"\u003eexpressjs/body-parser#700\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore:  add explicit type commonjs to package.json by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/711\"\u003eexpressjs/body-parser#711\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edeps: update dependencies to latest versions by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/708\"\u003eexpressjs/body-parser#708\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/download-artifact from 7.0.0 to 8.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/712\"\u003eexpressjs/body-parser#712\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.32.0 to 4.32.4 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/713\"\u003eexpressjs/body-parser#713\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/714\"\u003eexpressjs/body-parser#714\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: improve limit option validation by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/698\"\u003eexpressjs/body-parser#698\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.32.4 to 4.35.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/719\"\u003eexpressjs/body-parser#719\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.2.0 to 6.3.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/718\"\u003eexpressjs/body-parser#718\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/download-artifact from 8.0.0 to 8.0.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/717\"\u003eexpressjs/body-parser#717\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: eliminate conditional check in json strict mode hot path by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/651\"\u003eexpressjs/body-parser#651\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: add node.js 26 to text matrix by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/726\"\u003eexpressjs/body-parser#726\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.3.0 to 6.4.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/725\"\u003eexpressjs/body-parser#725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/724\"\u003eexpressjs/body-parser#724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.35.1 to 4.35.3 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/723\"\u003eexpressjs/body-parser#723\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade \u0026quot;content-type\u0026quot; by \u003ca href=\"https://github.com/blakeembrey\"\u003e\u003ccode\u003e@​blakeembrey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/728\"\u003eexpressjs/body-parser#728\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor: switch to const/let and enable eslint no-var rule by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/729\"\u003eexpressjs/body-parser#729\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate outdated reference to MDN docs by \u003ca href=\"https://github.com/krzysdz\"\u003e\u003ccode\u003e@​krzysdz\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/730\"\u003eexpressjs/body-parser#730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.35.3 to 4.36.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/731\"\u003eexpressjs/body-parser#731\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/checkout from 6.0.2 to 6.0.3 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/732\"\u003eexpressjs/body-parser#732\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: updated deps to latest by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/733\"\u003eexpressjs/body-parser#733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e2.3.0 by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/735\"\u003eexpressjs/body-parser#735\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/krzysdz\"\u003e\u003ccode\u003e@​krzysdz\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/730\"\u003eexpressjs/body-parser#730\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/v2.2.2...v2.3.0\"\u003ehttps://github.com/expressjs/body-parser/compare/v2.2.2...v2.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.2.2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocs: update README links by \u003ca href=\"https://github.com/efekrskl\"\u003e\u003ccode\u003e@​efekrskl\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/673\"\u003eexpressjs/body-parser#673\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: release notes for the v1.20.4 release by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/674\"\u003eexpressjs/body-parser#674\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: update URL-encoded parser description to include ISO-8859-1 encoding support by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/679\"\u003eexpressjs/body-parser#679\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: use standard jsdoc tags everywhere by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/677\"\u003eexpressjs/body-parser#677\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/body-parser/blob/master/HISTORY.md\"\u003ebody-parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e2.3.0 / 2026-06-15\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity fix for \u003ca href=\"https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6\"\u003eGHSA-v422-hmwv-36x6\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: use static exports instead of lazy getters to improve ESM compatibility\u003c/li\u003e\n\u003cli\u003efeat: add subpath exports for individual parsers\u003c/li\u003e\n\u003cli\u003efix: improve \u003ccode\u003elimit\u003c/code\u003e option validation (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/698\"\u003e#698\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003eInvalid \u003ccode\u003elimit\u003c/code\u003e values (e.g. unparseable strings or \u003ccode\u003eNaN\u003c/code\u003e) now throw instead of being silently ignored, which previously disabled size limit enforcement\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003enull\u003c/code\u003e and \u003ccode\u003eundefined\u003c/code\u003e fall back to the default 100kb limit\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003edeps:\n\u003cul\u003e\n\u003cli\u003econtent-type@^2.0.0\u003c/li\u003e\n\u003cli\u003ehttp-errors@^2.0.1\u003c/li\u003e\n\u003cli\u003eiconv-lite^0.7.2\u003c/li\u003e\n\u003cli\u003eqs@^6.15.2\u003c/li\u003e\n\u003cli\u003eraw-body@^3.0.2\u003c/li\u003e\n\u003cli\u003etype-is@^2.1.0\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e2.2.2 / 2026-01-07\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003edeps: qs@^6.14.1\u003c/li\u003e\n\u003cli\u003erefactor(json): simplify strict mode error string construction\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/d0f2ace6c74769da7d19b8661b9a01c01bdb0bf7\"\u003e\u003ccode\u003ed0f2ace\u003c/code\u003e\u003c/a\u003e 2.3.0 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/735\"\u003e#735\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/7d03f2f9d561dafd1576b137713353c95253512c\"\u003e\u003ccode\u003e7d03f2f\u003c/code\u003e\u003c/a\u003e chore: updated deps to latest (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/733\"\u003e#733\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/8024ba7a813e6647ed63832d209a2abb8531267a\"\u003e\u003ccode\u003e8024ba7\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/checkout from 6.0.2 to 6.0.3 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/732\"\u003e#732\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/32b4ed4639281f04563adcd41d724ab06c9105d4\"\u003e\u003ccode\u003e32b4ed4\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action from 4.35.3 to 4.36.1 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/731\"\u003e#731\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/ff0f6b907106ec5a1b81c80f5a552d921c1bc9a5\"\u003e\u003ccode\u003eff0f6b9\u003c/code\u003e\u003c/a\u003e docs: update outdated reference to MDN docs (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/730\"\u003e#730\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/14d001a9c90abc05891d895ad3e9cf0a65b7b34a\"\u003e\u003ccode\u003e14d001a\u003c/code\u003e\u003c/a\u003e refactor: switch to const/let and enable eslint no-var rule (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/729\"\u003e#729\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/37f36a27528e65d7216f2c31c7039d3458c72147\"\u003e\u003ccode\u003e37f36a2\u003c/code\u003e\u003c/a\u003e deps: update content-type and type-is (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/728\"\u003e#728\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/e1c244bf55fb00a6de4be882b4ed9fc20807d864\"\u003e\u003ccode\u003ee1c244b\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action from 4.35.1 to 4.35.3 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/723\"\u003e#723\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/e01087f52192e20e2d0f8726d4f28a8d49d06c87\"\u003e\u003ccode\u003ee01087f\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/724\"\u003e#724\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/a7698d30280a3e931ea8841396e5d0ac5414e429\"\u003e\u003ccode\u003ea7698d3\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/setup-node from 6.3.0 to 6.4.0 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/725\"\u003e#725\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/expressjs/body-parser/compare/v2.2.1...v2.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `body-parser` from 1.20.4 to 1.20.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/body-parser/releases\"\u003ebody-parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.3.0\u003c/h2\u003e\n\u003ch2\u003eImportant: Security\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity fix for \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2025-13466\"\u003eCVE-2026-12590\u003c/a\u003e (\u003ca href=\"https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6\"\u003eGHSA-v422-hmwv-36x6\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps): bump actions/download-artifact from 6.0.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/681\"\u003eexpressjs/body-parser#681\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/checkout from 5.0.0 to 6.0.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/682\"\u003eexpressjs/body-parser#682\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.0.0 to 6.1.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/683\"\u003eexpressjs/body-parser#683\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/685\"\u003eexpressjs/body-parser#685\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.31.2 to 4.31.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/684\"\u003eexpressjs/body-parser#684\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf(urlencoded): move empty-body guard to avoid extra function closure by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/647\"\u003eexpressjs/body-parser#647\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove ESM compatibility by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/697\"\u003eexpressjs/body-parser#697\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: add recommendations for configuring payload limits by \u003ca href=\"https://github.com/bjohansebas\"\u003e\u003ccode\u003e@​bjohansebas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/699\"\u003eexpressjs/body-parser#699\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.1.0 to 6.2.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/701\"\u003eexpressjs/body-parser#701\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.31.10 to 4.32.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/702\"\u003eexpressjs/body-parser#702\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/checkout from 6.0.1 to 6.0.2 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/700\"\u003eexpressjs/body-parser#700\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore:  add explicit type commonjs to package.json by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/711\"\u003eexpressjs/body-parser#711\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edeps: update dependencies to latest versions by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/708\"\u003eexpressjs/body-parser#708\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/download-artifact from 7.0.0 to 8.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/712\"\u003eexpressjs/body-parser#712\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.32.0 to 4.32.4 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/713\"\u003eexpressjs/body-parser#713\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/714\"\u003eexpressjs/body-parser#714\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: improve limit option validation by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/698\"\u003eexpressjs/body-parser#698\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.32.4 to 4.35.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/719\"\u003eexpressjs/body-parser#719\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.2.0 to 6.3.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/718\"\u003eexpressjs/body-parser#718\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/download-artifact from 8.0.0 to 8.0.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/717\"\u003eexpressjs/body-parser#717\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: eliminate conditional check in json strict mode hot path by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/651\"\u003eexpressjs/body-parser#651\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: add node.js 26 to text matrix by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/726\"\u003eexpressjs/body-parser#726\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.3.0 to 6.4.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/725\"\u003eexpressjs/body-parser#725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/724\"\u003eexpressjs/body-parser#724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.35.1 to 4.35.3 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/723\"\u003eexpressjs/body-parser#723\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade \u0026quot;content-type\u0026quot; by \u003ca href=\"https://github.com/blakeembrey\"\u003e\u003ccode\u003e@​blakeembrey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/728\"\u003eexpressjs/body-parser#728\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor: switch to const/let and enable eslint no-var rule by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/729\"\u003eexpressjs/body-parser#729\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate outdated reference to MDN docs by \u003ca href=\"https://github.com/krzysdz\"\u003e\u003ccode\u003e@​krzysdz\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/730\"\u003eexpressjs/body-parser#730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.35.3 to 4.36.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/731\"\u003eexpressjs/body-parser#731\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/checkout from 6.0.2 to 6.0.3 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/732\"\u003eexpressjs/body-parser#732\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: updated deps to latest by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/733\"\u003eexpressjs/body-parser#733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e2.3.0 by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/735\"\u003eexpressjs/body-parser#735\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/krzysdz\"\u003e\u003ccode\u003e@​krzysdz\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/730\"\u003eexpressjs/body-parser#730\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/v2.2.2...v2.3.0\"\u003ehttps://github.com/expressjs/body-parser/compare/v2.2.2...v2.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.2.2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocs: update README links by \u003ca href=\"https://github.com/efekrskl\"\u003e\u003ccode\u003e@​efekrskl\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/673\"\u003eexpressjs/body-parser#673\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: release notes for the v1.20.4 release by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/674\"\u003eexpressjs/body-parser#674\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: update URL-encoded parser description to include ISO-8859-1 encoding support by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/679\"\u003eexpressjs/body-parser#679\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: use standard jsdoc tags everywhere by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/677\"\u003eexpressjs/body-parser#677\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/body-parser/blob/master/HISTORY.md\"\u003ebody-parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e2.3.0 / 2026-06-15\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity fix for \u003ca href=\"https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6\"\u003eGHSA-v422-hmwv-36x6\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: use static exports instead of lazy getters to improve ESM compatibility\u003c/li\u003e\n\u003cli\u003efeat: add subpath exports for individual parsers\u003c/li\u003e\n\u003cli\u003efix: improve \u003ccode\u003elimit\u003c/code\u003e option validation (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/698\"\u003e#698\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003eInvalid \u003ccode\u003elimit\u003c/code\u003e values (e.g. unparseable strings or \u003ccode\u003eNaN\u003c/code\u003e) now throw instead of being silently ignored, which previously disabled size limit enforcement\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003enull\u003c/code\u003e and \u003ccode\u003eundefined\u003c/code\u003e fall back to the default 100kb limit\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003edeps:\n\u003cul\u003e\n\u003cli\u003econtent-type@^2.0.0\u003c/li\u003e\n\u003cli\u003ehttp-errors@^2.0.1\u003c/li\u003e\n\u003cli\u003eiconv-lite^0.7.2\u003c/li\u003e\n\u003cli\u003eqs@^6.15.2\u003c/li\u003e\n\u003cli\u003eraw-body@^3.0.2\u003c/li\u003e\n\u003cli\u003etype-is@^2.1.0\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e2.2.2 / 2026-01-07\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003edeps: qs@^6.14.1\u003c/li\u003e\n\u003cli\u003erefactor(json): simplify strict mode error string construction\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/d0f2ace6c74769da7d19b8661b9a01c01bdb0bf7\"\u003e\u003ccode\u003ed0f2ace\u003c/code\u003e\u003c/a\u003e 2.3.0 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/735\"\u003e#735\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/7d03f2f9d561dafd1576b137713353c95253512c\"\u003e\u003ccode\u003e7d03f2f\u003c/code\u003e\u003c/a\u003e chore: updated deps to latest (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/733\"\u003e#733\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/8024ba7a813e6647ed63832d209a2abb8531267a\"\u003e\u003ccode\u003e8024ba7\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/checkout from 6.0.2 to 6.0.3 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/732\"\u003e#732\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/32b4ed4639281f04563adcd41d724ab06c9105d4\"\u003e\u003ccode\u003e32b4ed4\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action from 4.35.3 to 4.36.1 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/731\"\u003e#731\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/ff0f6b907106ec5a1b81c80f5a552d921c1bc9a5\"\u003e\u003ccode\u003eff0f6b9\u003c/code\u003e\u003c/a\u003e docs: update outdated reference to MDN docs (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/730\"\u003e#730\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/14d001a9c90abc05891d895ad3e9cf0a65b7b34a\"\u003e\u003ccode\u003e14d001a\u003c/code\u003e\u003c/a\u003e refactor: switch to const/let and enable eslint no-var rule (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/729\"\u003e#729\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/37f36a27528e65d7216f2c31c7039d3458c72147\"\u003e\u003ccode\u003e37f36a2\u003c/code\u003e\u003c/a\u003e deps: update content-type and type-is (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/728\"\u003e#728\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/e1c244bf55fb00a6de4be882b4ed9fc20807d864\"\u003e\u003ccode\u003ee1c244b\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action from 4.35.1 to 4.35.3 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/723\"\u003e#723\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/e01087f52192e20e2d0f8726d4f28a8d49d06c87\"\u003e\u003ccode\u003ee01087f\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/724\"\u003e#724\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/a7698d30280a3e931ea8841396e5d0ac5414e429\"\u003e\u003ccode\u003ea7698d3\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/setup-node from 6.3.0 to 6.4.0 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/725\"\u003e#725\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/expressjs/body-parser/compare/v2.2.1...v2.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-uri` from 3.1.0 to 3.1.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.0...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `flatted` from 3.3.3 to 3.4.4\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/e6f5ca700c4ca8104a6a83472c8219e267bd5e84\"\u003e\u003ccode\u003ee6f5ca7\u003c/code\u003e\u003c/a\u003e 3.4.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/47f14fac0b1a41989f216b0cda4c50596ca339f6\"\u003e\u003ccode\u003e47f14fa\u003c/code\u003e\u003c/a\u003e removed E_STRICT from PHP\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/40505688464c49fe6374e7bc4cdd9bd2e9e6f330\"\u003e\u003ccode\u003e4050568\u003c/code\u003e\u003c/a\u003e fixced go-lang issues in CI\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/4303f4db38ba0ba8d5e2ed6e9689cefc74c46b63\"\u003e\u003ccode\u003e4303f4d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/WebReflection/flatted/issues/101\"\u003e#101\u003c/a\u003e from mfinelli/gocriticfixes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/106735b609c15df51539a0d7c0a270182efd904c\"\u003e\u003ccode\u003e106735b\u003c/code\u003e\u003c/a\u003e updated package-lock.json\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/670a1bdf9dcfba02111c3034294366f10696fb53\"\u003e\u003ccode\u003e670a1bd\u003c/code\u003e\u003c/a\u003e 3.4.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/50a61a90ea5ca64c114f0aa040ad127e3a97feff\"\u003e\u003ccode\u003e50a61a9\u003c/code\u003e\u003c/a\u003e Fix \u003ca href=\"https://redirect.github.com/WebReflection/flatted/issues/104\"\u003e#104\u003c/a\u003e - allow \u003ccode\u003enull\u003c/code\u003e as replacer value\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/8aa64f460cf0c4dac9cc214c831aade28f8f2c6e\"\u003e\u003ccode\u003e8aa64f4\u003c/code\u003e\u003c/a\u003e solved crytical errors over dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/b85577f39ff85959d02e8862cc0dde8114b43762\"\u003e\u003ccode\u003eb85577f\u003c/code\u003e\u003c/a\u003e Fix go-critic errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/bb8c63cea5befd4315519cb4458c6fc07bb9cf7b\"\u003e\u003ccode\u003ebb8c63c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/WebReflection/flatted/issues/100\"\u003e#100\u003c/a\u003e from WebReflection/WebReflection-patch-1\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/WebReflection/flatted/compare/v3.3.3...v3.4.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `hono` from 4.11.3 to 4.13.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/honojs/hono/releases\"\u003ehono's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.13.7\u003c/h2\u003e\n\u003ch2\u003eSecurity fixes\u003c/h2\u003e\n\u003cp\u003eThis release includes a fix for the following security issue:\u003c/p\u003e\n\u003ch3\u003e\u003ccode\u003ehono/jsx\u003c/code\u003e renders plain strings unescaped in boundary components, leading to XSS\u003c/h3\u003e\n\u003cp\u003eAffects: \u003ccode\u003eSuspense\u003c/code\u003e, \u003ccode\u003eErrorBoundary\u003c/code\u003e, and \u003ccode\u003eContext.Provider\u003c/code\u003e in \u003ccode\u003ehono/jsx\u003c/code\u003e, and \u003ccode\u003erenderToString()\u003c/code\u003e / \u003ccode\u003erenderToReadableStream()\u003c/code\u003e in \u003ccode\u003ehono/jsx/dom/server\u003c/code\u003e. Fixes missing HTML escaping for a plain string placed directly as a child or \u003ccode\u003efallback\u003c/code\u003e of these components, or as the root value of the server rendering functions, so untrusted strings could be emitted as markup. GHSA-hxh3-vqpv-xpqv\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003eUsers who render untrusted strings inside \u003ccode\u003eSuspense\u003c/code\u003e, \u003ccode\u003eErrorBoundary\u003c/code\u003e, or \u003ccode\u003eContext.Provider\u003c/code\u003e, or pass them directly to \u003ccode\u003ehono/jsx/dom/server\u003c/code\u003e, are strongly encouraged to upgrade to this version.\u003c/p\u003e\n\u003ch2\u003ev4.13.6\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(client): keep a param value of \u0026quot;index\u0026quot; in $url() and $path() in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5297\"\u003ehonojs/hono#5297\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(client): normalize root WebSocket URLs in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5291\"\u003ehonojs/hono#5291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(types): allow symbol keys in Context\u003c!-- raw HTML omitted --\u003e get and set fallbacks in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5300\"\u003ehonojs/hono#5300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump \u003ccode\u003eeditorconfig-checker\u003c/code\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5336\"\u003ehonojs/hono#5336\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor(on-handler): use forEach for consistent handler iteration in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5326\"\u003ehonojs/hono#5326\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong...\n\n_Description has been truncated_","html_url":"https://github.com/canstralian/MCPServerforRedTeamAgenticWorkflowszip/pull/6","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/canstralian%2FMCPServerforRedTeamAgenticWorkflowszip/issues/6","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/6/packages"},{"uuid":"5439800891","node_id":"PR_kwDOO7ALIM8AAAABDVKiGg","number":24,"state":"open","title":"chore(deps): bump fast-uri from 3.1.0 to 3.1.7","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-13T11:36:28.000Z","updated_at":"2026-09-13T11:36:35.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"fast-uri","old_version":"3.1.0","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"}],"path":null,"ecosystem":"npm"},"body":"Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.0 to 3.1.7.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.0...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=fast-uri\u0026package-manager=npm_and_yarn\u0026previous-version=3.1.0\u0026new-version=3.1.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/executiveusa/claude-task-master/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/executiveusa/claude-task-master/pull/24","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/executiveusa%2Fclaude-task-master/issues/24","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/24/packages"},{"uuid":"5439774092","node_id":"PR_kwDOQ43m0c8AAAABDVJOtw","number":21,"state":"open","title":"Bump the npm_and_yarn group across 1 directory with 10 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-13T11:30:52.000Z","updated_at":"2026-09-13T11:34:15.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"npm_and_yarn","update_count":10,"packages":[{"name":"next","old_version":"16.2.4","new_version":"16.3.5","repository_url":"https://github.com/vercel/next.js"},{"name":"@babel/core","old_version":"7.29.0","new_version":"7.29.7","repository_url":"https://github.com/babel/babel"},{"name":"@humanfs/node","old_version":"0.16.7","new_version":"0.16.8","repository_url":"https://github.com/humanwhocodes/humanfs"},{"name":"@opentelemetry/core","old_version":"2.6.1","new_version":"2.11.0","repository_url":"https://github.com/open-telemetry/opentelemetry-js"},{"name":"brace-expansion","old_version":"1.1.14","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"fast-uri","old_version":"3.1.0","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"js-yaml","old_version":"4.1.1","new_version":"4.3.2","repository_url":"https://github.com/nodeca/js-yaml"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 7 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [next](https://github.com/vercel/next.js) | `16.2.4` | `16.3.5` |\n| [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) | `7.29.0` | `7.29.7` |\n| [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node) | `0.16.7` | `0.16.8` |\n| [@opentelemetry/core](https://github.com/open-telemetry/opentelemetry-js) | `2.6.1` | `2.11.0` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.14` | `1.1.18` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.0` | `3.1.7` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.1` | `4.3.2` |\n\n\nUpdates `next` from 16.2.4 to 16.3.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003enext's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.5\u003c/h2\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does not include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003enext/image: Skip 0-byte entries when initializing disk LRU cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98185\"\u003e#98185\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enext/image: Reject empty images when reading/writing to the disk cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98186\"\u003e#98186\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEmit whole-app server NFTs when \u003ccode\u003eoutput: 'standalone'\u003c/code\u003e is used with an adapter (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98167\"\u003e#98167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd CSP nonce to script tags of loading and template files (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98403\"\u003e#98403\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003euse cache\u003c/code\u003e prerender signal retention (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98448\"\u003e#98448\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.4\u003c/h2\u003e\n\u003cp\u003eFollow-up release to \u003ca href=\"https://github.com/vercel/next.js/releases/tag/v16.3.3\"\u003ev16.3.3\u003c/a\u003e re-enabling AVIF Image Optimization (\u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97949\"\u003e#97949\u003c/a\u003e).\u003c/p\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003etestmode: Fix infinite recursion in testmode passthrough fetch (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97691\"\u003e#97691\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix build error when aliasing typescript to \u003ccode\u003e@​typescript/typescript6\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97997\"\u003e#97997\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix unset crossOrigin in Turbopack manifests (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97930\"\u003e#97930\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.3\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eCritical:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36\"\u003eUnauthenticated Remote Code Execution on windows-hosted servers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4\"\u003eUnauthenticated Remote Code Execution in Image Optimization API when AVIF files are used\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.2\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Scope app-entry export validation to files inside the app directory (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97357\"\u003e#97357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[backport] Fix catch-all index page being served for every other slug (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97416\"\u003e#97416\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: don't trace embedded WASM loader helpers (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97353\"\u003e#97353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97463\"\u003e#97463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: retain conditions when replacing resolve request keys (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97453\"\u003e#97453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Fix Turbopack worker chunk loading with asset prefix (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97419\"\u003e#97419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97603\"\u003e#97603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/lubieowoce\"\u003e\u003ccode\u003e@​lubieowoce\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[16.x] Turbopack: don't strip async-module runtime from shared runtime chunks by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96653\"\u003evercel/next.js#96653\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/ca2c75eb7f8d9dd012a8bb83c06132149fe221f9\"\u003e\u003ccode\u003eca2c75e\u003c/code\u003e\u003c/a\u003e v16.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/14fb290de65077e9f1e22ef56d8de6cc1e63d436\"\u003e\u003ccode\u003e14fb290\u003c/code\u003e\u003c/a\u003e [backport] Fix use cache prerender signal retention (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98448\"\u003e#98448\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/2b1f28dbe1de344807ec0946a85171bc890a6047\"\u003e\u003ccode\u003e2b1f28d\u003c/code\u003e\u003c/a\u003e [16.3.x] Add CSP nonce to script tags of loading and template files (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98403\"\u003e#98403\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/4b56cee3f01d3b249edcd798b51895d5126a4170\"\u003e\u003ccode\u003e4b56cee\u003c/code\u003e\u003c/a\u003e [16.3.x] Backport docs fixes (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98317\"\u003e#98317\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/5568a02a7d47f9cb088e58350f2c2e68d9e93a00\"\u003e\u003ccode\u003e5568a02\u003c/code\u003e\u003c/a\u003e [backport] docs: local development: Rewrite docker section, add Windows Dev D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/93249ab2144132abfd4a8d611dad5b5978107ee2\"\u003e\u003ccode\u003e93249ab\u003c/code\u003e\u003c/a\u003e [16.3.X] Emit whole-app server NFTs when \u003ccode\u003eoutput: 'standalone'\u003c/code\u003e is used with ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/6549fd7c4e15a8883b0ad1c2ef67dec287a44f12\"\u003e\u003ccode\u003e6549fd7\u003c/code\u003e\u003c/a\u003e [16.3.x] next/image: reject empty image on read/write to disk cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98186\"\u003e#98186\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/d9eac96e7526ff0b9cb51db9801f06e741fe1960\"\u003e\u003ccode\u003ed9eac96\u003c/code\u003e\u003c/a\u003e [16.3.x] next/image: skip 0-byte entries when initializing disk LRU cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/9\"\u003e#9\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/84b35feccb2b53a563e41ad2dfe7a5fe08c58d3f\"\u003e\u003ccode\u003e84b35fe\u003c/code\u003e\u003c/a\u003e [test] Fix 16.3 deploy test assertions (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98133\"\u003e#98133\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/14f9c1ac4e084a44633c354476ddeaf70969cd90\"\u003e\u003ccode\u003e14f9c1a\u003c/code\u003e\u003c/a\u003e [16.3.x][ci] Run flake detection and new deploy tests when merged and on back...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/compare/v16.2.4...v16.3.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for next since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@babel/core` from 7.29.0 to 7.29.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/babel/babel/releases\"\u003e@​babel/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.7 (2026-05-25)\u003c/h2\u003e\n\u003cp\u003eRe-release all packages with npm provenance attestations\u003c/p\u003e\n\u003ch2\u003ev7.29.6 (2026-05-25)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18014\"\u003e#18014\u003c/a\u003e Catchup source map position in preserveFormat (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18001\"\u003e#18001\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e, \u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17998\"\u003e#17998\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 3\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMateusz Burzyński (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.5 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:house:  Internal\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@babel/*\u003c/code\u003e dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.4 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17974\"\u003e#17974\u003c/a\u003e [7.x backport]fix(systemjs): improve module string name support (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 1\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.3 (2026-04-30)\u003c/h2\u003e\n\u003ch4\u003e:eyeglasses: Spec Compliance\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17923\"\u003e#17923\u003c/a\u003e Support flow extends bound (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-helper-create-class-features-plugin\u003c/code\u003e, \u003ccode\u003ebabel-plugin-proposal-decorators\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17931\"\u003e#17931\u003c/a\u003e fix(decorators): replace super within all removed static elements (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-register\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17915\"\u003e#17915\u003c/a\u003e Fix thread synchronization issues in \u003ccode\u003e@babel/register\u003c/code\u003e (\u003ca href=\"https://github.com/liuxingbaoyu\"\u003e\u003ccode\u003e@​liuxingbaoyu\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-compat-data\u003c/code\u003e, \u003ccode\u003ebabel-plugin-bugfix-safari-rest-destructuring-rhs-array\u003c/code\u003e, \u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17788\"\u003e#17788\u003c/a\u003e Add bugfix plugin for Safari array rest destructuring bug (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:nail_care: Polish\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/4fba7541180bf5f58256d8e358b544e3831ad090\"\u003e\u003ccode\u003e4fba754\u003c/code\u003e\u003c/a\u003e v7.29.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/04ea6b27fdac8f40c3481aec2080ac9678779509\"\u003e\u003ccode\u003e04ea6b2\u003c/code\u003e\u003c/a\u003e v7.29.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/99f498a9b9fa0b900d603fbe8f6601bb3b9e42bb\"\u003e\u003ccode\u003e99f498a\u003c/code\u003e\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/18001\"\u003e#18001\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/feba0a3654c596bd369d1ef1231f5d56666d56dc\"\u003e\u003ccode\u003efeba0a3\u003c/code\u003e\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17998\"\u003e#17998\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/babel/babel/commits/v7.29.7/packages/babel-core\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@humanfs/node` from 0.16.7 to 0.16.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/humanwhocodes/humanfs/releases\"\u003e@​humanfs/node's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003enode: v0.16.8\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/compare/node-v0.16.7...node-v0.16.8\"\u003e0.16.8\u003c/a\u003e (2026-04-17)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eInclude type dependencies at runtime (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e956ce7a\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/humanwhocodes/humanfs/issues/145\"\u003e#145\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe following workspace dependencies were updated\n\u003cul\u003e\n\u003cli\u003edependencies\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​humanfs/core\u003c/code\u003e bumped from ^0.19.1 to ^0.19.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/humanwhocodes/humanfs/blob/main/packages/node/CHANGELOG.md\"\u003e@​humanfs/node's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/compare/node-v0.16.7...node-v0.16.8\"\u003e0.16.8\u003c/a\u003e (2026-04-17)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEnsure symlinks are copied as symlinks in \u003ccode\u003ecopy()\u003c/code\u003e and \u003ccode\u003ecopyAll()\u003c/code\u003e (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/22bbaa4487a3e6c1197ca619840de4615d0c3404\"\u003e22bbaa44\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eInclude type dependencies at runtime (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e956ce7a\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/humanwhocodes/humanfs/issues/145\"\u003e#145\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe following workspace dependencies were updated\n\u003cul\u003e\n\u003cli\u003edependencies\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​humanfs/core\u003c/code\u003e bumped from ^0.19.1 to ^0.19.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/e96070e897f017ae8abd2b0676d98d14e49665cc\"\u003e\u003ccode\u003ee96070e\u003c/code\u003e\u003c/a\u003e chore: release main (\u003ca href=\"https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node/issues/146\"\u003e#146\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/22bbaa4487a3e6c1197ca619840de4615d0c3404\"\u003e\u003ccode\u003e22bbaa4\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e\u003ccode\u003e956ce7a\u003c/code\u003e\u003c/a\u003e fix: Include type dependencies at runtime\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/humanwhocodes/humanfs/commits/node-v0.16.8/packages/node\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@opentelemetry/core` from 2.6.1 to 2.11.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/releases\"\u003e@​opentelemetry/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.11.0\u003c/h2\u003e\n\u003ch2\u003e2.11.0\u003c/h2\u003e\n\u003ch3\u003e:rocket: Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(context-async-hooks): implement \u003ccode\u003eattach()\u003c/code\u003e on \u003ccode\u003eAsyncLocalStorageContextManager\u003c/code\u003e \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6845\"\u003e#6845\u003c/a\u003e \u003ca href=\"https://github.com/pichlermarc\"\u003e\u003ccode\u003e@​pichlermarc\u003c/code\u003e\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003eOn Node.js 25.9+, delegates to \u003ccode\u003eAsyncLocalStorage.withScope()\u003c/code\u003e returning a native \u003ccode\u003eRunScope\u003c/code\u003e. On older Node.js, falls back to \u003ccode\u003eenterWith()\u003c/code\u003e with a manual disposable wrapper.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003efeat(sdk-trace): allow configuring the force flush timeout per call \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6929\"\u003e#6929\u003c/a\u003e \u003ca href=\"https://github.com/LarryHu0217\"\u003e\u003ccode\u003e@​LarryHu0217\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(sdk-metrics): ignore \u003ccode\u003eInfinity\u003c/code\u003e in exponential histograms \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/7015\"\u003e#7015\u003c/a\u003e \u003ca href=\"https://github.com/mwear\"\u003e\u003ccode\u003e@​mwear\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:house: Internal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eperf(sdk-metrics): reuse a single DataView for exponential histogram bit reads \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6998\"\u003e#6998\u003c/a\u003e \u003ca href=\"https://github.com/mwear\"\u003e\u003ccode\u003e@​mwear\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(ci): run documentation tests on a weekly schedule \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6920\"\u003e#6920\u003c/a\u003e \u003ca href=\"https://github.com/LarryHu0217\"\u003e\u003ccode\u003e@​LarryHu0217\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(ci): support pre-releases and major version bumps in the release workflow \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6768\"\u003e#6768\u003c/a\u003e \u003ca href=\"https://github.com/pichlermarc\"\u003e\u003ccode\u003e@​pichlermarc\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(resources): Ensure that multiple uses of serviceInstanceIdDetector.detect() return the \u003cem\u003esame\u003c/em\u003e value for \u003ccode\u003eservice.instance.id\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.10.0\u003c/h2\u003e\n\u003ch2\u003e2.10.0\u003c/h2\u003e\n\u003ch3\u003e:rocket: Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(sdk-logs): implement log processor metrics \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6554\"\u003e#6554\u003c/a\u003e \u003ca href=\"https://github.com/anuraaga\"\u003e\u003ccode\u003e@​anuraaga\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(otlp-exporter): implement exporter metrics \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6480\"\u003e#6480\u003c/a\u003e \u003ca href=\"https://github.com/anuraaga\"\u003e\u003ccode\u003e@​anuraaga\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(propagator-jaeger):  \u003cem\u003eNotice\u003c/em\u003e: The \u003ccode\u003e@opentelemetry/propagator-jaeger\u003c/code\u003e package will be removed in SDK 3.x, planned for approximately September 2026. \u003ca href=\"https://github.com/pichlermarc\"\u003e\u003ccode\u003e@​pichlermarc\u003c/code\u003e\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003eThe Jaeger propagator has been deprecated by the OpenTelemetry specification in favor of \u003ccode\u003eW3CTraceContextPropagator\u003c/code\u003e. This package will be removed in a future release.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(sdk-trace): reject \u003ccode\u003eSimpleSpanProcessor.forceFlush()\u003c/code\u003e when a pending export fails \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6771\"\u003e#6771\u003c/a\u003e \u003ca href=\"https://github.com/LarryHu0217\"\u003e\u003ccode\u003e@​LarryHu0217\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(sdk-trace): include trace IDs at the ratio 1 upper bound in \u003ccode\u003eTraceIdRatioBasedSampler\u003c/code\u003e \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6890\"\u003e#6890\u003c/a\u003e \u003ca href=\"https://github.com/LarryHu0217\"\u003e\u003ccode\u003e@​LarryHu0217\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:house: Internal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003echore: build on Node 26 in CI \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6887\"\u003e#6887\u003c/a\u003e \u003ca href=\"https://github.com/overbalance\"\u003e\u003ccode\u003e@​overbalance\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump to typescript@5.2.2 \u003ca href=\"https://github.com/pichlermarc\"\u003e\u003ccode\u003e@​pichlermarc\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.9.0\u003c/h2\u003e\n\u003ch2\u003e2.9.0\u003c/h2\u003e\n\u003ch3\u003e:boom: Breaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003edocs(shim-opentracing): \u003cem\u003eNotice\u003c/em\u003e: The \u003ccode\u003e@opentelemetry/shim-opentracing\u003c/code\u003e package will be removed in SDK 3.x, planned for approximately September 2026.\n\u003cul\u003e\n\u003cli\u003eThe \u003ca href=\"https://opentelemetry.io/blog/2026/deprecating-opencensus-compatibility/\"\u003eOpenCensus\u003c/a\u003e and \u003ca href=\"https://opentelemetry.io/blog/2026/deprecating-opentracing-compatibility/\"\u003eOpenTracing\u003c/a\u003e compatibility requirements in the OpenTelemetry specification have been deprecated.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md\"\u003e@​opentelemetry/core's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.11.0\u003c/h2\u003e\n\u003ch3\u003e:rocket: Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(context-async-hooks): implement \u003ccode\u003eattach()\u003c/code\u003e on \u003ccode\u003eAsyncLocalStorageContextManager\u003c/code\u003e \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6845\"\u003e#6845\u003c/a\u003e \u003ca href=\"https://github.com/pichlermarc\"\u003e\u003ccode\u003e@​pichlermarc\u003c/code\u003e\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003eOn Node.js 25.9+, delegates to \u003ccode\u003eAsyncLocalStorage.withScope()\u003c/code\u003e returning a native \u003ccode\u003eRunScope\u003c/code\u003e. On older Node.js, falls back to \u003ccode\u003eenterWith()\u003c/code\u003e with a manual disposable wrapper.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003efeat(sdk-trace): allow configuring the force flush timeout per call \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6929\"\u003e#6929\u003c/a\u003e \u003ca href=\"https://github.com/LarryHu0217\"\u003e\u003ccode\u003e@​LarryHu0217\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(sdk-trace-base): avoid a Webpack self-reference error in CommonJS output \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6981\"\u003e#6981\u003c/a\u003e \u003ca href=\"https://github.com/sansynx\"\u003e\u003ccode\u003e@​sansynx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(sdk-metrics): ignore \u003ccode\u003eInfinity\u003c/code\u003e in exponential histograms \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/7015\"\u003e#7015\u003c/a\u003e \u003ca href=\"https://github.com/mwear\"\u003e\u003ccode\u003e@​mwear\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:house: Internal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eperf(sdk-metrics): reuse a single DataView for exponential histogram bit reads \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6998\"\u003e#6998\u003c/a\u003e \u003ca href=\"https://github.com/mwear\"\u003e\u003ccode\u003e@​mwear\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(ci): run documentation tests on a weekly schedule \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6920\"\u003e#6920\u003c/a\u003e \u003ca href=\"https://github.com/LarryHu0217\"\u003e\u003ccode\u003e@​LarryHu0217\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(ci): support pre-releases and major version bumps in the release workflow \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6768\"\u003e#6768\u003c/a\u003e \u003ca href=\"https://github.com/pichlermarc\"\u003e\u003ccode\u003e@​pichlermarc\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(resources): Ensure that multiple uses of serviceInstanceIdDetector.detect() return the \u003cem\u003esame\u003c/em\u003e value for \u003ccode\u003eservice.instance.id\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.10.0\u003c/h2\u003e\n\u003ch3\u003e:rocket: Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(sdk-logs): implement log processor metrics \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6554\"\u003e#6554\u003c/a\u003e \u003ca href=\"https://github.com/anuraaga\"\u003e\u003ccode\u003e@​anuraaga\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(otlp-exporter): implement exporter metrics \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6480\"\u003e#6480\u003c/a\u003e \u003ca href=\"https://github.com/anuraaga\"\u003e\u003ccode\u003e@​anuraaga\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(propagator-jaeger):  \u003cem\u003eNotice\u003c/em\u003e: The \u003ccode\u003e@opentelemetry/propagator-jaeger\u003c/code\u003e package will be removed in SDK 3.x, planned for approximately September 2026. \u003ca href=\"https://github.com/pichlermarc\"\u003e\u003ccode\u003e@​pichlermarc\u003c/code\u003e\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003eThe Jaeger propagator has been deprecated by the OpenTelemetry specification in favor of \u003ccode\u003eW3CTraceContextPropagator\u003c/code\u003e. This package will be removed in a future release.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(sdk-trace): reject \u003ccode\u003eSimpleSpanProcessor.forceFlush()\u003c/code\u003e when a pending export fails \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6771\"\u003e#6771\u003c/a\u003e \u003ca href=\"https://github.com/LarryHu0217\"\u003e\u003ccode\u003e@​LarryHu0217\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(sdk-trace): include trace IDs at the ratio 1 upper bound in \u003ccode\u003eTraceIdRatioBasedSampler\u003c/code\u003e \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6890\"\u003e#6890\u003c/a\u003e \u003ca href=\"https://github.com/LarryHu0217\"\u003e\u003ccode\u003e@​LarryHu0217\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:house: Internal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003echore: build on Node 26 in CI \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6887\"\u003e#6887\u003c/a\u003e \u003ca href=\"https://github.com/overbalance\"\u003e\u003ccode\u003e@​overbalance\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump to typescript@5.2.2 \u003ca href=\"https://github.com/pichlermarc\"\u003e\u003ccode\u003e@​pichlermarc\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.9.0\u003c/h2\u003e\n\u003ch3\u003e:boom: Breaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003edocs(shim-opentracing): \u003cem\u003eNotice\u003c/em\u003e: The \u003ccode\u003e@opentelemetry/shim-opentracing\u003c/code\u003e package will be removed in SDK 3.x, planned for approximately September 2026.\n\u003cul\u003e\n\u003cli\u003eThe \u003ca href=\"https://opentelemetry.io/blog/2026/deprecating-opencensus-compatibility/\"\u003eOpenCensus\u003c/a\u003e and \u003ca href=\"https://opentelemetry.io/blog/2026/deprecating-opentracing-compatibility/\"\u003eOpenTracing\u003c/a\u003e compatibility requirements in the OpenTelemetry specification have been deprecated.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:rocket: Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(sdk-metrics): add maxExportBatchSize option to PeriodicExportingMetricReader \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6655\"\u003e#6655\u003c/a\u003e \u003ca href=\"https://github.com/psx95\"\u003e\u003ccode\u003e@​psx95\u003c/code\u003e\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003eOptimized \u003ccode\u003ePeriodicExportingMetricReader.forceFlush\u003c/code\u003e to prevent redundant concurrent export cycles. Concurrent calls to forceFlush will now await any ongoing export and reuse a fresh export cycle if one is started concurrently by another caller. This ensures the latest metrics are always exported efficiently without triggering duplicate collection and export cycles.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/0b72a81636fa476e8f1f1afd2ae0c90a1362194c\"\u003e\u003ccode\u003e0b72a81\u003c/code\u003e\u003c/a\u003e chore: prepare next release (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/7044\"\u003e#7044\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/a9c5338a9f485f1433df9308f24bd7397a4a0321\"\u003e\u003ccode\u003ea9c5338\u003c/code\u003e\u003c/a\u003e ci: roll prerelease changelog into one final release changelog (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/7045\"\u003e#7045\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/f41805e769ba10fb6dae72a4b7a5a3dc67cca82e\"\u003e\u003ccode\u003ef41805e\u003c/code\u003e\u003c/a\u003e chore: prepare next release (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/7042\"\u003e#7042\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/b85eb28343ff6234e2bb4d46b7b4a3d360e5ea2f\"\u003e\u003ccode\u003eb85eb28\u003c/code\u003e\u003c/a\u003e chore(instrumentation-http): fix lint errors (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/7039\"\u003e#7039\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/3f9253009be2ae48419432e79a597ead7be8be6a\"\u003e\u003ccode\u003e3f92530\u003c/code\u003e\u003c/a\u003e ci: support pre-releases and major version bumps in release workflow (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/7035\"\u003e#7035\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/82a58316a63b6fde62afd268e145b82222d328cf\"\u003e\u003ccode\u003e82a5831\u003c/code\u003e\u003c/a\u003e docs(otlp-exporter-base): document HTTP exporter options (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6735\"\u003e#6735\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/e086dec7f9304107ef6d50b5877be88895c06aa7\"\u003e\u003ccode\u003ee086dec\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/59dac70d00d46fa56b2b921cf721fd922730f23d\"\u003e\u003ccode\u003e59dac70\u003c/code\u003e\u003c/a\u003e chore(deps): update jamesives/github-pages-deploy-action action to v4.9.0 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/7\"\u003e#7\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/d0ce7532b058631ec9eec111c04fefe7fd873e1f\"\u003e\u003ccode\u003ed0ce753\u003c/code\u003e\u003c/a\u003e chore: add \u003ca href=\"https://github.com/maryliag\"\u003e\u003ccode\u003e@​maryliag\u003c/code\u003e\u003c/a\u003e to maintainers (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/7024\"\u003e#7024\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/03469a129f97265c8eec93d566e9e00d4f741db3\"\u003e\u003ccode\u003e03469a1\u003c/code\u003e\u003c/a\u003e chore(deps): update open-telemetry/shared-workflows action to v0.10.0 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/7032\"\u003e#7032\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/compare/v2.6.1...v2.11.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.14 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24\"\u003e\u003ccode\u003e2203f4f\u003c/code\u003e\u003c/a\u003e 1.1.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd\"\u003e\u003ccode\u003e0b09384\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-uri` from 3.1.0 to 3.1.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.0...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `js-yaml` from 4.1.1 to 4.3.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md\"\u003ejs-yaml's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.3.2 - 2026-08-26\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Hard-limit merge sequence size to 100.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Count empty mappings in merge sequences toward \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e\nto limit CPU usage, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/797\"\u003e#797\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.3.1 - 2026-07-31\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Remove quadratic complexity from \u003ccode\u003e!!omap\u003c/code\u003e duplicate key detection.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.3.0 - 2026-06-27\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Added \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e (10000) loader option to limit the total number of\nkeys processed by YAML merge (\u003ccode\u003e\u0026lt;\u0026lt;\u003c/code\u003e) across one \u003ccode\u003eload()\u003c/code\u003e / \u003ccode\u003eloadAll()\u003c/code\u003e call.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRestore umd builds back to es5.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRemoved\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e replaced with \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e for limiting YAML merge\nprocessing.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[4.2.0] - 2026-06-01\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003edocs/safety.md\u003c/code\u003e with notes about processing untrusted YAML.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003emaxDepth\u003c/code\u003e (100) loader option. Not a problem, but gives a better\nexception instead of RangeError on stack overflow.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e (20) loader option. Not a problem after \u003ccode\u003emerge\u003c/code\u003e fix,\nbut an additional restriction for safety.\u003c/li\u003e\n\u003cli\u003eAdded sourcemaps to \u003ccode\u003edist/\u003c/code\u003e builds.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStop resolving numbers with underscores as numeric scalars, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/627\"\u003e#627\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eSwitched dev toolchains to Vite / neostandard.\u003c/li\u003e\n\u003cli\u003eUpdated demo.\u003c/li\u003e\n\u003cli\u003eReorganized tests.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edist/\u003c/code\u003e files are no longer kept in the repository.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix parsing of properties on the first implicit block mapping key, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/62\"\u003e#62\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix trailing whitespace handling when folding flow scalar lines, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/307\"\u003e#307\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eReject top-level block scalars without content indentation, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/280\"\u003e#280\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eEnsure numbers survive round-trip, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/737\"\u003e#737\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix test coverage for issue \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/221\"\u003e#221\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix flow scalar trailing whitespace folding, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/307\"\u003e#307\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/79ca68d90f333fbe6d9e42827527e62636200191\"\u003e\u003ccode\u003e79ca68d\u003c/code\u003e\u003c/a\u003e 4.3.2 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/d90b6612a5a84385bdcb556c44578eac76dc0f6b\"\u003e\u003ccode\u003ed90b661\u003c/code\u003e\u003c/a\u003e Backport merge limits from v5.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/86e91b815b8794c3c73a179c1770871e37ec2df8\"\u003e\u003ccode\u003e86e91b8\u003c/code\u003e\u003c/a\u003e 4.3.1 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/c3cc4b0bb9ddb9af2dd9b61e0d56f5ce7983cd4a\"\u003e\u003ccode\u003ec3cc4b0\u003c/code\u003e\u003c/a\u003e Backport quadratic complexity fix for !!omap\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/33d05b5d29a8c21360f620f7e1c1706e24522eda\"\u003e\u003ccode\u003e33d05b5\u003c/code\u003e\u003c/a\u003e 4.3.0 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/663bfab6db2b4a146a9366fd685f069345be4ddb\"\u003e\u003ccode\u003e663bfab\u003c/code\u003e\u003c/a\u003e Drop demo publish, to not override new v5 one.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/1cb8c7b94bf75e15116869c1c0482dcb22785986\"\u003e\u003ccode\u003e1cb8c7b\u003c/code\u003e\u003c/a\u003e Add v4-legacy tag for publish\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/02f27afad532763263cd2b6be35c24ee8e1f6157\"\u003e\u003ccode\u003e02f27af\u003c/code\u003e\u003c/a\u003e Restore umd builds back to es5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/8be84edaf15e7c394fa3b813179d1bcc280e87fb\"\u003e\u003ccode\u003e8be84ed\u003c/code\u003e\u003c/a\u003e Fix es5 compatibility\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/59423c6f8cdc78742ac00e25a4dd39ef16b702e4\"\u003e\u003ccode\u003e59423c6\u003c/code\u003e\u003c/a\u003e Replace \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e option with \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e (more robust). Ba...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodeca/js-yaml/compare/4.1.1...4.3.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nanoid` from 3.3.11 to 3.3.19\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/releases\"\u003enanoid's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed breaking Nano ID by requesting big ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/blob/main/CHANGELOG.md\"\u003enanoid's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID (by \u003ca href=\"https://github.com/geoffrey-diederichs\"\u003e\u003ccode\u003e@​geoffrey-diederichs\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed breaking Nano ID by requesting big ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/eb63bd6775188dc35d143bf24868be094f19b5ee\"\u003e\u003ccode\u003eeb63bd6\u003c/code\u003e\u003c/a\u003e Release 3.3.19 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9067e0361a643ab2c94ddd67606efbf275f6c0dd\"\u003e\u003ccode\u003e9067e03\u003c/code\u003e\u003c/a\u003e Sync CJS and ESM\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9ad98052b316c5e707f8098ace509d2ae165e54d\"\u003e\u003ccode\u003e9ad9805\u003c/code\u003e\u003c/a\u003e Release 3.3.18 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/55e50a0621ec084b4bb4000ea4e86e1191bd3da8\"\u003e\u003ccode\u003e55e50a0\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e10f8d40ce9d1ab47f66d65a16b48086432730d0\"\u003e\u003ccode\u003ee10f8d4\u003c/code\u003e\u003c/a\u003e Update index.native.js (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/606\"\u003e#606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/73d67168136b36fd3b644159b0cff149da4905d9\"\u003e\u003ccode\u003e73d6716\u003c/code\u003e\u003c/a\u003e Release 3.3.17 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/f9d13f150847d117877adee3460a46eceb0cf49b\"\u003e\u003ccode\u003ef9d13f1\u003c/code\u003e\u003c/a\u003e Sync 0 size behaviour with PostCSS 5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9760e112757cf7d46a79abd7a133bc4958757bb8\"\u003e\u003ccode\u003e9760e11\u003c/code\u003e\u003c/a\u003e Release 3.3.16 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66d\"\u003e\u003ccode\u003ee835c9b\u003c/code\u003e\u003c/a\u003e fix(non-secure): clamp negative size to prevent infinite loop (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/601\"\u003e#601\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/96dd086eb24396a275fa93ee78d73b2fece35809\"\u003e\u003ccode\u003e96dd086\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ai/nanoid/compare/3.3.11...3.3.19\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for nanoid since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.4.31 to 8.5.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003epostcss-scss\u003c/code\u003e commend regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed reading any file via user-generated CSS.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eopts.unsafeMap\u003c/code\u003e to disable checks.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed nested brackets parsing performance (by \u003ca href=\"https://github.com/offset\"\u003e\u003ccode\u003e@​offset\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.10\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed XSS via unescaped \u003ccode\u003e\u0026lt;/style\u0026gt;\u003c/code\u003e in non-bundler cases (by \u003ca href=\"https://github.com/TharVid\"\u003e\u003ccode\u003e@​TharVid\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8\"\u003e\u003ccode\u003e7beca13\u003c/code\u003e\u003c/a\u003e Does no load source map file without opts.from\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/decea51421682341401575b3740709fda0e12930\"\u003e\u003ccode\u003edecea51\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/c18e30d126395d42a0726aa00e03a8f1088985ae\"\u003e\u003ccode\u003ec18e30d\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/98a39ad73d163a90be924d5126c771262110f1fc\"\u003e\u003ccode\u003e98a39ad\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/a3e48c492ddec0e4879d513b8b995fee887af352\"\u003e\u003ccode\u003ea3e48c4\u003c/code\u003e\u003c/a\u003e Release 8.5.22 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f49d6911795f53b2cfe023bb686bf1144ec30618\"\u003e\u003ccode\u003ef49d691\u003c/code\u003e\u003c/a\u003e Fix custom property losing its semicolon before a comment (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2117\"\u003e#2117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/28e0daf8f2fe5ba9e19ea3f8c27c8fe176f9419e\"\u003e\u003ccode\u003e28e0daf\u003c/code\u003e\u003c/a\u003e Release 8.5.21 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3d2b4e43e38274f233b5609d09687cadad8215d9\"\u003e\u003ccode\u003e3d2b4e4\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.4.31...8.5.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `sharp` from 0.34.5 to 0.35.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lovell/sharp/releases\"\u003esharp's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.35.4\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\"\u003ehttps://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.35.4-rc.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpgrade to libvips v8.18.6 for upstream bug fixes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7f1a0a22cc285fe180766f4935d50b55af6e8432\"\u003e\u003ccode\u003e7f1a0a2\u003c/code\u003e\u003c/a\u003e Release v0.35.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/f927818924bc5a9493d822a4e8b23ec5857c52e1\"\u003e\u003ccode\u003ef927818\u003c/code\u003e\u003c/a\u003e Upgrade to sharp-libvips v1.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e80209240d005c71e1173a50dd9cd4db4ce2a9e6\"\u003e\u003ccode\u003ee802092\u003c/code\u003e\u003c/a\u003e Prerelease v0.35.4-rc.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e13eb2f97a0a22f1ef726e8d0cd33f7c56835945\"\u003e\u003ccode\u003ee13eb2f\u003c/code\u003e\u003c/a\u003e CI: Fix wasm32 build (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4589\"\u003e#4589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/a82a0b3d58bc25854ad1e925e6eb0a50725d1489\"\u003e\u003ccode\u003ea82a0b3\u003c/code\u003e\u003c/a\u003e Upgrade to libvips v8.18.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/8044fe43e36d0ea7f8beb89f79a37bb0f3342e84\"\u003e\u003ccode\u003e8044fe4\u003c/code\u003e\u003c/a\u003e Bound resize dimensions to coordinate limit\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/147f8591a153bc4a1e199c3fe3150fac2931b30c\"\u003e\u003ccode\u003e147f859\u003c/code\u003e\u003c/a\u003e Docs: changelog entries for \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4578\"\u003e#4578\u003c/a\u003e \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ee5bfb853de75a611c64381783b04032a3a897d8\"\u003e\u003ccode\u003eee5bfb8\u003c/code\u003e\u003c/a\u003e Tests: use yauzl directly rather than via extract-zip wrapper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7a7788928f8a2a429f45039010a87cee35401694\"\u003e\u003ccode\u003e7a77889\u003c/code\u003e\u003c/a\u003e Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4588\"\u003e#4588\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ea5bef24c187b2c7ee3fe3cad3b45c8cb67a46fd\"\u003e\u003ccode\u003eea5bef2\u003c/code\u003e\u003c/a\u003e Improve support for input Streams finishing before output is requested (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/lovell/sharp/compare/v0.34.5...v0.35.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/KryssNa/utilbyte/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/KryssNa/utilbyte/pull/21","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/KryssNa%2Futilbyte/issues/21","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/21/packages"},{"uuid":"5439439227","node_id":"PR_kwDOQRS3g88AAAABDU5SyQ","number":558,"state":"closed","title":"chore(deps): bump the npm_and_yarn group across 1 directory with 12 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-13T12:06:08.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-13T10:10:48.000Z","updated_at":"2026-09-13T12:06:10.000Z","time_to_close":6920,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":12,"packages":[{"name":"baseline-browser-mapping","old_version":"2.10.40","new_version":"2.11.23","repository_url":"https://github.com/web-platform-dx/baseline-browser-mapping"},{"name":"body-parser","old_version":"1.20.5","new_version":"1.20.8","repository_url":"https://github.com/expressjs/body-parser"},{"name":"brace-expansion","old_version":"2.1.1","new_version":"2.1.4","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"browserslist","old_version":"4.28.4","new_version":"4.28.9","repository_url":"https://github.com/browserslist/browserslist"},{"name":"colord","old_version":"2.9.3","new_version":"2.10.0","repository_url":"https://github.com/omgovich/colord"},{"name":"fast-uri","old_version":"3.1.2","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"joi","old_version":"17.13.4","new_version":"17.13.8","repository_url":"https://github.com/hapijs/joi"},{"name":"nanoid","old_version":"3.3.12","new_version":"3.3.19","repository_url":"https://github.com/ai/nanoid"},{"name":"postcss","old_version":"8.5.15","new_version":"8.5.28","repository_url":"https://github.com/postcss/postcss"},{"name":"shell-quote","old_version":"1.8.4","new_version":"1.10.0","repository_url":"https://github.com/ljharb/shell-quote"},{"name":"svgo","old_version":"3.3.3","new_version":"3.3.5","repository_url":"https://github.com/svg/svgo"},{"name":"undici","old_version":"7.28.0","new_version":"7.29.1","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 12 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) | `2.10.40` | `2.11.23` |\n| [body-parser](https://github.com/expressjs/body-parser) | `1.20.5` | `1.20.8` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `2.1.1` | `2.1.4` |\n| [browserslist](https://github.com/browserslist/browserslist) | `4.28.4` | `4.28.9` |\n| [colord](https://github.com/omgovich/colord) | `2.9.3` | `2.10.0` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.2` | `3.1.7` |\n| [joi](https://github.com/hapijs/joi) | `17.13.4` | `17.13.8` |\n| [nanoid](https://github.com/ai/nanoid) | `3.3.12` | `3.3.19` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.15` | `8.5.28` |\n| [shell-quote](https://github.com/ljharb/shell-quote) | `1.8.4` | `1.10.0` |\n| [svgo](https://github.com/svg/svgo) | `3.3.3` | `3.3.5` |\n| [undici](https://github.com/nodejs/undici) | `7.28.0` | `7.29.1` |\n\n\nUpdates `baseline-browser-mapping` from 2.10.40 to 2.11.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/releases\"\u003ebaseline-browser-mapping's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.11.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed in 2.11.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: Adds a new \u003ccode\u003egetTimeline()\u003c/code\u003e method for getting the series of minimum browser changes, either grouped by date or by browser.\u003c/li\u003e\n\u003cli\u003erefactor: Substantial refactoring of the data compression process that replaces the full list of browsers from \u003ccode\u003e@mdn/browser-compat-data\u003c/code\u003e and \u003ccode\u003edownstream-browsers.json\u003c/code\u003e and features from \u003ccode\u003eweb-features\u003c/code\u003e (in their very pared down form) with a change-list timeline that reflects which versions supported Baseline (newly available) on a given date.  Thanks to \u003ca href=\"https://github.com/swwind\"\u003e\u003ccode\u003e@​swwind\u003c/code\u003e\u003c/a\u003e for the idea!\u003c/li\u003e\n\u003cli\u003erefactor: Some common functions have been moved to a \u003ccode\u003eutil.ts\u003c/code\u003e module for use in other scripts.\u003c/li\u003e\n\u003cli\u003efix: Removes \u003ccode\u003eprocess.exit()\u003c/code\u003e calls when unsupported option combinations are passed to getCompatibleVersions() and \u003ccode\u003egetAllVersions()\u003c/code\u003e in favour of throwing an \u003ccode\u003eError\u003c/code\u003e.  There is a small security risk with \u003ccode\u003eprocess.exit()\u003c/code\u003e calls that sites accepting unsanitised inputs could be the subject of attacks.  Unsupported config options now throw and Error which should allow for more graceful handling.  Thanks to \u003ca href=\"https://github.com/bnbdr\"\u003e\u003ccode\u003e@​bnbdr\u003c/code\u003e\u003c/a\u003e for flagging this as vulnerability CVE-2026-45819 .\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFixes \u003ca href=\"https://redirect.github.com/web-platform-dx/baseline-browser-mapping/issues/134\"\u003e#134\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.10.44...v2.11.0\"\u003ehttps://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.10.44...v2.11.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/ebdc72f5637922808cfe1fbf9e67897ba9f89677\"\u003e\u003ccode\u003eebdc72f\u003c/code\u003e\u003c/a\u003e Patch to 2.11.23 because browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/55fa3a1503097faad7a9806d6c08029a36cb19e3\"\u003e\u003ccode\u003e55fa3a1\u003c/code\u003e\u003c/a\u003e Browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/5ac60db1f4eedbd9b61dfa6db0cab10cccc19c2a\"\u003e\u003ccode\u003e5ac60db\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/af7c3c4ebc2692844e521fada6c8d49250795f10\"\u003e\u003ccode\u003eaf7c3c4\u003c/code\u003e\u003c/a\u003e Patch to 2.11.22 because browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/7e10cadb03c00cb5eab538d62b6d16511cd93841\"\u003e\u003ccode\u003e7e10cad\u003c/code\u003e\u003c/a\u003e Browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/ebb97027ff15d916e66b02feb9e019d8c7bab081\"\u003e\u003ccode\u003eebb9702\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/ecc57a365d502e0c85574e45751c1b7475689936\"\u003e\u003ccode\u003eecc57a3\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/0e5ed80e21dda23cac3dc1f6ec37e6b5fc4ea734\"\u003e\u003ccode\u003e0e5ed80\u003c/code\u003e\u003c/a\u003e Patch to 2.11.21 because browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/11da0b699d6d03a1e30b37a8fe7a4f8d96e06f4d\"\u003e\u003ccode\u003e11da0b6\u003c/code\u003e\u003c/a\u003e Browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/69fcc81987ecc7dbbf4d21e17be8c4adf642aa2b\"\u003e\u003ccode\u003e69fcc81\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.10.40...v2.11.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `body-parser` from 1.20.5 to 1.20.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/body-parser/releases\"\u003ebody-parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.20.8\u003c/h2\u003e\n\u003ch2\u003eImportant\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eSame code base as \u003ca href=\"https://github.com/expressjs/body-parser/releases/tag/1.20.7\"\u003e1.20.7\u003c/a\u003e. This was created to test the new release process.\u003c/strong\u003e\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eci: backport npm-publish workflow from master by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/769\"\u003eexpressjs/body-parser#769\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e1.20.8 by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/770\"\u003eexpressjs/body-parser#770\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.7...1.20.8\"\u003ehttps://github.com/expressjs/body-parser/compare/1.20.7...1.20.8\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.20.7\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocs: include security fix in 1.20.6 changes by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/747\"\u003eexpressjs/body-parser#747\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edeps: qs@~6.16.0 by \u003ca href=\"https://github.com/krzysdz\"\u003e\u003ccode\u003e@​krzysdz\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/761\"\u003eexpressjs/body-parser#761\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e1.20.7 by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/767\"\u003eexpressjs/body-parser#767\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.6...1.20.7\"\u003ehttps://github.com/expressjs/body-parser/compare/1.20.6...1.20.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.20.6\u003c/h2\u003e\n\u003ch2\u003eImportant: Security\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity fix for \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2025-13466\"\u003eCVE-2026-12590\u003c/a\u003e (\u003ca href=\"https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6\"\u003eGHSA-v422-hmwv-36x6\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: improve limit option validation by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/741\"\u003eexpressjs/body-parser#741\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.5...1.20.6\"\u003ehttps://github.com/expressjs/body-parser/compare/1.20.5...1.20.6\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/body-parser/blob/1.20.8/HISTORY.md\"\u003ebody-parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e1.20.8\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eSame code base as 1.20.7. This was created to test the new release process.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.20.7\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003edeps: qs@~6.16.0\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.20.6\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity fix for \u003ca href=\"https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6\"\u003eGHSA-v422-hmwv-36x6\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: improve \u003ccode\u003elimit\u003c/code\u003e option validation (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/698\"\u003e#698\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003eInvalid \u003ccode\u003elimit\u003c/code\u003e values (e.g. unparseable strings or \u003ccode\u003eNaN\u003c/code\u003e) now throw instead of being silently ignored, which previously disabled size limit enforcement\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003enull\u003c/code\u003e and \u003ccode\u003eundefined\u003c/code\u003e fall back to the default 100kb limit\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/5c08c2008eac79abddb8abfa5095491d02958d56\"\u003e\u003ccode\u003e5c08c20\u003c/code\u003e\u003c/a\u003e 1.20.8 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/770\"\u003e#770\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/0cea4f42a40996eafac441d0e71084afbe1407d4\"\u003e\u003ccode\u003e0cea4f4\u003c/code\u003e\u003c/a\u003e ci: backport npm-publish workflow from master (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/769\"\u003e#769\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/0f0f0d7f96fc7444407aef85a6d1fa363279e654\"\u003e\u003ccode\u003e0f0f0d7\u003c/code\u003e\u003c/a\u003e 1.20.7 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/767\"\u003e#767\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/355eb04ade7c27f57f93a0e90e26ed6f121becc5\"\u003e\u003ccode\u003e355eb04\u003c/code\u003e\u003c/a\u003e deps: qs@~6.16.0 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/761\"\u003e#761\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/8be369a5f8b0f4070ebb7a0ae9aca12db9d8f947\"\u003e\u003ccode\u003e8be369a\u003c/code\u003e\u003c/a\u003e docs: include security fix in 1.20.6 changes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/5cc4fb8867c93a3aa4455927e38858c9ab89ff43\"\u003e\u003ccode\u003e5cc4fb8\u003c/code\u003e\u003c/a\u003e 1.20.6 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/746\"\u003e#746\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/3492672eee593d5c158f239b6e9115498a5dbeac\"\u003e\u003ccode\u003e3492672\u003c/code\u003e\u003c/a\u003e fix: improve limit option validation (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/741\"\u003e#741\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.5...1.20.8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for body-parser since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 2.1.1 to 2.1.4\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/b25213dff0446d622f97d736420b9830ee1abc32\"\u003e\u003ccode\u003eb25213d\u003c/code\u003e\u003c/a\u003e 2.1.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac\"\u003e\u003ccode\u003e1e30c93\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/878df3989e816dfb28cbe0d64de0b88738ff0ed6\"\u003e\u003ccode\u003e878df39\u003c/code\u003e\u003c/a\u003e 2.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/c8bd93cfff4e45cb295557d2be17e1d1d4e52a11\"\u003e\u003ccode\u003ec8bd93c\u003c/code\u003e\u003c/a\u003e npm ignore .claude\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d13ff455a58b0d56704f0111e3c2a0b16ceb06eb\"\u003e\u003ccode\u003ed13ff45\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/130\"\u003e#130\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/9e67a3b151e418679ac4800f31f874ec6d220b4a\"\u003e\u003ccode\u003e9e67a3b\u003c/code\u003e\u003c/a\u003e 2.1.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/835d6be91201122d9adffb0c0c8c094189ace265\"\u003e\u003ccode\u003e835d6be\u003c/code\u003e\u003c/a\u003e fix: v2 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/123\"\u003e#123\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v2.1.1...v2.1.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `browserslist` from 4.28.4 to 4.28.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/releases\"\u003ebrowserslist's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eincluding kaios\u003c/code\u003e in baseline queries (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved parsing performance.\u003c/li\u003e\n\u003cli\u003eFixed unbounded memory growth (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed prototype write issue (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Electron version queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003e\u0026gt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;=\u003c/code\u003e queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md\"\u003ebrowserslist's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eincluding kaios\u003c/code\u003e in baseline queries (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved parsing performance.\u003c/li\u003e\n\u003cli\u003eFixed unbounded memory growth (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed prototype write issue (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Electron version queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003e\u0026gt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;=\u003c/code\u003e queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/12ed5252dabc14fee4e97b465894b2f90910ca62\"\u003e\u003ccode\u003e12ed525\u003c/code\u003e\u003c/a\u003e Release 4.28.9 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/b1d8cf9d7a7dc76f6585425a8360218289194297\"\u003e\u003ccode\u003eb1d8cf9\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/21517b651c915cdbbfb8c122268bc36f5cabb7ef\"\u003e\u003ccode\u003e21517b6\u003c/code\u003e\u003c/a\u003e Improve \u003ccode\u003eor\u003c/code\u003e parsing performance\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/f2f2e6cfb01bb4942941d328737546f4e2ae41ad\"\u003e\u003ccode\u003ef2f2e6c\u003c/code\u003e\u003c/a\u003e Release 4.28.8 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/d0787c88fa29ba895fea51cfe921232c7b5d1377\"\u003e\u003ccode\u003ed0787c8\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/fcf8fa9857b30ccdf801a548f5d09d3c4ff0d43f\"\u003e\u003ccode\u003efcf8fa9\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/browserslist/browserslist/issues/939\"\u003e#939\u003c/a\u003e from Jaybhade/fix/baseline-kaios-without-downstream\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/57ecd64454e9252afdd6a7e76926e13dda48a38c\"\u003e\u003ccode\u003e57ecd64\u003c/code\u003e\u003c/a\u003e fix: support \u0026quot;including kaios\u0026quot; without downstream\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/093a0f67bb0becda55235d767b134df3197c54a1\"\u003e\u003ccode\u003e093a0f6\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/b637868045806d2fba4c24eb0060e4cc8b1db276\"\u003e\u003ccode\u003eb637868\u003c/code\u003e\u003c/a\u003e Release 4.28.7 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/313f4659b9f985ade89d1d6a54a860371c41cc46\"\u003e\u003ccode\u003e313f465\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/browserslist/browserslist/compare/4.28.4...4.28.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `colord` from 2.9.3 to 2.10.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/omgovich/colord/releases\"\u003ecolord's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.10 (RGB color mixing)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003emix\u003c/code\u003e, \u003ccode\u003etints\u003c/code\u003e, \u003ccode\u003eshades\u003c/code\u003e and \u003ccode\u003etones\u003c/code\u003e (\u003ccode\u003emix\u003c/code\u003e plugin) now accept an optional interpolation color space. LAB stays the default; pass \u003ccode\u003e\u0026quot;rgb\u0026quot;\u003c/code\u003e to interpolate RGB channels instead — the way browsers and design tools (such as Figma) composite translucent layers.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003eimport { colord, extend } from \u0026quot;colord\u0026quot;;\nimport mixPlugin from \u0026quot;colord/plugins/mix\u0026quot;;\n\u003cp\u003eextend([mixPlugin]);\u003c/p\u003e\n\u003cp\u003ecolord(\u0026quot;#ff0000\u0026quot;).mix(\u0026quot;#ffffff\u0026quot;, 0.5, \u0026quot;rgb\u0026quot;).toHex(); // \u0026quot;#ff8080\u0026quot;\ncolord(\u0026quot;#f0f3f1\u0026quot;).mix(\u0026quot;#007d40\u0026quot;, 0.14, \u0026quot;rgb\u0026quot;).toHex(); // \u0026quot;#cee2d8\u0026quot; — same as compositing rgba(0, 125, 64, 0.14) over #f0f3f1\ncolord(\u0026quot;#ff0000\u0026quot;).tints(3, \u0026quot;rgb\u0026quot;).map((c) =\u0026gt; c.toHex()); // [\u0026quot;#ff0000\u0026quot;, \u0026quot;#ff8080\u0026quot;, \u0026quot;#ffffff\u0026quot;]\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/omgovich/colord/blob/master/CHANGELOG.md\"\u003ecolord's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch3\u003e2.10.0\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003emix\u003c/code\u003e plugin by adding an optional \u003ccode\u003e\u0026quot;rgb\u0026quot;\u003c/code\u003e interpolation mode to \u003ccode\u003emix\u003c/code\u003e, \u003ccode\u003etints\u003c/code\u003e, \u003ccode\u003etones\u003c/code\u003e and \u003ccode\u003eshades\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e2.9.7\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eMake HEX parsing and serialization more than 2x faster\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e2.9.6\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix: Rotate the unrounded hue so \u003ccode\u003erotate\u003c/code\u003e and \u003ccode\u003eharmonies\u003c/code\u003e preserve the original color\u003c/li\u003e\n\u003cli\u003eFix: Normalize HWB whiteness + blackness over 100% to gray ❤️ \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e2.9.5\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix: Use adjusted chroma for the CIEDE2000 rotation term ❤️ \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix: Keep the hue within \u003ccode\u003e[0, 360)\u003c/code\u003e in every color model ❤️ \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eBoth fixes change returned numbers for a small set of colors; \u003ccode\u003etoHex()\u003c/code\u003e output is unchanged. Snapshots holding \u003ccode\u003eh: 360\u003c/code\u003e, \u003ccode\u003e\u0026quot;hsl(360, …)\u0026quot;\u003c/code\u003e or a \u003ccode\u003edelta()\u003c/code\u003e value may need updating.\u003c/p\u003e\n\u003ch3\u003e2.9.4\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix: Reject malformed color strings in linear time ❤️ \u003ca href=\"https://github.com/GAP-dev\"\u003e\u003ccode\u003e@​GAP-dev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/omgovich/colord/commits/v2.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-uri` from 3.1.2 to 3.1.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `joi` from 17.13.4 to 17.13.8\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/4ae6af96f7990fdb336aa8ad7dee5e9f847d084a\"\u003e\u003ccode\u003e4ae6af9\u003c/code\u003e\u003c/a\u003e 17.13.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/b3ed6fbdf123f4d77755e6a5df2d6a7af27cd9e8\"\u003e\u003ccode\u003eb3ed6fb\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hapijs/joi/issues/3153\"\u003e#3153\u003c/a\u003e from hapijs/fix/messages-proto-flat-v17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/1d2001cad9971327a62c9fd8eb1afec20cd784d2\"\u003e\u003ccode\u003e1d2001c\u003c/code\u003e\u003c/a\u003e chore: backport \u003ca href=\"https://redirect.github.com/hapijs/joi/issues/3151\"\u003e#3151\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/ed9d7cdd11ef5f7751fd46886f38dc605c9c3995\"\u003e\u003ccode\u003eed9d7cd\u003c/code\u003e\u003c/a\u003e 17.13.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/f2729f71839c57c94ac500b4be9e4b5b26d4e637\"\u003e\u003ccode\u003ef2729f7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hapijs/joi/issues/3145\"\u003e#3145\u003c/a\u003e from hapijs/backport/isodate-timeshift-v17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/c43fc964799c9b5f0c6921bf788162b67066ae81\"\u003e\u003ccode\u003ec43fc96\u003c/code\u003e\u003c/a\u003e chore: add regression test for \u003ca href=\"https://redirect.github.com/hapijs/joi/issues/3143\"\u003e#3143\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/115e7b58d5eaaecc5e9b7093d41899ad6fb053ec\"\u003e\u003ccode\u003e115e7b5\u003c/code\u003e\u003c/a\u003e fix(isoDate): pad a bare-hour timeshift with a colon, not just zeros\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/850be1ee24be8d548bb09359bdb0cf9fe41635ff\"\u003e\u003ccode\u003e850be1e\u003c/code\u003e\u003c/a\u003e 17.13.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/9faeecc48b18ec40e3881467645ae9074f0dfa3c\"\u003e\u003ccode\u003e9faeecc\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hapijs/joi/issues/3139\"\u003e#3139\u003c/a\u003e from hapijs/chore/backport-messages-proto\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/8d0b808f3e874d28f9078f61b7742290989afb36\"\u003e\u003ccode\u003e8d0b808\u003c/code\u003e\u003c/a\u003e fix: prevent messages proto injection\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hapijs/joi/compare/v17.13.4...v17.13.8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nanoid` from 3.3.12 to 3.3.19\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/releases\"\u003enanoid's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/blob/main/CHANGELOG.md\"\u003enanoid's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID (by \u003ca href=\"https://github.com/geoffrey-diederichs\"\u003e\u003ccode\u003e@​geoffrey-diederichs\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/eb63bd6775188dc35d143bf24868be094f19b5ee\"\u003e\u003ccode\u003eeb63bd6\u003c/code\u003e\u003c/a\u003e Release 3.3.19 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9067e0361a643ab2c94ddd67606efbf275f6c0dd\"\u003e\u003ccode\u003e9067e03\u003c/code\u003e\u003c/a\u003e Sync CJS and ESM\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9ad98052b316c5e707f8098ace509d2ae165e54d\"\u003e\u003ccode\u003e9ad9805\u003c/code\u003e\u003c/a\u003e Release 3.3.18 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/55e50a0621ec084b4bb4000ea4e86e1191bd3da8\"\u003e\u003ccode\u003e55e50a0\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e10f8d40ce9d1ab47f66d65a16b48086432730d0\"\u003e\u003ccode\u003ee10f8d4\u003c/code\u003e\u003c/a\u003e Update index.native.js (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/606\"\u003e#606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/73d67168136b36fd3b644159b0cff149da4905d9\"\u003e\u003ccode\u003e73d6716\u003c/code\u003e\u003c/a\u003e Release 3.3.17 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/f9d13f150847d117877adee3460a46eceb0cf49b\"\u003e\u003ccode\u003ef9d13f1\u003c/code\u003e\u003c/a\u003e Sync 0 size behaviour with PostCSS 5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9760e112757cf7d46a79abd7a133bc4958757bb8\"\u003e\u003ccode\u003e9760e11\u003c/code\u003e\u003c/a\u003e Release 3.3.16 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66d\"\u003e\u003ccode\u003ee835c9b\u003c/code\u003e\u003c/a\u003e fix(non-secure): clamp negative size to prevent infinite loop (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/601\"\u003e#601\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/96dd086eb24396a275fa93ee78d73b2fece35809\"\u003e\u003ccode\u003e96dd086\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ai/nanoid/compare/3.3.12...3.3.19\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for nanoid since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.15 to 8.5.28\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.28\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes types regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed removing any comments starting with \u003ccode\u003e/*#\u003c/code\u003e (by \u003ca href=\"https://github.com/dylanpulver\"\u003e\u003ccode\u003e@​dylanpulver\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e*\u003c/code\u003e hack before a comment in Custom Properties (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed empty values in the middle of \u003ccode\u003elist.comma()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed whitespace-only values in \u003ccode\u003elist.space()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed rule’s end position on space before semicolon (by \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/romainmenke\"\u003e\u003ccode\u003e@​romainmenke\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed Chinese text in deprecation warning (by \u003ca href=\"https://github.com/Jesse205\"\u003e\u003ccode\u003e@​Jesse205\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.28\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes types regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed removing any comments starting with \u003ccode\u003e/*#\u003c/code\u003e (by \u003ca href=\"https://github.com/dylanpulver\"\u003e\u003ccode\u003e@​dylanpulver\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e*\u003c/code\u003e hack before a comment in Custom Properties (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed empty values in the middle of \u003ccode\u003elist.comma()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed whitespace-only values in \u003ccode\u003elist.space()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed rule’s end position on space before semicolon (by \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/romainmenke\"\u003e\u003ccode\u003e@​romainmenke\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed Chinese text in deprecation warning (by \u003ca href=\"https://github.com/Jesse205\"\u003e\u003ccode\u003e@​Jesse205\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/e544bffc4f4b3966d8ec69c41744b3ed65afc64a\"\u003e\u003ccode\u003ee544bff\u003c/code\u003e\u003c/a\u003e Release 8.5.28 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f8fc2525717a6a7216659f7be43c525f60c6a15a\"\u003e\u003ccode\u003ef8fc252\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/5039fd78962d285abea5d7b3aebef32f053781ce\"\u003e\u003ccode\u003e5039fd7\u003c/code\u003e\u003c/a\u003e Add missed release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/ae40ca499cf6a9afdbb264c0ec09e71fe934e2af\"\u003e\u003ccode\u003eae40ca4\u003c/code\u003e\u003c/a\u003e Release 8.5.27 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/62b1626bb7fbb28eda616d002cbd525d239b18ba\"\u003e\u003ccode\u003e62b1626\u003c/code\u003e\u003c/a\u003e Fix linter\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/1dba9384515a2dbc64517697c2f738b6d5c3f9a4\"\u003e\u003ccode\u003e1dba938\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3e82edc9f037faa41647342dceceba9b841f9881\"\u003e\u003ccode\u003e3e82edc\u003c/code\u003e\u003c/a\u003e Keep non-annotation comments when the processor has no plugins (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2150\"\u003e#2150\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/6d23bc362203118478bc8051b81f2910907ebe6e\"\u003e\u003ccode\u003e6d23bc3\u003c/code\u003e\u003c/a\u003e Fix link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/508e9976be81536292e7666741e1c35e876b9a6a\"\u003e\u003ccode\u003e508e997\u003c/code\u003e\u003c/a\u003e Add GitHub Sponsors link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/e993739dc49b6055f7dfc59b161d75702f0b2b8b\"\u003e\u003ccode\u003ee993739\u003c/code\u003e\u003c/a\u003e Add CodeRabbit sponsor (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2145\"\u003e#2145\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.15...8.5.28\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `shell-quote` from 1.8.4 to 1.10.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md\"\u003eshell-quote's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.9.0...v1.10.0\"\u003ev1.10.0\u003c/a\u003e - 2026-07-10\u003c/h2\u003e\n\u003ch3\u003eMerged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[New] \u003ccode\u003eparse\u003c/code\u003e: add opt-in \u003ccode\u003esplitUnquoted\u003c/code\u003e option for shell field-splitting of unquoted expansions \u003ca href=\"https://redirect.github.com/ljharb/shell-quote/pull/1\"\u003e\u003ccode\u003e[#1](https://github.com/ljharb/shell-quote/issues/1)\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: match nested \u003ccode\u003e${...}\u003c/code\u003e braces so nested parameter expansion is consumed as one substitution \u003ca href=\"https://github.com/ljharb/shell-quote/commit/c0842c8a7a034066da2496a75e91cbe500ff736c\"\u003e\u003ccode\u003ec0842c8\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003eparse\u003c/code\u003e: pin single-quote literalness and unmatched-quote handling \u003ca href=\"https://github.com/ljharb/shell-quote/commit/a0d03e35c8ede24016502c4433b8f5d6b3100a62\"\u003e\u003ccode\u003ea0d03e3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] remove the space in js code fences so evalmd evaluates them \u003ca href=\"https://github.com/ljharb/shell-quote/commit/2116fa36aeea77fe8d561b0db46b1f9b26b8cf1b\"\u003e\u003ccode\u003e2116fa3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003equote\u003c/code\u003e: pin conservative escaping of \u003ccode\u003e=\u003c/code\u003e, \u003ccode\u003e@\u003c/code\u003e, \u003ccode\u003e^\u003c/code\u003e, \u003ccode\u003e,\u003c/code\u003e, \u003ccode\u003e:\u003c/code\u003e, \u003ccode\u003e!\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/1c36f3ff77d26d200620c1027e5c271050120b8e\"\u003e\u003ccode\u003e1c36f3f\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] document that \u003ccode\u003equote\u003c/code\u003e outputs POSIX quoting, not \u003ccode\u003ecmd.exe\u003c/code\u003e/PowerShell \u003ca href=\"https://github.com/ljharb/shell-quote/commit/100e96e0ffadcca97d63dda15651c70b9f83507c\"\u003e\u003ccode\u003e100e96e\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] document \u003ccode\u003eparse\u003c/code\u003e's supported parameter-expansion subset \u003ca href=\"https://github.com/ljharb/shell-quote/commit/e1c75cd6e4a3c60003792c7f2802587d328622cb\"\u003e\u003ccode\u003ee1c75cd\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: a backslash inside single quotes must not escape the closing quote \u003ca href=\"https://github.com/ljharb/shell-quote/commit/5d460a332b54b83153297fe7d1964330b28fa491\"\u003e\u003ccode\u003e5d460a3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] fix stale example outputs \u003ca href=\"https://github.com/ljharb/shell-quote/commit/2de86f5d44f44d3ac9df36413d8a05f3534cdec6\"\u003e\u003ccode\u003e2de86f5\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003equote\u003c/code\u003e: pin that a backslash with whitespace is not doubled in single quotes (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/14\"\u003e#14\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/190e236bcf1d81caa8e40e8ea3bb11998575be71\"\u003e\u003ccode\u003e190e236\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] \u003ccode\u003equote\u003c/code\u003e: use output verbatim; do not re-quote it (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/1b364683b1e9e8d078fd3017cde82cf10c9c04a5\"\u003e\u003ccode\u003e1b36468\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Refactor] \u003ccode\u003eparse\u003c/code\u003e: fix swapped \u003ccode\u003eSINGLE_QUOTE\u003c/code\u003e/\u003ccode\u003eDOUBLE_QUOTE\u003c/code\u003e variable names \u003ca href=\"https://github.com/ljharb/shell-quote/commit/801af5c935b27d6dcda63b3975d5e92a7b6f887f\"\u003e\u003ccode\u003e801af5c\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[types] fix an error TS v6 ignores but v7 fails on \u003ca href=\"https://github.com/ljharb/shell-quote/commit/59bbf8b81bf3236842deb72805744d489f650eba\"\u003e\u003ccode\u003e59bbf8b\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@arethetypeswrong/cli\u003c/code\u003e, \u003ccode\u003eevalmd\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/a04d47516e1cd5b1b4d3f720ddf97561ed0082fc\"\u003e\u003ccode\u003ea04d475\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@arethetypeswrong/ci\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/d390f9a92b97a04b1f799298634e90dc581021e6\"\u003e\u003ccode\u003ed390f9a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003equote\u003c/code\u003e: the tilde test escapes every \u003ccode\u003e~\u003c/code\u003e, not just a leading one (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/9\"\u003e#9\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/617d119795c7b44d6e49a4d41f80195c4aa5735c\"\u003e\u003ccode\u003e617d119\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.4...v1.9.0\"\u003ev1.9.0\u003c/a\u003e - 2026-06-24\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[New] add types \u003ca href=\"https://github.com/ljharb/shell-quote/commit/dca6e21a02df4cc1a83ed1b5baa4d82df134170a\"\u003e\u003ccode\u003edca6e21\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9aa9e8f60991f8c4053a29e476795d891ff851ad\"\u003e\u003ccode\u003e9aa9e8f\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: finalize tokens in linear time (GHSA-395f-4hp3-45gv) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7ff5488599d01c323514f02f5efb74088dd134ec\"\u003e\u003ccode\u003e7ff5488\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] update workflows \u003ca href=\"https://github.com/ljharb/shell-quote/commit/75e849741ffaf2d3aa53ae0e18ef6bf9929ef478\"\u003e\u003ccode\u003e75e8497\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] Windows + node 4/6/7: pin eslint to 9 before install, since npm 2/3 cannot stage eslint 10\u003ccode\u003e@types/esrecurse\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/3fb739de44b81c69431947d54fbfc18998dd6d72\"\u003e\u003ccode\u003e3fb739d\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] retry \u003ccode\u003enpm install\u003c/code\u003e on Windows to survive npm 2/3 staging-rename flake \u003ca href=\"https://github.com/ljharb/shell-quote/commit/abe0163293c82963fa8a16cfaa87181846d5aced\"\u003e\u003ccode\u003eabe0163\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] Windows + node 5/7: install deps with a modern node \u003ca href=\"https://github.com/ljharb/shell-quote/commit/b4bafa2e7e58d53d9839b1c24976f61e54b43326\"\u003e\u003ccode\u003eb4bafa2\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003equote\u003c/code\u003e: escape leading \u003ccode\u003e~\u003c/code\u003e to prevent shell tilde-expansion \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7a76c1a12d8461c2234a1c655b943cee84cbff91\"\u003e\u003ccode\u003e7a76c1a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003etape\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7184b4458b65c17b931e126d8cb5f586c6717dc8\"\u003e\u003ccode\u003e7184b44\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] apparently \u003ccode\u003ejackspeak\u003c/code\u003e is no longer in the graph \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9ba368a4057b9f498b0fef23b5b15543ef81b98c\"\u003e\u003ccode\u003e9ba368a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/64988d9a0e73a2ae710488952e3614958ef289d4\"\u003e\u003ccode\u003e64988d9\u003c/code\u003e\u003c/a\u003e v1.10.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/617d119795c7b44d6e49a4d41f80195c4aa5735c\"\u003e\u003ccode\u003e617d119\u003c/code\u003e\u003c/a\u003e [Tests] \u003ccode\u003equote\u003c/code\u003e: the tilde test escapes every \u003ccode\u003e~\u003c/code\u003e, not just a leading one (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/9\"\u003e#9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/59bbf8b81bf3236842deb72805744d489f650eba\"\u003e\u003ccode\u003e59bbf8b\u003c/code\u003e\u003c/a\u003e [types] fix an error TS v6 ignores but v7 fails on\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/190e236bcf1d81caa8e40e8ea3bb11998575be71\"\u003e\u003ccode\u003e190e236\u003c/code\u003e\u003c/a\u003e [Tests] \u003ccode\u003equote\u003c/code\u003e: pin that a backslash with whitespace is not doubled in singl...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/a04d47516e1cd5b1b4d3f720ddf97561ed0082fc\"\u003e\u003ccode\u003ea04d475\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003e@arethetypeswrong/cli\u003c/code\u003e, \u003ccode\u003eevalmd\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/b9545b39f4de17aa169410823c98acf58387e474\"\u003e\u003ccode\u003eb9545b3\u003c/code\u003e\u003c/a\u003e [New] \u003ccode\u003eparse\u003c/code\u003e: add opt-in \u003ccode\u003esplitUnquoted\u003c/code\u003e option for shell field-splitting of...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/1b364683b1e9e8d078fd3017cde82cf10c9c04a5\"\u003e\u003ccode\u003e1b36468\u003c/code\u003e\u003c/a\u003e [readme] \u003ccode\u003equote\u003c/code\u003e: use output verbatim; do not re-quote it (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/1c36f3ff77d26d200620c1027e5c271050120b8e\"\u003e\u003ccode\u003e1c36f3f\u003c/code\u003e\u003c/a\u003e [Tests] \u003ccode\u003equote\u003c/code\u003e: pin conservative escaping of \u003ccode\u003e=\u003c/code\u003e, \u003ccode\u003e@\u003c/code\u003e, \u003ccode\u003e^\u003c/code\u003e, \u003ccode\u003e,\u003c/code\u003e, \u003ccode\u003e:\u003c/code\u003e, \u003ccode\u003e!\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/e1c75cd6e4a3c60003792c7f2802587d328622cb\"\u003e\u003ccode\u003ee1c75cd\u003c/code\u003e\u003c/a\u003e [readme] document \u003ccode\u003eparse\u003c/code\u003e's supported parameter-expansion subset\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/c0842c8a7a034066da2496a75e91cbe500ff736c\"\u003e\u003ccode\u003ec0842c8\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003eparse\u003c/code\u003e: match nested \u003ccode\u003e${...}\u003c/code\u003e braces so nested parameter expansion is ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.4...v1.10.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `svgo` from 3.3.3 to 3.3.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/svg/svgo/releases\"\u003esvgo's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.3.5\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBackport the \u003ccode\u003eremoveScriptElement\u003c/code\u003e hardening from SVGO v4 in \u003ca href=\"https://redirect.github.com/svg/svgo/issues/2269\"\u003e#2269\u003c/a\u003e:\n\u003cul\u003e\n\u003cli\u003ereject executable \u003ccode\u003edata:\u003c/code\u003e URLs and legacy \u003ccode\u003evbscript:\u003c/code\u003e URLs\u003c/li\u003e\n\u003cli\u003esanitize executable HTML inside \u003ccode\u003e\u0026lt;foreignObject\u0026gt;\u003c/code\u003e elements\u003c/li\u003e\n\u003cli\u003ehandle namespace-prefixed SVG anchors and URL schemes containing ASCII tabs or newlines\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThis addresses \u003ca href=\"https://github.com/svg/svgo/security/advisories/GHSA-4vpr-x523-8j87\"\u003eGHSA-4vpr-x523-8j87\u003c/a\u003e and \u003ca href=\"https://github.com/svg/svgo/security/advisories/GHSA-w27v-7q3p-w38r\"\u003eGHSA-w27v-7q3p-w38r\u003c/a\u003e for the v3 release line.\u003c/p\u003e\n\u003ch2\u003eSupport\u003c/h2\u003e\n\u003cp\u003eSVGO v3 is not officially supported; please consider upgrading to SVGO v4. This security fix has been backported, but there is no commitment to backport more complex changes in the future.\u003c/p\u003e\n\u003cp\u003eSee the \u003ca href=\"https://svgo.dev/docs/migrations/migration-from-v3-to-v4/\"\u003emigration guide from v3 to v4\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003ev3.3.4\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://svgo.dev/docs/plugins/removeScripts/\"\u003eremoveScriptElement\u003c/a\u003e, remove JavaScript URIs case-insensitively and make \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e handling namespace aware. By \u003ca href=\"https://github.com/SethFalco\"\u003e\u003ccode\u003e@​SethFalco\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eSupport\u003c/h2\u003e\n\u003cp\u003eSVGO v3 is not officially supported, please consider upgrading to SVGO v4 instead. We've backported this fix as there are security implications, but there is no commitment to do this for more complex changes in future.\u003c/p\u003e\n\u003cp\u003eConsider reading our \u003ca href=\"https://svgo.dev/docs/migrations/migration-from-v3-to-v4/\"\u003eMigration Guide from v3 to v4\u003c/a\u003e which should ease the process.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/svg/svgo/commit/438059032950dde2c2d36ce45f912085947e60d0\"\u003e\u003ccode\u003e4380590\u003c/code\u003e\u003c/a\u003e ci: configure v3 publish tag in package metadata (\u003ca href=\"https://redirect.github.com/svg/svgo/issues/2271\"\u003e#2271\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/svg/svgo/commit/4c84fe7ef022f05350404a469ca66321e0afcb47\"\u003e\u003ccode\u003e4c84fe7\u003c/code\u003e\u003c/a\u003e ci: publish v3 with npm trusted publishing (\u003ca href=\"https://redirect.github.com/svg/svgo/issues/2270\"\u003e#2270\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/svg/svgo/commit/994a9f00d79ddec68ce19a1ce9eb8ca08d747e4f\"\u003e\u003ccode\u003e994a9f0\u003c/code\u003e\u003c/a\u003e fix(removeScriptElement): backport security hardening to v3 (\u003ca href=\"https://redirect.github.com/svg/svgo/issues/2269\"\u003e#2269\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/svg/svgo/commit/72a23886b4698b27624b936f3a15a80afd36d75f\"\u003e\u003ccode\u003e72a2388\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/svg/svgo/compare/v3.3.3...v3.3.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for svgo since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.28.0 to 7.29.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.1\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/f690157d728508652fef14673630c71515123e96\"\u003ef690157d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6615e0175e9b635bcd2e3e87a47daa82f6f5b728\"\u003e6615e017\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/63cf698b611fecc6ee0a17b185b930051e4b982f\"\u003e63cf698b\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1858656ebb1e919311c1f31613dfd581b7214349\"\u003e1858656e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/b6c5a00252c37da9dd2db9bead053bb843e1f988\"\u003eb6c5a002\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2c7d7e1227043c644c4c32cfd1e276f4fd4fcb11\"\u003e2c7d7e12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3c6726599cea8646384dde846c97d630da472a74\"\u003e3c672659\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/b61d9432bac7caac51273ad209862e4c0bf935ae\"\u003eb61d9432\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/21693f406f0142f3504192e9f9b022dcf84782ae\"\u003e21693f40\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cd8af90b38ae33c2838d54a2d629774122effe95\"\u003ecd8af90b\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[v7.x] drop: remove Node.js 26 from shared-builtin CI build by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5592\"\u003enodejs/undici#5592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): honour headersTimeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5604\"\u003enodejs/undici#5604\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): keep the connection ref'd while requests are outstanding by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5605\"\u003enodejs/undici#5605\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: increase Windows workflow timeout on v7.x by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5621\"\u003enodejs/undici#5621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): retire the request that completed, not the head of the queue by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5618\"\u003enodejs/undici#5618\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): settle a request whose stream is cancelled by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5607\"\u003enodejs/undici#5607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: reduce EventSourceStream parser allocations (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5032\"\u003e#5032\u003c/a\u003e) by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5646\"\u003enodejs/undici#5646\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): handle GOAWAY for CONNECT streams by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5640\"\u003enodejs/undici#5640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v7.x] perf(h1): drop idle-socket timer floor with a ref'd setImmediate (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5707\"\u003e#5707\u003c/a\u003e) by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5769\"\u003enodejs/undici#5769\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.29.0...v7.29.1\"\u003ehttps://github.com/nodejs/undici/compare/v7.29.0...v7.29.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d39a83e7b0d631590c3b85b5cc0dbeab66c3a1d8\"\u003e\u003ccode\u003ed39a83e\u003c/code\u003e\u003c/a\u003e Bumped v7.29.1 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5772\"\u003e#5772\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0d88464876d02bdb9cf27015d9d66500a8aaa782\"\u003e\u003ccode\u003e0d88464\u003c/code\u003e\u003c/a\u003e fix(test): remove unused EventEmitter import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f57411b894d45b89964252971497507500c32bc1\"\u003e\u003ccode\u003ef57411b\u003c/code\u003e\u003c/a\u003e perf(h1): drop idle-socket timer floor with a ref'd setImmediate (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5707\"\u003e#5707\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5769\"\u003e#5769\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3c6726599cea8646384dde846c97d630da472a74\"\u003e\u003ccode\u003e3c67265\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cd8af90b38ae33c2838d54a2d629774122effe95\"\u003e\u003ccode\u003ecd8af90\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6615e0175e9b635bcd2e3e87a47daa82f6f5b728\"\u003e\u003ccode\u003e6615e01\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2c7d7e1227043c644c4c32cfd1e276f4fd4fcb11\"\u003e\u003ccode\u003e2c7d7e1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b6c5a00252c37da9dd2db9bead053bb843e1f988\"\u003e\u003ccode\u003eb6c5a00\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/21693f406f0142f3504192e9f9b022dcf84782ae\"\u003e\u003ccode\u003e21693f4\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f690157d728508652fef14673630c71515123e96\"\u003e\u003ccode\u003ef690157\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot cr...\n\n_Description has been truncated_","html_url":"https://github.com/presiannedyalkov/eco-balance-documentation/pull/558","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/presiannedyalkov%2Feco-balance-documentation/issues/558","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/558/packages"},{"uuid":"5439014474","node_id":"PR_kwDOKD4oKs8AAAABDUlQSg","number":310,"state":"closed","title":"chore(deps): bump the npm_and_yarn group across 1 directory with 23 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":"2026-09-13T08:16:41.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-13T08:16:33.000Z","updated_at":"2026-09-13T08:16:50.000Z","time_to_close":8,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":23,"packages":[{"name":"@astrojs/netlify","old_version":"6.6.5","new_version":"8.1.2","repository_url":"https://github.com/withastro/astro"},{"name":"astro","old_version":"5.18.1","new_version":"7.2.8","repository_url":"https://github.com/withastro/astro"},{"name":"@babel/core","old_version":"7.29.0","new_version":"7.29.7","repository_url":"https://github.com/babel/babel"},{"name":"@babel/plugin-transform-modules-systemjs","old_version":"7.29.0","new_version":"7.29.8","repository_url":"https://github.com/babel/babel"},{"name":"brace-expansion","old_version":"1.1.14","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"esbuild","old_version":"0.25.12","new_version":"0.28.2","repository_url":"https://github.com/evanw/esbuild"},{"name":"vite","old_version":"6.4.2","new_version":"7.3.6","repository_url":"https://github.com/vitejs/vite"},{"name":"baseline-browser-mapping","old_version":"2.10.19","new_version":"2.11.23","repository_url":"https://github.com/web-platform-dx/baseline-browser-mapping"},{"name":"browserslist","old_version":"4.28.2","new_version":"4.28.9","repository_url":"https://github.com/browserslist/browserslist"},{"name":"fast-uri","old_version":"3.1.0","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"postcss-selector-parser","old_version":"7.1.1","new_version":"7.1.6","repository_url":"https://github.com/postcss/postcss-selector-parser"},{"name":"serialize-javascript","old_version":"6.0.2","new_version":"7.1.1","repository_url":"https://github.com/yahoo/serialize-javascript"},{"name":"smol-toml","old_version":"1.6.1","new_version":"1.8.0","repository_url":"https://github.com/squirrelchat/smol-toml"},{"name":"svgo","old_version":"4.0.1","new_version":"4.1.0","repository_url":"https://github.com/svg/svgo"},{"name":"yaml","old_version":"2.7.1","new_version":"2.8.3","repository_url":"https://github.com/eemeli/yaml"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 15 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@astrojs/netlify](https://github.com/withastro/astro/tree/HEAD/packages/integrations/netlify) | `6.6.5` | `8.1.2` |\n| [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro) | `5.18.1` | `7.2.8` |\n| [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) | `7.29.0` | `7.29.7` |\n| [@babel/plugin-transform-modules-systemjs](https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs) | `7.29.0` | `7.29.8` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.14` | `1.1.18` |\n| [esbuild](https://github.com/evanw/esbuild) | `0.25.12` | `0.28.2` |\n| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `6.4.2` | `7.3.6` |\n| [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) | `2.10.19` | `2.11.23` |\n| [browserslist](https://github.com/browserslist/browserslist) | `4.28.2` | `4.28.9` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.0` | `3.1.7` |\n| [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) | `7.1.1` | `7.1.6` |\n| [serialize-javascript](https://github.com/yahoo/serialize-javascript) | `6.0.2` | `7.1.1` |\n| [smol-toml](https://github.com/squirrelchat/smol-toml) | `1.6.1` | `1.8.0` |\n| [svgo](https://github.com/svg/svgo) | `4.0.1` | `4.1.0` |\n| [yaml](https://github.com/eemeli/yaml) | `2.7.1` | `2.8.3` |\n\n\nUpdates `@astrojs/netlify` from 6.6.5 to 8.1.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/withastro/astro/blob/main/packages/integrations/netlify/CHANGELOG.md\"\u003e@​astrojs/netlify's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.1.2\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17368\"\u003e#17368\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/ee74c289bfe32fb6a7f59ed97c5c22db16394b72\"\u003e\u003ccode\u003eee74c28\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Fixes the generated Netlify Image CDN \u003ccode\u003eremote_images\u003c/code\u003e patterns so that regex metacharacters (such as \u003ccode\u003e.\u003c/code\u003e) in \u003ccode\u003eimage.remotePatterns\u003c/code\u003e (\u003ccode\u003ehostname\u003c/code\u003e, \u003ccode\u003epathname\u003c/code\u003e) and \u003ccode\u003eimage.domains\u003c/code\u003e are matched literally instead of behaving like wildcards. This makes the generated patterns consistent with how Astro matches these values elsewhere.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated dependencies []:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​astrojs/underscore-redirects\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.0.3\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.1.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies [\u003ca href=\"https://github.com/withastro/astro/commit/eb6f97e391ee587747e37609c255c7cd4b9cce3c\"\u003e\u003ccode\u003eeb6f97e\u003c/code\u003e\u003c/a\u003e]:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​astrojs/internal-helpers\u003c/code\u003e\u003ca href=\"https://github.com/0\"\u003e\u003ccode\u003e@​0\u003c/code\u003e\u003c/a\u003e.10.1\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​astrojs/underscore-redirects\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.0.3\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.1.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17245\"\u003e#17245\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/f56d9e7eb46ca59e70f636cb8cd281bdf41971c4\"\u003e\u003ccode\u003ef56d9e7\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/astrobot-houston\"\u003e\u003ccode\u003e@​astrobot-houston\u003c/code\u003e\u003c/a\u003e! - Adds \u003ccode\u003eedgeFunctions\u003c/code\u003e to the \u003ccode\u003edevFeatures\u003c/code\u003e adapter option, allowing users to disable Netlify Edge Function emulation during \u003ccode\u003eastro dev\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eSome npm packages that access the filesystem at initialization (e.g. \u003ccode\u003enode-html-parser\u003c/code\u003e) fail inside the edge function sandbox with \u0026quot;Reading or writing files with Edge Functions is not supported yet.\u0026quot; You can now disable edge function emulation to avoid this error:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003eimport netlify from '@astrojs/netlify';\nimport { defineConfig } from 'astro/config';\n\u003cp\u003eexport default defineConfig({\nadapter: netlify({\ndevFeatures: {\nedgeFunctions: false,\n},\n}),\n});\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eEdge functions will still work in production builds and via \u003ccode\u003enetlify dev\u003c/code\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17249\"\u003e#17249\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/02b73b0fc2e32102e788fd9031ce061337490a73\"\u003e\u003ccode\u003e02b73b0\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ematipico\"\u003e\u003ccode\u003e@​ematipico\u003c/code\u003e\u003c/a\u003e! - Fixes an issue where the \u003ccode\u003epeerDependencies\u003c/code\u003e field used incorrect dependencies.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated dependencies []:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​astrojs/underscore-redirects\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.0.3\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.0.0\u003c/h2\u003e\n\u003ch3\u003eMajor Changes\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/dec769217f62b4f7546b448c4e9f947bda4422c8\"\u003e\u003ccode\u003edec7692\u003c/code\u003e\u003c/a\u003e [ci] release (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/integrations/netlify/issues/17338\"\u003e#17338\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/ee74c289bfe32fb6a7f59ed97c5c22db16394b72\"\u003e\u003ccode\u003eee74c28\u003c/code\u003e\u003c/a\u003e Match remotePatterns and domains metacharacters literally in Netlify Image CD...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/a86160ee79e4600bf77f89eb2dc84782acdeab6f\"\u003e\u003ccode\u003ea86160e\u003c/code\u003e\u003c/a\u003e [ci] release (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/integrations/netlify/issues/17256\"\u003e#17256\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/7d8ec1f10365a1e99e226172e5694bf078b25a51\"\u003e\u003ccode\u003e7d8ec1f\u003c/code\u003e\u003c/a\u003e [ci] release (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/integrations/netlify/issues/17237\"\u003e#17237\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/3a36fffdb0b8a3337279aa3d21cff53acf95eb10\"\u003e\u003ccode\u003e3a36fff\u003c/code\u003e\u003c/a\u003e [ci] format\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/f56d9e7eb46ca59e70f636cb8cd281bdf41971c4\"\u003e\u003ccode\u003ef56d9e7\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003eedgeFunctions\u003c/code\u003e to Netlify adapter \u003ccode\u003edevFeatures\u003c/code\u003e to allow disabling edge ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/02b73b0fc2e32102e788fd9031ce061337490a73\"\u003e\u003ccode\u003e02b73b0\u003c/code\u003e\u003c/a\u003e fix: peer deps of packages (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/integrations/netlify/issues/17249\"\u003e#17249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/d5fbee8ec341049dc5ddc7b6c251b7a859abf437\"\u003e\u003ccode\u003ed5fbee8\u003c/code\u003e\u003c/a\u003e chore(deps): update sharp to v0.35 (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/integrations/netlify/issues/17234\"\u003e#17234\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/2bfb179545249786e9f395325c88a9dfef574acb\"\u003e\u003ccode\u003e2bfb179\u003c/code\u003e\u003c/a\u003e chore: simpler package.json types (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/integrations/netlify/issues/17229\"\u003e#17229\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/f55ba4caca7c587555da86e3211ae1f1b3407c5f\"\u003e\u003ccode\u003ef55ba4c\u003c/code\u003e\u003c/a\u003e [ci] release (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/integrations/netlify/issues/17132\"\u003e#17132\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/withastro/astro/commits/@astrojs/netlify@8.1.2/packages/integrations/netlify\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `astro` from 5.18.1 to 7.2.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/withastro/astro/releases\"\u003eastro's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eastro@7.2.8\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17837\"\u003e#17837\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/ecb4082131490b4fe9a56aa44fda84b54ef8967b\"\u003e\u003ccode\u003eecb4082\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Updates the minimum supported version of Sharp to 0.35.4\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17786\"\u003e#17786\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/db7c53b1707856866e06cdeeef1aa4ae3598b1f2\"\u003e\u003ccode\u003edb7c53b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/gameroman\"\u003e\u003ccode\u003e@​gameroman\u003c/code\u003e\u003c/a\u003e! - Replaces the internal \u003ccode\u003efind-process\u003c/code\u003e dependency with a smaller, lighter alternative\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eastro@7.2.7\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17415\"\u003e#17415\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/55d38c868b7cbf2266649929c60ddf442abe674f\"\u003e\u003ccode\u003e55d38c8\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/iseraph-dev\"\u003e\u003ccode\u003e@​iseraph-dev\u003c/code\u003e\u003c/a\u003e! - Deserializes each route once when loading the SSR manifest\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17772\"\u003e#17772\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/023b48b139a2c40420b340f61b53a62b47a557e5\"\u003e\u003ccode\u003e023b48b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Fixes route selection for normalized request paths in adapter and development request handling\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17819\"\u003e#17819\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/633855b0cabd55cc7b913eb556a739a6a2d93dd2\"\u003e\u003ccode\u003e633855b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Updates generated and default Cloudflare \u003ccode\u003ecompatibility_date\u003c/code\u003e values to match the installed runtime and requires Wrangler \u003ccode\u003e^4.125.0\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17813\"\u003e#17813\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/ae26d18c71515c47ecbd7e1ffe5c5dfc29fbd613\"\u003e\u003ccode\u003eae26d18\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ccode\u003erewrite()\u003c/code\u003e and \u003ccode\u003enext(payload)\u003c/code\u003e for GET and HEAD requests with host-provided bodies\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17816\"\u003e#17816\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/a0d2fe3af25a25bc9b808070f25886c37d5be6fc\"\u003e\u003ccode\u003ea0d2fe3\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes the experimental \u003ccode\u003esvgOptimizer\u003c/code\u003e not generating unique per-file ID prefixes when using SVGO's \u003ccode\u003eprefixIds\u003c/code\u003e plugin\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eastro@7.2.6\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17812\"\u003e#17812\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/29af6da5c11aff673133f96df029f40345674f0e\"\u003e\u003ccode\u003e29af6da\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Fixes a bug where \u003ccode\u003enew FetchState(request)\u003c/code\u003e could fail in development when server dependencies were optimized\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eastro@7.2.5\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17758\"\u003e#17758\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/5f419e25c570002a2ce0e10a973aa13336016b0c\"\u003e\u003ccode\u003e5f419e2\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes a bug where \u003ccode\u003eexperimental_getFontFileURL()\u003c/code\u003e rejected valid font URLs when using the Cloudflare adapter\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17416\"\u003e#17416\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/493796b4c318b19985eccaac7a11aa7b787e1efe\"\u003e\u003ccode\u003e493796b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/iseraph-dev\"\u003e\u003ccode\u003e@​iseraph-dev\u003c/code\u003e\u003c/a\u003e! - Skips no-op pathname writes when normalizing SSR request URLs\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17712\"\u003e#17712\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/bd374b7507de8d706c845946fd847e76de6fc06b\"\u003e\u003ccode\u003ebd374b7\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/fkatsuhiro\"\u003e\u003ccode\u003e@​fkatsuhiro\u003c/code\u003e\u003c/a\u003e! - Updates deprecation messages target from Astro 7 to 8\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17719\"\u003e#17719\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/dac17688f691c6cecdff969aa48523bf17fc0657\"\u003e\u003ccode\u003edac1768\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/astrobot-houston\"\u003e\u003ccode\u003e@​astrobot-houston\u003c/code\u003e\u003c/a\u003e! - Fixes session ID validation to reject non-UUID cookie values before using them as storage keys\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17770\"\u003e#17770\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/84eb7e7db99573b80c339efe0392d959e7a9b6cf\"\u003e\u003ccode\u003e84eb7e7\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ccode\u003e--mode\u003c/code\u003e, \u003ccode\u003e--site\u003c/code\u003e, \u003ccode\u003e--base\u003c/code\u003e, \u003ccode\u003e--out-dir\u003c/code\u003e, \u003ccode\u003e--verbose\u003c/code\u003e, \u003ccode\u003e--silent\u003c/code\u003e, and \u003ccode\u003e--open\u003c/code\u003e flags being silently dropped when using \u003ccode\u003eastro dev --background\u003c/code\u003e or \u003ccode\u003eastro preview --background\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17713\"\u003e#17713\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/d035290a14afac8834885b727327a7f44d3a3a48\"\u003e\u003ccode\u003ed035290\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/wakqasahmed\"\u003e\u003ccode\u003e@​wakqasahmed\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ccode\u003econtent-modules.mjs\u003c/code\u003e not removing entries for deleted or renamed content files, which could cause Vite to attempt to resolve non-existent modules\u003c/p\u003e\n\u003cp\u003eAs part of this fix, \u003ccode\u003e#moduleImports\u003c/code\u003e is now fully rebuilt from \u003ccode\u003edeferredRender\u003c/code\u003e entries before every write, so a module import added only through the public \u003ccode\u003eaddModuleImport()\u003c/code\u003e API without a corresponding \u003ccode\u003edeferredRender\u003c/code\u003e entry in the store will no longer be preserved across writes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17743\"\u003e#17743\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/adc750fa27ea1d4767e30fc12e64a342fbebbd89\"\u003e\u003ccode\u003eadc750f\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/contactjawad\"\u003e\u003ccode\u003e@​contactjawad\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ccode\u003eAstro.preferredLocale\u003c/code\u003e and \u003ccode\u003eAstro.preferredLocaleList\u003c/code\u003e ignoring \u003ccode\u003eAccept-Language\u003c/code\u003e quality values when they are absent or \u003ccode\u003e0\u003c/code\u003e. An entry without an explicit \u003ccode\u003eq=\u003c/code\u003e now correctly counts as quality \u003ccode\u003e1.0\u003c/code\u003e (per RFC 7231) and an entry with \u003ccode\u003eq=0\u003c/code\u003e is treated as not acceptable, so the highest-quality locale is selected regardless of header order.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17757\"\u003e#17757\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/660991c820fbeb087b2f27361e6ebaeba8285358\"\u003e\u003ccode\u003e660991c\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes build errors showing wrong file location, missing line:col, and misleading hints when a plugin error (e.g. from MDX) is wrapped by Vite's build error\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17783\"\u003e#17783\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/60b14ffff5b7a66b06d9b12e72933ba9222f519d\"\u003e\u003ccode\u003e60b14ff\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Fixes a type error when passing an image from a content collection \u003ccode\u003eimage()\u003c/code\u003e schema to a component or \u003ccode\u003e\u0026lt;Image /\u0026gt;\u003c/code\u003e. The schema returned by \u003ccode\u003eimage()\u003c/code\u003e was missing the \u003ccode\u003eapng\u003c/code\u003e format, so it no longer matched the type of an imported image.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17664\"\u003e#17664\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/d48312502ef33a32aef3f25b6b6035db8b38e189\"\u003e\u003ccode\u003ed483125\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/astrobot-houston\"\u003e\u003ccode\u003e@​astrobot-houston\u003c/code\u003e\u003c/a\u003e! - Fixes an issue where Astro CSP support didn't correctly handle cases \u003ccode\u003e\u0026quot;unsafe-inline\u0026quot;\u003c/code\u003e resource. Now when \u003ccode\u003e\u0026quot;unsafe-inline\u0026quot;\u003c/code\u003e, Astro won't emit hashes for the directive specified.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md\"\u003eastro's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e7.2.8\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17837\"\u003e#17837\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/ecb4082131490b4fe9a56aa44fda84b54ef8967b\"\u003e\u003ccode\u003eecb4082\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Updates the minimum supported version of Sharp to 0.35.4\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17786\"\u003e#17786\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/db7c53b1707856866e06cdeeef1aa4ae3598b1f2\"\u003e\u003ccode\u003edb7c53b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/gameroman\"\u003e\u003ccode\u003e@​gameroman\u003c/code\u003e\u003c/a\u003e! - Replaces the internal \u003ccode\u003efind-process\u003c/code\u003e dependency with a smaller, lighter alternative\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.2.7\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17415\"\u003e#17415\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/55d38c868b7cbf2266649929c60ddf442abe674f\"\u003e\u003ccode\u003e55d38c8\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/iseraph-dev\"\u003e\u003ccode\u003e@​iseraph-dev\u003c/code\u003e\u003c/a\u003e! - Deserializes each route once when loading the SSR manifest\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17772\"\u003e#17772\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/023b48b139a2c40420b340f61b53a62b47a557e5\"\u003e\u003ccode\u003e023b48b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Fixes route selection for normalized request paths in adapter and development request handling\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17819\"\u003e#17819\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/633855b0cabd55cc7b913eb556a739a6a2d93dd2\"\u003e\u003ccode\u003e633855b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Updates generated and default Cloudflare \u003ccode\u003ecompatibility_date\u003c/code\u003e values to match the installed runtime and requires Wrangler \u003ccode\u003e^4.125.0\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17813\"\u003e#17813\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/ae26d18c71515c47ecbd7e1ffe5c5dfc29fbd613\"\u003e\u003ccode\u003eae26d18\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ccode\u003erewrite()\u003c/code\u003e and \u003ccode\u003enext(payload)\u003c/code\u003e for GET and HEAD requests with host-provided bodies\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17816\"\u003e#17816\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/a0d2fe3af25a25bc9b808070f25886c37d5be6fc\"\u003e\u003ccode\u003ea0d2fe3\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes the experimental \u003ccode\u003esvgOptimizer\u003c/code\u003e not generating unique per-file ID prefixes when using SVGO's \u003ccode\u003eprefixIds\u003c/code\u003e plugin\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.2.6\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17812\"\u003e#17812\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/29af6da5c11aff673133f96df029f40345674f0e\"\u003e\u003ccode\u003e29af6da\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Fixes a bug where \u003ccode\u003enew FetchState(request)\u003c/code\u003e could fail in development when server dependencies were optimized\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.2.5\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17758\"\u003e#17758\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/5f419e25c570002a2ce0e10a973aa13336016b0c\"\u003e\u003ccode\u003e5f419e2\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes a bug where \u003ccode\u003eexperimental_getFontFileURL()\u003c/code\u003e rejected valid font URLs when using the Cloudflare adapter\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17416\"\u003e#17416\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/493796b4c318b19985eccaac7a11aa7b787e1efe\"\u003e\u003ccode\u003e493796b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/iseraph-dev\"\u003e\u003ccode\u003e@​iseraph-dev\u003c/code\u003e\u003c/a\u003e! - Skips no-op pathname writes when normalizing SSR request URLs\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17712\"\u003e#17712\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/bd374b7507de8d706c845946fd847e76de6fc06b\"\u003e\u003ccode\u003ebd374b7\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/fkatsuhiro\"\u003e\u003ccode\u003e@​fkatsuhiro\u003c/code\u003e\u003c/a\u003e! - Updates deprecation messages target from Astro 7 to 8\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17719\"\u003e#17719\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/dac17688f691c6cecdff969aa48523bf17fc0657\"\u003e\u003ccode\u003edac1768\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/astrobot-houston\"\u003e\u003ccode\u003e@​astrobot-houston\u003c/code\u003e\u003c/a\u003e! - Fixes session ID validation to reject non-UUID cookie values before using them as storage keys\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17770\"\u003e#17770\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/84eb7e7db99573b80c339efe0392d959e7a9b6cf\"\u003e\u003ccode\u003e84eb7e7\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ccode\u003e--mode\u003c/code\u003e, \u003ccode\u003e--site\u003c/code\u003e, \u003ccode\u003e--base\u003c/code\u003e, \u003ccode\u003e--out-dir\u003c/code\u003e, \u003ccode\u003e--verbose\u003c/code\u003e, \u003ccode\u003e--silent\u003c/code\u003e, and \u003ccode\u003e--open\u003c/code\u003e flags being silently dropped when using \u003ccode\u003eastro dev --background\u003c/code\u003e or \u003ccode\u003eastro preview --background\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17713\"\u003e#17713\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/d035290a14afac8834885b727327a7f44d3a3a48\"\u003e\u003ccode\u003ed035290\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/wakqasahmed\"\u003e\u003ccode\u003e@​wakqasahmed\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ccode\u003econtent-modules.mjs\u003c/code\u003e not removing entries for deleted or renamed content files, which could cause Vite to attempt to resolve non-existent modules\u003c/p\u003e\n\u003cp\u003eAs part of this fix, \u003ccode\u003e#moduleImports\u003c/code\u003e is now fully rebuilt from \u003ccode\u003edeferredRender\u003c/code\u003e entries before every write, so a module import added only through the public \u003ccode\u003eaddModuleImport()\u003c/code\u003e API without a corresponding \u003ccode\u003edeferredRender\u003c/code\u003e entry in the store will no longer be preserved across writes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17743\"\u003e#17743\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/adc750fa27ea1d4767e30fc12e64a342fbebbd89\"\u003e\u003ccode\u003eadc750f\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/contactjawad\"\u003e\u003ccode\u003e@​contactjawad\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ccode\u003eAstro.preferredLocale\u003c/code\u003e and \u003ccode\u003eAstro.preferredLocaleList\u003c/code\u003e ignoring \u003ccode\u003eAccept-Language\u003c/code\u003e quality values when they are absent or \u003ccode\u003e0\u003c/code\u003e. An entry without an explicit \u003ccode\u003eq=\u003c/code\u003e now correctly counts as quality \u003ccode\u003e1.0\u003c/code\u003e (per RFC 7231) and an entry with \u003ccode\u003eq=0\u003c/code\u003e is treated as not acceptable, so the highest-quality locale is selected regardless of header order.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17757\"\u003e#17757\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/660991c820fbeb087b2f27361e6ebaeba8285358\"\u003e\u003ccode\u003e660991c\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes build errors showing wrong file location, missing line:col, and misleading hints when a plugin error (e.g. from MDX) is wrapped by Vite's build error\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/7cadf1055a61c85d0b05f3c7d8c709f7faa5cf0d\"\u003e\u003ccode\u003e7cadf10\u003c/code\u003e\u003c/a\u003e [ci] release (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17826\"\u003e#17826\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/ecb4082131490b4fe9a56aa44fda84b54ef8967b\"\u003e\u003ccode\u003eecb4082\u003c/code\u003e\u003c/a\u003e Update Sharp to 0.35.4 (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17837\"\u003e#17837\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/8bf6f1af679947ffbc702db26425f3f13a7f3040\"\u003e\u003ccode\u003e8bf6f1a\u003c/code\u003e\u003c/a\u003e chore: split v5/v6 changelogs (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17825\"\u003e#17825\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/db7c53b1707856866e06cdeeef1aa4ae3598b1f2\"\u003e\u003ccode\u003edb7c53b\u003c/code\u003e\u003c/a\u003e chore(deps): replace \u0026quot;find-process\u0026quot; with a smaller, lighter alternative (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17786\"\u003e#17786\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/eface15c86b38d44e94b841c9d1e27394c470600\"\u003e\u003ccode\u003eeface15\u003c/code\u003e\u003c/a\u003e [ci] release (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17815\"\u003e#17815\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/633855b0cabd55cc7b913eb556a739a6a2d93dd2\"\u003e\u003ccode\u003e633855b\u003c/code\u003e\u003c/a\u003e Use workerd's compatibility date for Cloudflare defaults (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17819\"\u003e#17819\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/55d38c868b7cbf2266649929c60ddf442abe674f\"\u003e\u003ccode\u003e55d38c8\u003c/code\u003e\u003c/a\u003e Deserialize each route once when loading the manifest (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17415\"\u003e#17415\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/a0d2fe3af25a25bc9b808070f25886c37d5be6fc\"\u003e\u003ccode\u003ea0d2fe3\u003c/code\u003e\u003c/a\u003e Pass file path to SVGO so \u003ccode\u003eprefixIds\u003c/code\u003e generates unique per-file prefixes (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17\"\u003e#17\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/ae26d18c71515c47ecbd7e1ffe5c5dfc29fbd613\"\u003e\u003ccode\u003eae26d18\u003c/code\u003e\u003c/a\u003e Handle GET and HEAD request bodies during rewrites (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17813\"\u003e#17813\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/023b48b139a2c40420b340f61b53a62b47a557e5\"\u003e\u003ccode\u003e023b48b\u003c/code\u003e\u003c/a\u003e Normalize request paths before route matching (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17772\"\u003e#17772\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/withastro/astro/commits/astro@7.2.8/packages/astro\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@babel/core` from 7.29.0 to 7.29.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/babel/babel/releases\"\u003e@​babel/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.7 (2026-05-25)\u003c/h2\u003e\n\u003cp\u003eRe-release all packages with npm provenance attestations\u003c/p\u003e\n\u003ch2\u003ev7.29.6 (2026-05-25)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18014\"\u003e#18014\u003c/a\u003e Catchup source map position in preserveFormat (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18001\"\u003e#18001\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e, \u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17998\"\u003e#17998\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 3\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMateusz Burzyński (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.5 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:house:  Internal\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@babel/*\u003c/code\u003e dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.4 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17974\"\u003e#17974\u003c/a\u003e [7.x backport]fix(systemjs): improve module string name support (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 1\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.3 (2026-04-30)\u003c/h2\u003e\n\u003ch4\u003e:eyeglasses: Spec Compliance\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17923\"\u003e#17923\u003c/a\u003e Support flow extends bound (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-helper-create-class-features-plugin\u003c/code\u003e, \u003ccode\u003ebabel-plugin-proposal-decorators\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17931\"\u003e#17931\u003c/a\u003e fix(decorators): replace super within all removed static elements (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-register\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17915\"\u003e#17915\u003c/a\u003e Fix thread synchronization issues in \u003ccode\u003e@babel/register\u003c/code\u003e (\u003ca href=\"https://github.com/liuxingbaoyu\"\u003e\u003ccode\u003e@​liuxingbaoyu\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-compat-data\u003c/code\u003e, \u003ccode\u003ebabel-plugin-bugfix-safari-rest-destructuring-rhs-array\u003c/code\u003e, \u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17788\"\u003e#17788\u003c/a\u003e Add bugfix plugin for Safari array rest destructuring bug (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:nail_care: Polish\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/4fba7541180bf5f58256d8e358b544e3831ad090\"\u003e\u003ccode\u003e4fba754\u003c/code\u003e\u003c/a\u003e v7.29.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/04ea6b27fdac8f40c3481aec2080ac9678779509\"\u003e\u003ccode\u003e04ea6b2\u003c/code\u003e\u003c/a\u003e v7.29.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/99f498a9b9fa0b900d603fbe8f6601bb3b9e42bb\"\u003e\u003ccode\u003e99f498a\u003c/code\u003e\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/18001\"\u003e#18001\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/feba0a3654c596bd369d1ef1231f5d56666d56dc\"\u003e\u003ccode\u003efeba0a3\u003c/code\u003e\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17998\"\u003e#17998\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/babel/babel/commits/v7.29.7/packages/babel-core\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@babel/plugin-transform-modules-systemjs` from 7.29.0 to 7.29.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/babel/babel/releases\"\u003e@​babel/plugin-transform-modules-systemjs's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.8 (2026-07-31)\u003c/h2\u003e\n\u003ch4\u003e:eyeglasses: Spec Compliance\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e, \u003ccode\u003ebabel-parser\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-spread\u003c/code\u003e, \u003ccode\u003ebabel-traverse\u003c/code\u003e, \u003ccode\u003ebabel-types\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17871\"\u003e#17871\u003c/a\u003e Disallow super call after new (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18046\"\u003e#18046\u003c/a\u003e fix(generator): improve new callee parens check (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-node\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18044\"\u003e#18044\u003c/a\u003e fix(systemjs): support \u003ccode\u003e__proto__\u003c/code\u003e as an export name (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 2\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.7 (2026-05-25)\u003c/h2\u003e\n\u003cp\u003eRe-release all packages with npm provenance attestations\u003c/p\u003e\n\u003ch2\u003ev7.29.6 (2026-05-25)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18014\"\u003e#18014\u003c/a\u003e Catchup source map position in preserveFormat (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18001\"\u003e#18001\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e, \u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17998\"\u003e#17998\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 3\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMateusz Burzyński (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.5 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:house:  Internal\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@babel/*\u003c/code\u003e dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.4 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17974\"\u003e#17974\u003c/a\u003e [7.x backport]fix(systemjs): improve module string name support (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 1\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/5de11ca9234379b78ef95df72aebbec93f28bf45\"\u003e\u003ccode\u003e5de11ca\u003c/code\u003e\u003c/a\u003e v7.29.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/f08d4342e1f189a56e7cee46e60a1817af96219e\"\u003e\u003ccode\u003ef08d434\u003c/code\u003e\u003c/a\u003e fix(systemjs): support \u003cstrong\u003eproto\u003c/strong\u003e as an export name (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs/issues/18044\"\u003e#18044\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/4fba7541180bf5f58256d8e358b544e3831ad090\"\u003e\u003ccode\u003e4fba754\u003c/code\u003e\u003c/a\u003e v7.29.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/a458f66074b97d54773db8159af673d23b26079b\"\u003e\u003ccode\u003ea458f66\u003c/code\u003e\u003c/a\u003e v7.29.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/32ebd5aaf2526ddd176fd6a3d1e3dc594abdc8d9\"\u003e\u003ccode\u003e32ebd5a\u003c/code\u003e\u003c/a\u003e [7.x backport]fix(systemjs): improve module string name support (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs/issues/17974\"\u003e#17974\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/babel/babel/commits/v7.29.8/packages/babel-plugin-transform-modules-systemjs\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.14 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24\"\u003e\u003ccode\u003e2203f4f\u003c/code\u003e\u003c/a\u003e 1.1.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd\"\u003e\u003ccode\u003e0b09384\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@opentelemetry/core` from 1.30.1 to 2.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/releases\"\u003e@​opentelemetry/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.8.0\u003c/h2\u003e\n\u003ch2\u003e2.8.0\u003c/h2\u003e\n\u003ch3\u003e:rocket: Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(sdk-trace-base): pretty-print \u003ccode\u003eSpanImpl\u003c/code\u003e, \u003ccode\u003eTracer\u003c/code\u003e, and \u003ccode\u003eBasicTracerProvider\u003c/code\u003e via \u003ccode\u003eutil.inspect\u003c/code\u003e so they render through \u003ccode\u003ediag\u003c/code\u003e and \u003ccode\u003econsole.log\u003c/code\u003e \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6690\"\u003e#6690\u003c/a\u003e \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(sdk-metrics): implement metric reader self-observability metrics \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6449\"\u003e#6449\u003c/a\u003e \u003ca href=\"https://github.com/anuraaga\"\u003e\u003ccode\u003e@​anuraaga\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(core): add \u003ccode\u003ehrTimeToSeconds\u003c/code\u003e \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6449\"\u003e#6449\u003c/a\u003e \u003ca href=\"https://github.com/anuraaga\"\u003e\u003ccode\u003e@​anuraaga\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(core): limit processing of incoming \u0026quot;baggage\u0026quot; header to 8192 bytes \u003ca href=\"https://github.com/pichlermarc\"\u003e\u003ccode\u003e@​pichlermarc\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.7.1\u003c/h2\u003e\n\u003ch2\u003e2.7.1\u003c/h2\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(core, api): defer trace state validation. Deprecate trace state implementation in api \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6459\"\u003e#6459\u003c/a\u003e \u003ca href=\"https://github.com/david-luna\"\u003e\u003ccode\u003e@​david-luna\u003c/code\u003e\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eimportant:\u003c/strong\u003e this bug fix may be breaking for certain uses of \u003ccode\u003eTraceState\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eset\u003c/code\u003e now returns the same \u003ccode\u003eTraceState\u003c/code\u003e instance if key/value are invalid or makes the while trace state invalid.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eunset\u003c/code\u003e now returns the same \u003ccode\u003eTraceState\u003c/code\u003e instance if key is not present.\u003c/li\u003e\n\u003cli\u003ebest-effort parsing of invalid \u003ccode\u003eTraceState\u003c/code\u003es has changed: when multiple keys with the same name are present, the most recent one will win.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:house: Internal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eperf(sdk-trace-base): optimize TraceIdRatioBasedSampler performance \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6284\"\u003e#6284\u003c/a\u003e \u003ca href=\"https://github.com/AbhiPrasad\"\u003e\u003ccode\u003e@​AbhiPrasad\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf(sdk-metrics): reduce loop overhead in sdk hot paths \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6593\"\u003e#6593\u003c/a\u003e \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.7.0\u003c/h2\u003e\n\u003ch2\u003e2.7.0\u003c/h2\u003e\n\u003ch3\u003e:rocket: Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(sdk-logs): implement log creation metrics \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6433\"\u003e#6433\u003c/a\u003e \u003ca href=\"https://github.com/anuraaga\"\u003e\u003ccode\u003e@​anuraaga\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(sdk-metrics): add the cardinalitySelector argument to PeriodicExportingMetricReaders\n\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6460\"\u003e#6460\u003c/a\u003e \u003ca href=\"https://github.com/starzlocker\"\u003e\u003ccode\u003e@​starzlocker\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(opentelemetry-core): add extra checks on internal merge function for safety \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6587\"\u003e#6587\u003c/a\u003e \u003ca href=\"https://github.com/maryliag\"\u003e\u003ccode\u003e@​maryliag\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(opentelemetry-resources): do not discard OTEL_RESOURCE_ATTRIBUTES when it contains empty kv pairs\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:house: Internal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003etest(exporter-zipkin): fix broken browser test assertions and add missing coverage \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6566\"\u003e#6566\u003c/a\u003e \u003ca href=\"https://github.com/overbalance\"\u003e\u003ccode\u003e@​overbalance\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(sdk-metrics): repair ExponentialHistogram tests \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6565\"\u003e#6565\u003c/a\u003e \u003ca href=\"https://github.com/overbalance\"\u003e\u003ccode\u003e@​overbalance\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md\"\u003e@​opentelemetry/core's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.8.0\u003c/h2\u003e\n\u003ch3\u003e:rocket: Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(sdk-trace-base): pretty-print \u003ccode\u003eSpanImpl\u003c/code\u003e, \u003ccode\u003eTracer\u003c/code\u003e, and \u003ccode\u003eBasicTracerProvider\u003c/code\u003e via \u003ccode\u003eutil.inspect\u003c/code\u003e so they render through \u003ccode\u003ediag\u003c/code\u003e and \u003ccode\u003econsole.log\u003c/code\u003e \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6690\"\u003e#6690\u003c/a\u003e \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(sdk-metrics): implement metric reader self-observability metrics \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6449\"\u003e#6449\u003c/a\u003e \u003ca href=\"https://github.com/anuraaga\"\u003e\u003ccode\u003e@​anuraaga\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(core): add \u003ccode\u003ehrTimeToSeconds\u003c/code\u003e \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6449\"\u003e#6449\u003c/a\u003e \u003ca href=\"https://github.com/anuraaga\"\u003e\u003ccode\u003e@​anuraaga\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(core): limit processing of incoming \u0026quot;baggage\u0026quot; header to 8192 bytes \u003ca href=\"https://github.com/pichlermarc\"\u003e\u003ccode\u003e@​pichlermarc\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.7.1\u003c/h2\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(core, api): defer trace state validation. Deprecate trace state implementation in api \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6459\"\u003e#6459\u003c/a\u003e \u003ca href=\"https://github.com/david-luna\"\u003e\u003ccode\u003e@​david-luna\u003c/code\u003e\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eimportant:\u003c/strong\u003e this bug fix may be breaking for certain uses of \u003ccode\u003eTraceState\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eset\u003c/code\u003e now returns the same \u003ccode\u003eTraceState\u003c/code\u003e instance if key/value are invalid or makes the while trace state invalid.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eunset\u003c/code\u003e now returns the same \u003ccode\u003eTraceState\u003c/code\u003e instance if key is not present.\u003c/li\u003e\n\u003cli\u003ebest-effort parsing of invalid \u003ccode\u003eTraceState\u003c/code\u003es has changed: when multiple keys with the same name are present, the most recent one will win.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:house: Internal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eperf(sdk-trace-base): optimize TraceIdRatioBasedSampler performance \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6284\"\u003e#6284\u003c/a\u003e \u003ca href=\"https://github.com/AbhiPrasad\"\u003e\u003ccode\u003e@​AbhiPrasad\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: test Node.js 26 in CI \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6671\"\u003e#6671\u003c/a\u003e \u003ca href=\"https://github.com/cjihrig\"\u003e\u003ccode\u003e@​cjihrig\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.7.0\u003c/h2\u003e\n\u003ch3\u003e:rocket: Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(sdk-logs): implement log creation metrics \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6433\"\u003e#6433\u003c/a\u003e \u003ca href=\"https://github.com/anuraaga\"\u003e\u003ccode\u003e@​anuraaga\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(sdk-metrics): add the cardinalitySelector argument to PeriodicExportingMetricReaders\n\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6460\"\u003e#6460\u003c/a\u003e \u003ca href=\"https://github.com/starzlocker\"\u003e\u003ccode\u003e@​starzlocker\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(opentelemetry-core): add extra checks on internal merge function for safety \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6587\"\u003e#6587\u003c/a\u003e \u003ca href=\"https://github.com/maryliag\"\u003e\u003ccode\u003e@​maryliag\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(opentelemetry-resources): do not discard OTEL_RESOURCE_ATTRIBUTES when it contains empty kv pairs\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:house: Internal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003etest(exporter-zipkin): fix broken browser test assertions and add missing coverage \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6566\"\u003e#6566\u003c/a\u003e \u003ca href=\"https://github.com/overbalance\"\u003e\u003ccode\u003e@​overbalance\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(sdk-metrics): repair ExponentialHistogram tests \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6565\"\u003e#6565\u003c/a\u003e \u003ca href=\"https://github.com/overbalance\"\u003e\u003ccode\u003e@​overbalance\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf(sdk-metrics): reduce loop overhead in sdk hot paths \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6593\"\u003e#6593\u003c/a\u003e \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.6.1\u003c/h2\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/13a035bc695996cf4aec885fef7b9866f48bc555\"\u003e\u003ccode\u003e13a035b\u003c/code\u003e\u003c/a\u003e chore: prepare next release (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6756\"\u003e#6756\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/4b13587d1e08b47baf153e5312ccd08a3240d074\"\u003e\u003ccode\u003e4b13587\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/71d195c508320295f1892aaed1ee2f1971ffb470\"\u003e\u003ccode\u003e71d195c\u003c/code\u003e\u003c/a\u003e chore(renovate): set minimumReleaseAge to 3 days (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6792\"\u003e#6792\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/555fca6ce94fb8d40a5f869dbd28e43143b4e730\"\u003e\u003ccode\u003e555fca6\u003c/code\u003e\u003c/a\u003e Update renovate.json to use matchManagers (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6141\"\u003e#6141\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/b711a81d5262904245d70f1857b6f3bc811b22cd\"\u003e\u003ccode\u003eb711a81\u003c/code\u003e\u003c/a\u003e docs(otlp-exporter-base): add typedoc entry points so public API is indexed a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/da704029ccd291d65402f3d1c469bd3f25aec047\"\u003e\u003ccode\u003eda70402\u003c/code\u003e\u003c/a\u003e fix(ci): supply-chain sec: disable caching in release-related workflow (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6790\"\u003e#6790\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/002267b1c639aac1d2f1d6e5c7ac3ed023109ea0\"\u003e\u003ccode\u003e002267b\u003c/code\u003e\u003c/a\u003e chore: complete the move to the smaller SPDX license header (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6791\"\u003e#6791\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/056ef9c4e1ddf9306477b7ce26acc7be489f9c6c\"\u003e\u003ccode\u003e056ef9c\u003c/code\u003e\u003c/a\u003e feat(sdk-metrics): implement metric reader metrics (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6449\"\u003e#6449\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/3bd69ce18011f9a16a7231489d9c3acc8294e8d9\"\u003e\u003ccode\u003e3bd69ce\u003c/code\u003e\u003c/a\u003e fix(configuration): improve environment variable substitution to handle all t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/bfbda7c2d90e1686f51cd0fc4d02d785ab9a9cc0\"\u003e\u003ccode\u003ebfbda7c\u003c/code\u003e\u003c/a\u003e docs(exporter-trace-otlp-grpc): import CompressionAlgorithm from otlp-exporte...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/compare/v1.30.1...v2.8.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​opentelemetry/core\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `esbuild` from 0.25.12 to 0.28.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/evanw/esbuild/releases\"\u003eesbuild's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.28.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix tree shaking bug due to TypeScript import alias (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4507\"\u003e#4507\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific \u003ccode\u003eimport\u003c/code\u003e assignment and looks something like this:\u003c/p\u003e\n\u003cpre lang=\"ts\"\u003e\u003ccode\u003eimport Base from './dep.js';\r\nimport Alias = Base.SomeType;\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix CSS minification bug involving \u003ccode\u003e\u0026amp;\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4497\"\u003e#4497\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug where esbuild's CSS minifier incorrectly removed a \u003ccode\u003e\u0026amp;\u003c/code\u003e when it was unsafe to do so. Here is an example:\u003c/p\u003e\n\u003cpre lang=\"css\"\u003e\u003ccode\u003e/* Original code */\r\n.a .b {\r\n  \u0026amp; .b:not(\u0026amp; .c) {\r\n    color: red;\r\n  }\r\n}\r\n\u003cp\u003e/* Old output (with --minify) */\u003cbr /\u003e\n.a .b{.b:not(\u0026amp; .c){color:red}}\u003c/p\u003e\n\u003cp\u003e/* New output (with --minify) */\u003cbr /\u003e\n.a .b{\u0026amp; .b:not(\u0026amp; .c){color:red}}\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eThis should match \u003ccode\u003e\u0026lt;span class=\u0026quot;a\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;yes\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u003c/code\u003e but not \u003ccode\u003e\u0026lt;span class=\u0026quot;a\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;no\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u003c/code\u003e. The old output incorrectly matched both.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAvoid overwriting input files without \u003ccode\u003e--allow-overwrite\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4484\"\u003e#4484\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eFor example: \u003ccode\u003eesbuild input.js --outfile=input.js\u003c/code\u003e tells esbuild to overwrite \u003ccode\u003einput.js\u003c/code\u003e with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.\u003c/p\u003e\n\u003cp\u003eThis release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless \u003ccode\u003e--allow-overwrite\u003c/code\u003e is explicitly present. This is done by not writing out any files when a build error is encountered.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix incorrect code generated when using top-level await (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4498\"\u003e#4498\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003ePreviously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing \u003ccode\u003easync\u003c/code\u003e on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an \u003ccode\u003easync\u003c/code\u003e module wrapper.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix a minification bug with lowered logical assignment operators (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4508\"\u003e#4508\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Original code\r\nfunction foo() {\r\n  let x\r\n  bar(x ||= {})\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/evanw/esbuild/blob/main/CHANGELOG-2025.md\"\u003eesbuild's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog: 2025\u003c/h1\u003e\n\u003cp\u003eThis changelog documents all esbuild versions published in the year 2025 (versions 0.25.0 through 0.27.2).\u003c/p\u003e\n\u003ch2\u003e0.27.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eAllow import path specifiers starting with \u003ccode\u003e#/\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/evanw/esbuild/pull/4361\"\u003e#4361\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003ePreviously the specification for \u003ccode\u003epackage.json\u003c/code\u003e disallowed import path specifiers starting with \u003ccode\u003e#/\u003c/code\u003e, but this restriction \u003ca href=\"https://redirect.github.com/nodejs/node/pull/60864\"\u003ehas recently been relaxed\u003c/a\u003e and support for it is being added across the JavaScript ecosystem. One use case is using it for a wildcard pattern such as mapping \u003ccode\u003e#/*\u003c/code\u003e to \u003ccode\u003e./src/*\u003c/code\u003e (previously you had to use another character such as \u003ccode\u003e#_*\u003c/code\u003e instead, which was more confusing). There is some more context in \u003ca href=\"https://redirect.github.com/nodejs/node/issues/49182\"\u003enodejs/node#49182\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eThis change was contributed by \u003ca href=\"https://github.com/hybrist\"\u003e\u003ccode\u003e@​hybrist\u003c/code\u003e\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAutomatically add the \u003ccode\u003e-webkit-mask\u003c/code\u003e prefix (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4357\"\u003e#4357\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4358\"\u003e#4358\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release automatically adds the \u003ccode\u003e-webkit-\u003c/code\u003e vendor prefix for the \u003ca href=\"https://developer.mozilla.org/en-US/docs/Web/CSS/Reference/Properties/mask\"\u003e\u003ccode\u003emask\u003c/code\u003e\u003c/a\u003e CSS shorthand property:\u003c/p\u003e\n\u003cpre lang=\"css\"\u003e\u003ccode\u003e/* Original code */\nmain {\n  mask: url(x.png) center/5rem no-repeat\n}\n\u003cp\u003e/* Old output (with --target=chrome110) */\u003cbr /\u003e\nmain {\u003cbr /\u003e\nmask: url(x.png) center/5rem no-repeat;\u003cbr /\u003e\n}\u003c/p\u003e\n\u003cp\u003e/* New output (with --target=chrome110) */\u003cbr /\u003e\nmain {\u003cbr /\u003e\n-webkit-mask: url(x.png) center/5rem no-repeat;\u003cbr /\u003e\nmask: url(x.png) center/5rem no-repeat;\u003cbr /\u003e\n}\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eThis change was contributed by \u003ca href=\"https://github.com/BPJEnnova\"\u003e\u003ccode\u003e@​BPJEnnova\u003c/code\u003e\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdditional minification of \u003ccode\u003eswitch\u003c/code\u003e statements (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4176\"\u003e#4176\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4359\"\u003e#4359\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release contains additional minification patterns for reducing \u003ccode\u003eswitch\u003c/code\u003e statements. Here is an example:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Original code\nswitch (x) {\n  case 0:\n    foo()\n    break\n  case 1:\n  default:\n    bar()\n}\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/609683d892977362a0f99026cb74b96263d728a9\"\u003e\u003ccode\u003e609683d\u003c/code\u003e\u003c/a\u003e publish 0.28.2 to npm\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/11b1fe48df6859393d9469f323b5ebd17baaf989\"\u003e\u003ccode\u003e11b1fe4\u003c/code\u003e\u003c/a\u003e add to release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/ab50d91559a27e54cd0a27a403389130ea10d97d\"\u003e\u003ccode\u003eab50d91\u003c/code\u003e\u003c/a\u003e css: fix green/blue channel swap in oklch gamut mapping (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4488\"\u003e#4488\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/04627b6cf99b4a7491bebb0268173a7c77a85030\"\u003e\u003ccode\u003e04627b6\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4498\"\u003e#4498\u003c/a\u003e: \u003ccode\u003easync\u003c/code\u003e TLA checks need a worklist\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/5c15177a308c7224604058a769c4abf0a66b0a36\"\u003e\u003ccode\u003e5c15177\u003c/code\u003e\u003c/a\u003e disable \u003ccode\u003egopls\u003c/code\u003e in the \u003ccode\u003ego\u003c/code\u003e folder\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/fc2ee9babc5a2e8ea7ec7c10dd5850b71f7cec7e\"\u003e\u003ccode\u003efc2ee9b\u003c/code\u003e\u003c/a\u003e css: adjust parser to allow \u003ccode\u003e--foo: {...}\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/209db54371e62ad1c50e12e56bb93c74c53b0408\"\u003e\u003ccode\u003e209db54\u003c/code\u003e\u003c/a\u003e release notes for css nesting bugfix\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/c625d31bf08a0647ec724bf76c7115f7aec55971\"\u003e\u003ccode\u003ec625d31\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4497\"\u003e#4497\u003c/a\u003e: preserve nested ampersands during minification (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4500\"\u003e#4500\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/34474e278528a60f58c959c0f422d2bfa6f6886d\"\u003e\u003ccode\u003e34474e2\u003c/code\u003e\u003c/a\u003e better isolation of current part in js parser\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/07f6e8c50677e0b41e5ed726c08b0ea200b14e5b\"\u003e\u003ccode\u003e07f6e8c\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4507\"\u003e#4507\u003c/a\u003e: \u003ccode\u003eimport\u003c/code\u003e assignment tree-shaking bug\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/evanw/esbuild/compare/v0.25.12...v0.28.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for esbuild since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `vite` from 6.4.2 to 7.3.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/releases\"\u003evite's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.3.6\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.6/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.3.5\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.5/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.3.3\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.3/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.3.2\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.2/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.3.1\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.1/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.3.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.0/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.2.7\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.2.7/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.2.6\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.2.6/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.2.5\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.2.5/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eNote: 7.2.5 failed to publish so it is skipped on npm\u003c/em\u003e\u003c/p\u003e\n\u003ch2\u003ev7.2.4\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.2.4/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.2.3\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.2.3/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.2.2\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.2.2/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.2.1\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.2.1/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.2.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.2.0/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.2.0-beta.1\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.2.0-beta.1/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.2.0-beta.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.2.0-beta.0/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.6/packages/vite/CHANGELOG.md\"\u003evite's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.5...v7.3.6\"\u003e7.3.6\u003c/a\u003e (2026-06-25)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eallow esbuild 0.28 (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22743\"\u003e#22743\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/a24931e7934e80eff5895b89d9e612ad3ad3e1f4\"\u003ea24931e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.3...v7.3.5\"\u003e7.3.5\u003c/a\u003e (2026-06-01)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ebackport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22572\"\u003e#22572\u003c/a\u003e, reject windows alternate paths (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22574\"\u003e#22574\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8c1855607b7c9884c4565d897ee98899a008a2d0\"\u003e8c18556\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e backport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22571\"\u003e#22571\u003c/a\u003e, reject UNC paths for launch-editor-middleware (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22573\"\u003e#22573\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/f20d64bef6e0ef1e4fa7a9783281c7bba0ce5292\"\u003ef20d64b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMiscellaneous Chores\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eskip v7.3.4 release (\u003ca href=\"https://github.com/vitejs/vite/commit/8a6a0c9fc734dbfe293ac33a4954506ee50430e1\"\u003e8a6a0c9\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.3...v7.3.4\"\u003e7.3.4\u003c/a\u003e (2026-06-01)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ebackport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22572\"\u003e#22572\u003c/a\u003e, reject windows alternate paths (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22574\"\u003e#22574\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8c1855607b7c9884c4565d897ee98899a008a2d0\"\u003e8c18556\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e backport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22571\"\u003e#22571\u003c/a\u003e, reject UNC paths for launch-editor-middleware (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22573\"\u003e#22573\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/f20d64bef6e0ef1e4fa7a9783281c7bba0ce5292\"\u003ef20d64b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.2...v7.3.3\"\u003e7.3.3\u003c/a\u003e (2026-05-07)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eavoid destructure lowering for newer safari (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22346\"\u003e#22346\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/5ab51c0f76f0896175e02ad797c1f5fe116d02f4\"\u003e5ab51c0\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.1...v7.3.2\"\u003e7.3.2\u003c/a\u003e (2026-04-06)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eavoid...\n\n_Description has been truncated_","html_url":"https://github.com/milliorn/portfolio/pull/310","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/milliorn%2Fportfolio/issues/310","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/310/packages"},{"uuid":"5438857810","node_id":"PR_kwDOSmyDHM8AAAABDUdj-Q","number":12,"state":"open","title":"build(deps): bump the npm_and_yarn group across 1 directory with 9 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-13T07:42:39.000Z","updated_at":"2026-09-13T07:43:01.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"npm_and_yarn","update_count":9,"packages":[{"name":"next","old_version":"16.2.9","new_version":"16.3.5","repository_url":"https://github.com/vercel/next.js"},{"name":"baseline-browser-mapping","old_version":"2.10.32","new_version":"2.11.23","repository_url":"https://github.com/web-platform-dx/baseline-browser-mapping"},{"name":"browserslist","old_version":"4.28.2","new_version":"4.28.9","repository_url":"https://github.com/browserslist/browserslist"},{"name":"fast-uri","old_version":"3.1.4","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"find-my-way","old_version":"9.6.0","new_version":"9.7.0","repository_url":"https://github.com/delvedor/find-my-way"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 5 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [next](https://github.com/vercel/next.js) | `16.2.9` | `16.3.5` |\n| [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) | `2.10.32` | `2.11.23` |\n| [browserslist](https://github.com/browserslist/browserslist) | `4.28.2` | `4.28.9` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.4` | `3.1.7` |\n| [find-my-way](https://github.com/delvedor/find-my-way) | `9.6.0` | `9.7.0` |\n\n\nUpdates `next` from 16.2.9 to 16.3.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003enext's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.5\u003c/h2\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does not include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003enext/image: Skip 0-byte entries when initializing disk LRU cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98185\"\u003e#98185\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enext/image: Reject empty images when reading/writing to the disk cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98186\"\u003e#98186\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEmit whole-app server NFTs when \u003ccode\u003eoutput: 'standalone'\u003c/code\u003e is used with an adapter (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98167\"\u003e#98167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd CSP nonce to script tags of loading and template files (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98403\"\u003e#98403\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003euse cache\u003c/code\u003e prerender signal retention (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98448\"\u003e#98448\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.4\u003c/h2\u003e\n\u003cp\u003eFollow-up release to \u003ca href=\"https://github.com/vercel/next.js/releases/tag/v16.3.3\"\u003ev16.3.3\u003c/a\u003e re-enabling AVIF Image Optimization (\u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97949\"\u003e#97949\u003c/a\u003e).\u003c/p\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003etestmode: Fix infinite recursion in testmode passthrough fetch (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97691\"\u003e#97691\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix build error when aliasing typescript to \u003ccode\u003e@​typescript/typescript6\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97997\"\u003e#97997\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix unset crossOrigin in Turbopack manifests (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97930\"\u003e#97930\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.3\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eCritical:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36\"\u003eUnauthenticated Remote Code Execution on windows-hosted servers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4\"\u003eUnauthenticated Remote Code Execution in Image Optimization API when AVIF files are used\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.2\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Scope app-entry export validation to files inside the app directory (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97357\"\u003e#97357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[backport] Fix catch-all index page being served for every other slug (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97416\"\u003e#97416\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: don't trace embedded WASM loader helpers (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97353\"\u003e#97353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97463\"\u003e#97463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: retain conditions when replacing resolve request keys (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97453\"\u003e#97453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Fix Turbopack worker chunk loading with asset prefix (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97419\"\u003e#97419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97603\"\u003e#97603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/lubieowoce\"\u003e\u003ccode\u003e@​lubieowoce\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[16.x] Turbopack: don't strip async-module runtime from shared runtime chunks by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96653\"\u003evercel/next.js#96653\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/ca2c75eb7f8d9dd012a8bb83c06132149fe221f9\"\u003e\u003ccode\u003eca2c75e\u003c/code\u003e\u003c/a\u003e v16.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/14fb290de65077e9f1e22ef56d8de6cc1e63d436\"\u003e\u003ccode\u003e14fb290\u003c/code\u003e\u003c/a\u003e [backport] Fix use cache prerender signal retention (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98448\"\u003e#98448\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/2b1f28dbe1de344807ec0946a85171bc890a6047\"\u003e\u003ccode\u003e2b1f28d\u003c/code\u003e\u003c/a\u003e [16.3.x] Add CSP nonce to script tags of loading and template files (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98403\"\u003e#98403\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/4b56cee3f01d3b249edcd798b51895d5126a4170\"\u003e\u003ccode\u003e4b56cee\u003c/code\u003e\u003c/a\u003e [16.3.x] Backport docs fixes (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98317\"\u003e#98317\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/5568a02a7d47f9cb088e58350f2c2e68d9e93a00\"\u003e\u003ccode\u003e5568a02\u003c/code\u003e\u003c/a\u003e [backport] docs: local development: Rewrite docker section, add Windows Dev D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/93249ab2144132abfd4a8d611dad5b5978107ee2\"\u003e\u003ccode\u003e93249ab\u003c/code\u003e\u003c/a\u003e [16.3.X] Emit whole-app server NFTs when \u003ccode\u003eoutput: 'standalone'\u003c/code\u003e is used with ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/6549fd7c4e15a8883b0ad1c2ef67dec287a44f12\"\u003e\u003ccode\u003e6549fd7\u003c/code\u003e\u003c/a\u003e [16.3.x] next/image: reject empty image on read/write to disk cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98186\"\u003e#98186\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/d9eac96e7526ff0b9cb51db9801f06e741fe1960\"\u003e\u003ccode\u003ed9eac96\u003c/code\u003e\u003c/a\u003e [16.3.x] next/image: skip 0-byte entries when initializing disk LRU cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/9\"\u003e#9\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/84b35feccb2b53a563e41ad2dfe7a5fe08c58d3f\"\u003e\u003ccode\u003e84b35fe\u003c/code\u003e\u003c/a\u003e [test] Fix 16.3 deploy test assertions (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98133\"\u003e#98133\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/14f9c1ac4e084a44633c354476ddeaf70969cd90\"\u003e\u003ccode\u003e14f9c1a\u003c/code\u003e\u003c/a\u003e [16.3.x][ci] Run flake detection and new deploy tests when merged and on back...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/compare/v16.2.9...v16.3.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.16 to 8.5.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8\"\u003e\u003ccode\u003e7beca13\u003c/code\u003e\u003c/a\u003e Does no load source map file without opts.from\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/decea51421682341401575b3740709fda0e12930\"\u003e\u003ccode\u003edecea51\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/c18e30d126395d42a0726aa00e03a8f1088985ae\"\u003e\u003ccode\u003ec18e30d\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/98a39ad73d163a90be924d5126c771262110f1fc\"\u003e\u003ccode\u003e98a39ad\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/a3e48c492ddec0e4879d513b8b995fee887af352\"\u003e\u003ccode\u003ea3e48c4\u003c/code\u003e\u003c/a\u003e Release 8.5.22 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f49d6911795f53b2cfe023bb686bf1144ec30618\"\u003e\u003ccode\u003ef49d691\u003c/code\u003e\u003c/a\u003e Fix custom property losing its semicolon before a comment (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2117\"\u003e#2117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/28e0daf8f2fe5ba9e19ea3f8c27c8fe176f9419e\"\u003e\u003ccode\u003e28e0daf\u003c/code\u003e\u003c/a\u003e Release 8.5.21 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3d2b4e43e38274f233b5609d09687cadad8215d9\"\u003e\u003ccode\u003e3d2b4e4\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.16...8.5.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `baseline-browser-mapping` from 2.10.32 to 2.11.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/releases\"\u003ebaseline-browser-mapping's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.11.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed in 2.11.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: Adds a new \u003ccode\u003egetTimeline()\u003c/code\u003e method for getting the series of minimum browser changes, either grouped by date or by browser.\u003c/li\u003e\n\u003cli\u003erefactor: Substantial refactoring of the data compression process that replaces the full list of browsers from \u003ccode\u003e@mdn/browser-compat-data\u003c/code\u003e and \u003ccode\u003edownstream-browsers.json\u003c/code\u003e and features from \u003ccode\u003eweb-features\u003c/code\u003e (in their very pared down form) with a change-list timeline that reflects which versions supported Baseline (newly available) on a given date.  Thanks to \u003ca href=\"https://github.com/swwind\"\u003e\u003ccode\u003e@​swwind\u003c/code\u003e\u003c/a\u003e for the idea!\u003c/li\u003e\n\u003cli\u003erefactor: Some common functions have been moved to a \u003ccode\u003eutil.ts\u003c/code\u003e module for use in other scripts.\u003c/li\u003e\n\u003cli\u003efix: Removes \u003ccode\u003eprocess.exit()\u003c/code\u003e calls when unsupported option combinations are passed to getCompatibleVersions() and \u003ccode\u003egetAllVersions()\u003c/code\u003e in favour of throwing an \u003ccode\u003eError\u003c/code\u003e.  There is a small security risk with \u003ccode\u003eprocess.exit()\u003c/code\u003e calls that sites accepting unsanitised inputs could be the subject of attacks.  Unsupported config options now throw and Error which should allow for more graceful handling.  Thanks to \u003ca href=\"https://github.com/bnbdr\"\u003e\u003ccode\u003e@​bnbdr\u003c/code\u003e\u003c/a\u003e for flagging this as vulnerability CVE-2026-45819 .\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFixes \u003ca href=\"https://redirect.github.com/web-platform-dx/baseline-browser-mapping/issues/134\"\u003e#134\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.10.44...v2.11.0\"\u003ehttps://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.10.44...v2.11.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/ebdc72f5637922808cfe1fbf9e67897ba9f89677\"\u003e\u003ccode\u003eebdc72f\u003c/code\u003e\u003c/a\u003e Patch to 2.11.23 because browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/55fa3a1503097faad7a9806d6c08029a36cb19e3\"\u003e\u003ccode\u003e55fa3a1\u003c/code\u003e\u003c/a\u003e Browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/5ac60db1f4eedbd9b61dfa6db0cab10cccc19c2a\"\u003e\u003ccode\u003e5ac60db\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/af7c3c4ebc2692844e521fada6c8d49250795f10\"\u003e\u003ccode\u003eaf7c3c4\u003c/code\u003e\u003c/a\u003e Patch to 2.11.22 because browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/7e10cadb03c00cb5eab538d62b6d16511cd93841\"\u003e\u003ccode\u003e7e10cad\u003c/code\u003e\u003c/a\u003e Browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/ebb97027ff15d916e66b02feb9e019d8c7bab081\"\u003e\u003ccode\u003eebb9702\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/ecc57a365d502e0c85574e45751c1b7475689936\"\u003e\u003ccode\u003eecc57a3\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/0e5ed80e21dda23cac3dc1f6ec37e6b5fc4ea734\"\u003e\u003ccode\u003e0e5ed80\u003c/code\u003e\u003c/a\u003e Patch to 2.11.21 because browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/11da0b699d6d03a1e30b37a8fe7a4f8d96e06f4d\"\u003e\u003ccode\u003e11da0b6\u003c/code\u003e\u003c/a\u003e Browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/69fcc81987ecc7dbbf4d21e17be8c4adf642aa2b\"\u003e\u003ccode\u003e69fcc81\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.10.32...v2.11.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `browserslist` from 4.28.2 to 4.28.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/releases\"\u003ebrowserslist's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eincluding kaios\u003c/code\u003e in baseline queries (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved parsing performance.\u003c/li\u003e\n\u003cli\u003eFixed unbounded memory growth (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed prototype write issue (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Electron version queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003e\u0026gt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;=\u003c/code\u003e queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eSyntaxError\u003c/code\u003e regression of 4.28.3.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed baseline query case-insensitivity (by \u003ca href=\"https://github.com/swwind\"\u003e\u003ccode\u003e@​swwind\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md\"\u003ebrowserslist's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eincluding kaios\u003c/code\u003e in baseline queries (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved parsing performance.\u003c/li\u003e\n\u003cli\u003eFixed unbounded memory growth (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed prototype write issue (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Electron version queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003e\u0026gt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;=\u003c/code\u003e queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eSyntaxError\u003c/code\u003e regression of 4.28.3.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed baseline query case-insensitivity (by \u003ca href=\"https://github.com/swwind\"\u003e\u003ccode\u003e@​swwind\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/12ed5252dabc14fee4e97b465894b2f90910ca62\"\u003e\u003ccode\u003e12ed525\u003c/code\u003e\u003c/a\u003e Release 4.28.9 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/b1d8cf9d7a7dc76f6585425a8360218289194297\"\u003e\u003ccode\u003eb1d8cf9\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/21517b651c915cdbbfb8c122268bc36f5cabb7ef\"\u003e\u003ccode\u003e21517b6\u003c/code\u003e\u003c/a\u003e Improve \u003ccode\u003eor\u003c/code\u003e parsing performance\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/f2f2e6cfb01bb4942941d328737546f4e2ae41ad\"\u003e\u003ccode\u003ef2f2e6c\u003c/code\u003e\u003c/a\u003e Release 4.28.8 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/d0787c88fa29ba895fea51cfe921232c7b5d1377\"\u003e\u003ccode\u003ed0787c8\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/fcf8fa9857b30ccdf801a548f5d09d3c4ff0d43f\"\u003e\u003ccode\u003efcf8fa9\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/browserslist/browserslist/issues/939\"\u003e#939\u003c/a\u003e from Jaybhade/fix/baseline-kaios-without-downstream\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/57ecd64454e9252afdd6a7e76926e13dda48a38c\"\u003e\u003ccode\u003e57ecd64\u003c/code\u003e\u003c/a\u003e fix: support \u0026quot;including kaios\u0026quot; without downstream\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/093a0f67bb0becda55235d767b134df3197c54a1\"\u003e\u003ccode\u003e093a0f6\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/b637868045806d2fba4c24eb0060e4cc8b1db276\"\u003e\u003ccode\u003eb637868\u003c/code\u003e\u003c/a\u003e Release 4.28.7 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/313f4659b9f985ade89d1d6a54a860371c41cc46\"\u003e\u003ccode\u003e313f465\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/browserslist/browserslist/compare/4.28.2...4.28.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for browserslist since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-uri` from 3.1.4 to 3.1.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `find-my-way` from 9.6.0 to 9.7.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/delvedor/find-my-way/releases\"\u003efind-my-way's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev9.7.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: backtrack on regex param mismatch by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/427\"\u003edelvedor/find-my-way#427\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: apply root path fallback for optional params in off() by \u003ca href=\"https://github.com/aquie00t\"\u003e\u003ccode\u003e@​aquie00t\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/428\"\u003edelvedor/find-my-way#428\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: add node v26 to test matrix by \u003ca href=\"https://github.com/aquie00t\"\u003e\u003ccode\u003e@​aquie00t\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/435\"\u003edelvedor/find-my-way#435\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf(host): cache regex lookup results in HostStorage by \u003ca href=\"https://github.com/aquie00t\"\u003e\u003ccode\u003e@​aquie00t\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/436\"\u003edelvedor/find-my-way#436\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump inquirer from 13.4.3 to 14.0.2 in the dev-dependencies group by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/437\"\u003edelvedor/find-my-way#437\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump fastify/github-action-merge-dependabot from 3.12.0 to 3.15.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/438\"\u003edelvedor/find-my-way#438\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump \u003ccode\u003e@​types/node\u003c/code\u003e from 25.9.4 to 26.1.0 in the dev-dependencies group by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/440\"\u003edelvedor/find-my-way#440\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: prevent done from being called multiple times on async constraint errors by \u003ca href=\"https://github.com/deepview-autofix\"\u003e\u003ccode\u003e@​deepview-autofix\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/425\"\u003edelvedor/find-my-way#425\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: align isParamSafe state in findRoute with _on by \u003ca href=\"https://github.com/deepview-autofix\"\u003e\u003ccode\u003e@​deepview-autofix\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/424\"\u003edelvedor/find-my-way#424\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump actions/checkout from 6 to 7 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/439\"\u003edelvedor/find-my-way#439\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid crash on undefined regex capture during route lookup by \u003ca href=\"https://github.com/bianyifan\"\u003e\u003ccode\u003e@​bianyifan\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/441\"\u003edelvedor/find-my-way#441\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aquie00t\"\u003e\u003ccode\u003e@​aquie00t\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/428\"\u003edelvedor/find-my-way#428\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/deepview-autofix\"\u003e\u003ccode\u003e@​deepview-autofix\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/425\"\u003edelvedor/find-my-way#425\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bianyifan\"\u003e\u003ccode\u003e@​bianyifan\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/441\"\u003edelvedor/find-my-way#441\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/delvedor/find-my-way/compare/v9.6.0...v9.7.0\"\u003ehttps://github.com/delvedor/find-my-way/compare/v9.6.0...v9.7.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/delvedor/find-my-way/commit/827248e64fe17e44cbd9690e4eb0121e51256385\"\u003e\u003ccode\u003e827248e\u003c/code\u003e\u003c/a\u003e Bumped v9.7.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/delvedor/find-my-way/commit/b9d7bf17cd1dbc01590010ef66f66f14ee76cbb2\"\u003e\u003ccode\u003eb9d7bf1\u003c/code\u003e\u003c/a\u003e Merge branch 'main' of github.com:delvedor/find-my-way\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/delvedor/find-my-way/commit/b7b5657bd44517a20204c2c6432e0c19528412b3\"\u003e\u003ccode\u003eb7b5657\u003c/code\u003e\u003c/a\u003e fix: avoid crash on undefined regex capture during route lookup (\u003ca href=\"https://redirect.github.com/delvedor/find-my-way/issues/441\"\u003e#441\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/delvedor/find-my-way/commit/4263d82315bc09d1e6f3b2d3fa3e2be28a6efebf\"\u003e\u003ccode\u003e4263d82\u003c/code\u003e\u003c/a\u003e chore: bump actions/checkout from 6 to 7 (\u003ca href=\"https://redirect.github.com/delvedor/find-my-way/issues/439\"\u003e#439\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/delvedor/find-my-way/commit/66d30150c6eeebf9499fa9d0cd7b0425a4f91c10\"\u003e\u003ccode\u003e66d3015\u003c/code\u003e\u003c/a\u003e fix: align isParamSafe state in findRoute with _on (\u003ca href=\"https://redirect.github.com/delvedor/find-my-way/issues/424\"\u003e#424\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/delvedor/find-my-way/commit/75e47287c19247d172291e4713220310dfcf4877\"\u003e\u003ccode\u003e75e4728\u003c/code\u003e\u003c/a\u003e fix: prevent done from being called multiple times on async constraint errors...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/delvedor/find-my-way/commit/902a02dd09613e0ed08bbc9d911d3e1123470fc2\"\u003e\u003ccode\u003e902a02d\u003c/code\u003e\u003c/a\u003e chore: bump \u003ccode\u003e@​types/node\u003c/code\u003e in the dev-dependencies group (\u003ca href=\"https://redirect.github.com/delvedor/find-my-way/issues/440\"\u003e#440\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/delvedor/find-my-way/commit/b803e4ee59092d31d6e06c714552da9c086400f0\"\u003e\u003ccode\u003eb803e4e\u003c/code\u003e\u003c/a\u003e chore: bump fastify/github-action-merge-dependabot from 3.12.0 to 3.15.0 (\u003ca href=\"https://redirect.github.com/delvedor/find-my-way/issues/438\"\u003e#438\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/delvedor/find-my-way/commit/e63cb77c4f318780557305d757f90a5ebe1914dd\"\u003e\u003ccode\u003ee63cb77\u003c/code\u003e\u003c/a\u003e chore: bump inquirer from 13.4.3 to 14.0.2 in the dev-dependencies group (\u003ca href=\"https://redirect.github.com/delvedor/find-my-way/issues/437\"\u003e#437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/delvedor/find-my-way/commit/992c1df719f06292048cf6764f91deeaead30214\"\u003e\u003ccode\u003e992c1df\u003c/code\u003e\u003c/a\u003e perf(host): cache regex lookup results in HostStorage (\u003ca href=\"https://redirect.github.com/delvedor/find-my-way/issues/436\"\u003e#436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/delvedor/find-my-way/compare/v9.6.0...v9.7.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nanoid` from 3.3.12 to 3.3.19\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/releases\"\u003enanoid's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/blob/main/CHANGELOG.md\"\u003enanoid's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID (by \u003ca href=\"https://github.com/geoffrey-diederichs\"\u003e\u003ccode\u003e@​geoffrey-diederichs\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/eb63bd6775188dc35d143bf24868be094f19b5ee\"\u003e\u003ccode\u003eeb63bd6\u003c/code\u003e\u003c/a\u003e Release 3.3.19 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9067e0361a643ab2c94ddd67606efbf275f6c0dd\"\u003e\u003ccode\u003e9067e03\u003c/code\u003e\u003c/a\u003e Sync CJS and ESM\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9ad98052b316c5e707f8098ace509d2ae165e54d\"\u003e\u003ccode\u003e9ad9805\u003c/code\u003e\u003c/a\u003e Release 3.3.18 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/55e50a0621ec084b4bb4000ea4e86e1191bd3da8\"\u003e\u003ccode\u003e55e50a0\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e10f8d40ce9d1ab47f66d65a16b48086432730d0\"\u003e\u003ccode\u003ee10f8d4\u003c/code\u003e\u003c/a\u003e Update index.native.js (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/606\"\u003e#606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/73d67168136b36fd3b644159b0cff149da4905d9\"\u003e\u003ccode\u003e73d6716\u003c/code\u003e\u003c/a\u003e Release 3.3.17 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/f9d13f150847d117877adee3460a46eceb0cf49b\"\u003e\u003ccode\u003ef9d13f1\u003c/code\u003e\u003c/a\u003e Sync 0 size behaviour with PostCSS 5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9760e112757cf7d46a79abd7a133bc4958757bb8\"\u003e\u003ccode\u003e9760e11\u003c/code\u003e\u003c/a\u003e Release 3.3.16 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66d\"\u003e\u003ccode\u003ee835c9b\u003c/code\u003e\u003c/a\u003e fix(non-secure): clamp negative size to prevent infinite loop (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/601\"\u003e#601\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/96dd086eb24396a275fa93ee78d73b2fece35809\"\u003e\u003ccode\u003e96dd086\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ai/nanoid/compare/3.3.12...3.3.19\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for nanoid since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `sharp` from 0.34.5 to 0.35.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lovell/sharp/releases\"\u003esharp's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.35.4\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\"\u003ehttps://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.35.4-rc.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpgrade to libvips v8.18.6 for upstream bug fixes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7f1a0a22cc285fe180766f4935d50b55af6e8432\"\u003e\u003ccode\u003e7f1a0a2\u003c/code\u003e\u003c/a\u003e Release v0.35.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/f927818924bc5a9493d822a4e8b23ec5857c52e1\"\u003e\u003ccode\u003ef927818\u003c/code\u003e\u003c/a\u003e Upgrade to sharp-libvips v1.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e80209240d005c71e1173a50dd9cd4db4ce2a9e6\"\u003e\u003ccode\u003ee802092\u003c/code\u003e\u003c/a\u003e Prerelease v0.35.4-rc.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e13eb2f97a0a22f1ef726e8d0cd33f7c56835945\"\u003e\u003ccode\u003ee13eb2f\u003c/code\u003e\u003c/a\u003e CI: Fix wasm32 build (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4589\"\u003e#4589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/a82a0b3d58bc25854ad1e925e6eb0a50725d1489\"\u003e\u003ccode\u003ea82a0b3\u003c/code\u003e\u003c/a\u003e Upgrade to libvips v8.18.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/8044fe43e36d0ea7f8beb89f79a37bb0f3342e84\"\u003e\u003ccode\u003e8044fe4\u003c/code\u003e\u003c/a\u003e Bound resize dimensions to coordinate limit\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/147f8591a153bc4a1e199c3fe3150fac2931b30c\"\u003e\u003ccode\u003e147f859\u003c/code\u003e\u003c/a\u003e Docs: changelog entries for \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4578\"\u003e#4578\u003c/a\u003e \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ee5bfb853de75a611c64381783b04032a3a897d8\"\u003e\u003ccode\u003eee5bfb8\u003c/code\u003e\u003c/a\u003e Tests: use yauzl directly rather than via extract-zip wrapper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7a7788928f8a2a429f45039010a87cee35401694\"\u003e\u003ccode\u003e7a77889\u003c/code\u003e\u003c/a\u003e Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4588\"\u003e#4588\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ea5bef24c187b2c7ee3fe3cad3b45c8cb67a46fd\"\u003e\u003ccode\u003eea5bef2\u003c/code\u003e\u003c/a\u003e Improve support for input Streams finishing before output is requested (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/lovell/sharp/compare/v0.34.5...v0.35.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `valibot` from 1.2.0 to 1.4.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-circle/valibot/releases\"\u003evalibot's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.4.2\u003c/h2\u003e\n\u003cp\u003eMany thanks to \u003ca href=\"https://github.com/Faze-up\"\u003e\u003ccode\u003e@​Faze-up\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e for contributing to this release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix word count actions to cache the \u003ccode\u003eIntl.Segmenter\u003c/code\u003e for non-primitive locales, preventing it from being recreated on every \u003ccode\u003ewords\u003c/code\u003e, \u003ccode\u003eminWords\u003c/code\u003e, \u003ccode\u003emaxWords\u003c/code\u003e and \u003ccode\u003enotWords\u003c/code\u003e validation (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1521\"\u003e#1521\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eflatten\u003c/code\u003e method to handle issue path keys that collide with \u003ccode\u003eObject.prototype\u003c/code\u003e members like \u003ccode\u003etoString\u003c/code\u003e instead of throwing a \u003ccode\u003eTypeError\u003c/code\u003e (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1522\"\u003e#1522\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eintersect\u003c/code\u003e schema to merge object keys that collide with \u003ccode\u003eObject.prototype\u003c/code\u003e members like \u003ccode\u003etoString\u003c/code\u003e instead of failing to merge them (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1522\"\u003e#1522\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.4.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eintersect\u003c/code\u003e schema to infer correct input and output types for non-tuple array options instead of \u003ccode\u003enever\u003c/code\u003e (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1478\"\u003e#1478\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.4.0\u003c/h2\u003e\n\u003cp\u003eMany thanks to \u003ca href=\"https://github.com/ksaurav24\"\u003e\u003ccode\u003e@​ksaurav24\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/heiwen\"\u003e\u003ccode\u003e@​heiwen\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/compulim\"\u003e\u003ccode\u003e@​compulim\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/ysknsid25\"\u003e\u003ccode\u003e@​ysknsid25\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/alaycock-stripe\"\u003e\u003ccode\u003e@​alaycock-stripe\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/IlyaSemenov\"\u003e\u003ccode\u003e@​IlyaSemenov\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/wszgrcy\"\u003e\u003ccode\u003e@​wszgrcy\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/LMGO\"\u003e\u003ccode\u003e@​LMGO\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/yslpn\"\u003e\u003ccode\u003e@​yslpn\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/EltonLobo07\"\u003e\u003ccode\u003e@​EltonLobo07\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/Eronmmer\"\u003e\u003ccode\u003e@​Eronmmer\u003c/code\u003e\u003c/a\u003e for contributing to this release.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eRead the \u003ca href=\"https://valibot.dev/blog/valibot-v1.4-release-notes/\"\u003erelease notes\u003c/a\u003e on our website for a quick overview of the most exciting new features in this release.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003eisoDateTimeSecond\u003c/code\u003e validation action to validate ISO date times with seconds (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1418\"\u003e#1418\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003etoCamelCase\u003c/code\u003e, \u003ccode\u003etoKebabCase\u003c/code\u003e, \u003ccode\u003etoPascalCase\u003c/code\u003e and \u003ccode\u003etoSnakeCase\u003c/code\u003e transformation actions to convert strings between common naming conventions (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1457\"\u003e#1457\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChange internal \u003ccode\u003eReadonlyOutputKeys\u003c/code\u003e and \u003ccode\u003eOutputWithReadonly\u003c/code\u003e types of \u003ccode\u003eobject\u003c/code\u003e schemas and \u003ccode\u003eWithReadonly\u003c/code\u003e type of \u003ccode\u003erecord\u003c/code\u003e schemas to improve TypeScript type performance (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1442\"\u003e#1442\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChange hot paths to reduce object allocations and improve runtime performance (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1437\"\u003e#1437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChange build target to ES2020 so distributed output stays compatible with environments that lack support for newer syntax (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1455\"\u003e#1455\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChange internal \u003ccode\u003e_LruCache\u003c/code\u003e to use a TypeScript \u003ccode\u003eprivate\u003c/code\u003e method instead of a \u003ccode\u003e#private\u003c/code\u003e class field to avoid runtime helpers in the transpiled output (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1455\"\u003e#1455\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChange internal \u003ccode\u003e_isValidObjectKey\u003c/code\u003e to use \u003ccode\u003eObject.prototype.hasOwnProperty.call\u003c/code\u003e instead of \u003ccode\u003eObject.hasOwn\u003c/code\u003e so the distributed output stays compatible with runtimes that lack the ES2022 \u003ccode\u003eObject.hasOwn\u003c/code\u003e builtin (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1421\"\u003e#1421\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChange \u003ccode\u003eflatten\u003c/code\u003e method to accept readonly issue arrays (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1269\"\u003e#1269\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix potential \u003ccode\u003eRangeError\u003c/code\u003e caused by spreading large issue arrays (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1437\"\u003e#1437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003ecreditCard\u003c/code\u003e validation action to reject Mastercard numbers with invalid lengths (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1462\"\u003e#1462\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eintersect\u003c/code\u003e schema to no longer mutate input values, allowing frozen objects and arrays to be merged (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1463\"\u003e#1463\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.4.0 (to-json-schema)\u003c/h2\u003e\n\u003cp\u003eMany thanks to \u003ca href=\"https://github.com/stefanprobst\"\u003e\u003ccode\u003e@​stefanprobst\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/sruenwg\"\u003e\u003ccode\u003e@​sruenwg\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/cruzdanilo\"\u003e\u003ccode\u003e@​cruzdanilo\u003c/code\u003e\u003c/a\u003e for contributing to this release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for \u003ccode\u003eexamples\u003c/code\u003e action\u003c/li\u003e\n\u003cli\u003eAdd support for \u003ccode\u003einteger\u003c/code\u003e when used with \u003ccode\u003eminValue\u003c/code\u003e and \u003ccode\u003emaxValue\u003c/code\u003e actions (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1367\"\u003e#1367\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChange Valibot peer dependency to v1.2.0\u003c/li\u003e\n\u003cli\u003eFix conversion of \u003ccode\u003eexactOptional\u003c/code\u003e object properties (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1220\"\u003e#1220\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix conversion of \u003ccode\u003evariant\u003c/code\u003e to use \u003ccode\u003eoneOf\u003c/code\u003e instead of \u003ccode\u003eanyOf\u003c/code\u003e (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1193\"\u003e#1193\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.3.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChange \u003ccode\u003eMAC48_REGEX\u003c/code\u003e, \u003ccode\u003eMAC64_REGEX\u003c/code\u003e and \u003ccode\u003eMAC_REGEX\u003c/code\u003e to drop the \u003ccode\u003ei\u003c/code\u003e flag for better JSON Schema compatibility (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1430\"\u003e#1430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChange \u003ccode\u003ehash\u003c/code\u003e action to use case-expanded character classes instead of the \u003ccode\u003ei\u003c/code\u003e flag (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1430\"\u003e#1430\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.3.0\u003c/h2\u003e\n\u003cp\u003eMany thanks to \u003ca href=\"https://github.com/EskiMojo14\"\u003e\u003ccode\u003e@​EskiMojo14\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/yslpn\"\u003e\u003ccode\u003e@​yslpn\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/alexilyaev\"\u003e\u003ccode\u003e@​alexilyaev\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/idleberg\"\u003e\u003ccode\u003e@​idleberg\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/BerkliumBirb\"\u003e\u003ccode\u003e@​BerkliumBirb\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/frenzzy\"\u003e\u003ccode\u003e@​frenzzy\u003c/code\u003e\u003c/a\u003e for contributing to this release.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eRead the \u003ca href=\"https://valibot.dev/blog/valibot-v1.3-release-notes/\"\u003erelease notes\u003c/a\u003e on our website for a quick overview of the most exciting new features in this release.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003eguard\u003c/code\u003e transformation action to narrow types using type predicates (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1204\"\u003e#1204\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eparseBoolean\u003c/code\u003e transformation action to parse boolean values from strings and other types (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1251\"\u003e#1251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eisrc\u003c/code\u003e validation action to validate ISRC codes (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1373\"\u003e#1373\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003ecache\u003c/code\u003e method for caching schema output by input (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1170\"\u003e#1170\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003edomain\u003c/code\u003e validation action to validate domain names (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1284\"\u003e#1284\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-circle/valibot/commit/0dc26ea88cf07a414653375f0da43f97e0eed607\"\u003e\u003ccode\u003e0dc26ea\u003c/code\u003e\u003c/a\u003e Bump library version to 1.4.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-circle/valibot/commit/1bd01c304657cd0809cc92694360b6cc60f700bf\"\u003e\u003ccode\u003e1bd01c3\u003c/code\u003e\u003c/a\u003e fix: handle keys that collide with Object.prototype in flatten and merge (\u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1522\"\u003e#1522\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-circle/valibot/commit/752c6369bbd05904bab22149bf79f716a274c99d\"\u003e\u003ccode\u003e752c636\u003c/code\u003e\u003c/a\u003e docs: clarify string length semantics (\u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1505\"\u003e#1505\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-circle/valibot/commit/a3beff96ad65e5409cb9202c9d2b30f670b3cde3\"\u003e\u003ccode\u003ea3beff9\u003c/code\u003e\u003c/a\u003e fix: cache word-count segmenter for non-primitive locales (\u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1521\"\u003e#1521\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-circle/valibot/commit/1f9b18338ad5530f1f6c63c2cf241962bd82d6f8\"\u003e\u003ccode\u003e1f9b183\u003c/code\u003e\u003c/a\u003e Update FUNDING.yml in fabvor of Open Collective\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-circle/valibot/commit/2c63b2a0c8ad23ace4e52f6e4a93524d39c25947\"\u003e\u003ccode\u003e2c63b2a\u003c/code\u003e\u003c/a\u003e Update logos of partners in README\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-circle/valibot/commit/09616b20c8772aeb2e6203b58f1254fae27cb071\"\u003e\u003ccode\u003e09616b2\u003c/code\u003e\u003c/a\u003e Add CodeRabbit as partner and remove Stainless\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-circle/valibot/commit/92bcf55fff4347f7d43327a0224565699df6602c\"\u003e\u003ccode\u003e92bcf55\u003c/code\u003e\u003c/a\u003e Add Cloudflare to privacy policy page\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-circle/valibot/commit/9bb6617f2f04e735cc815d771eb15f6b7ad0feb6\"\u003e\u003ccode\u003e9bb6617\u003c/code\u003e\u003c/a\u003e Add Cloudflare as a deploy target to our website (\u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1508\"\u003e#1508\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-circle/valibot/commit/c05bf954ada47d5ff953cdfad905cc701b25719c\"\u003e\u003ccode\u003ec05bf95\u003c/code\u003e\u003c/a\u003e Bump to-json-schema version to 1.7.1\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/open-circle/valibot/compare/v1.2.0...v1.4.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for valibot since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/executiveusa/pauli-glot/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/executiveusa/pauli-glot/pull/12","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/executiveusa%2Fpauli-glot/issues/12","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/12/packages"},{"uuid":"5438402679","node_id":"PR_kwDOSAxHtc8AAAABDUGkkQ","number":157,"state":"closed","title":"build(deps-dev): Bump the cadence-npm-development group across 1 directory with 15 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":"2026-09-13T07:37:51.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-13T06:06:05.000Z","updated_at":"2026-09-13T07:38:00.000Z","time_to_close":5506,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps-dev): Bump","group_name":"cadence-npm-development","update_count":15,"packages":[{"name":"@playwright/test","old_version":"1.61.1","new_version":"1.63.0","repository_url":"https://github.com/microsoft/playwright"},{"name":"@testing-library/jest-dom","old_version":"6.9.1","new_version":"7.0.1","repository_url":"https://github.com/testing-library/jest-dom"},{"name":"@testing-library/react","old_version":"16.3.2","new_version":"16.3.3","repository_url":"https://github.com/testing-library/react-testing-library"},{"name":"@types/node","old_version":"26.1.1","new_version":"26.5.1","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"@typescript-eslint/eslint-plugin","old_version":"8.63.0","new_version":"8.70.0","repository_url":"https://github.com/typescript-eslint/typescript-eslint"},{"name":"@vitejs/plugin-react","old_version":"6.0.3","new_version":"6.1.1","repository_url":"https://github.com/vitejs/vite-plugin-react"},{"name":"@vitest/coverage-v8","old_version":"4.1.10","new_version":"5.0.0","repository_url":"https://github.com/vitest-dev/vitest"},{"name":"browserslist","old_version":"4.28.8","new_version":"4.28.9","repository_url":"https://github.com/browserslist/browserslist"},{"name":"eslint","old_version":"10.6.0","new_version":"10.10.0","repository_url":"https://github.com/eslint/eslint"},{"name":"fast-uri","old_version":"3.1.7","new_version":"4.1.4","repository_url":"https://github.com/fastify/fast-uri"},{"name":"jsdom","old_version":"29.1.1","new_version":"30.0.1","repository_url":"https://github.com/jsdom/jsdom"},{"name":"prettier","old_version":"3.9.4","new_version":"3.9.6","repository_url":"https://github.com/prettier/prettier"},{"name":"vite","old_version":"8.1.3","new_version":"8.2.2","repository_url":"https://github.com/vitejs/vite"},{"name":"vitest","old_version":"4.1.10","new_version":"5.0.0","repository_url":"https://github.com/vitest-dev/vitest"}],"path":null,"ecosystem":"npm"},"body":"Bumps the cadence-npm-development group with 14 updates in the /Cadence/web directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@playwright/test](https://github.com/microsoft/playwright) | `1.61.1` | `1.63.0` |\n| [@testing-library/jest-dom](https://github.com/testing-library/jest-dom) | `6.9.1` | `7.0.1` |\n| [@testing-library/react](https://github.com/testing-library/react-testing-library) | `16.3.2` | `16.3.3` |\n| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.1.1` | `26.5.1` |\n| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.63.0` | `8.70.0` |\n| [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) | `6.0.3` | `6.1.1` |\n| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `4.1.10` | `5.0.0` |\n| [browserslist](https://github.com/browserslist/browserslist) | `4.28.8` | `4.28.9` |\n| [eslint](https://github.com/eslint/eslint) | `10.6.0` | `10.10.0` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.7` | `4.1.4` |\n| [jsdom](https://github.com/jsdom/jsdom) | `29.1.1` | `30.0.1` |\n| [prettier](https://github.com/prettier/prettier) | `3.9.4` | `3.9.6` |\n| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.1.3` | `8.2.2` |\n| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.10` | `5.0.0` |\n\n\nUpdates `@playwright/test` from 1.61.1 to 1.63.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/microsoft/playwright/releases\"\u003e@​playwright/test's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.63.0\u003c/h2\u003e\n\u003ch2\u003e🔒 Test locks\u003c/h2\u003e\n\u003cp\u003eTests that access a shared resource — an external service, a global account setting — can now declare a named \u003ccode\u003elock\u003c/code\u003e.\nTests that share a lock name never run concurrently, across files, workers and \u003ca href=\"https://playwright.dev/docs/test-projects\"\u003eprojects\u003c/a\u003e, while\neverything else keeps running in parallel:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003etest('update user settings', { lock: 'user-settings' }, async ({ page }) =\u0026gt; {\r\n  // never runs at the same time as other tests holding 'user-settings'\r\n});\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eA test can hold multiple locks, and \u003ca href=\"https://playwright.dev/docs/api/class-test#test-describe\"\u003etest.describe()\u003c/a\u003e accepts a \u003ccode\u003elock\u003c/code\u003e for the whole group.\nLearn more about \u003ca href=\"https://playwright.dev/docs/test-parallel#test-locks\"\u003etest locks\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003e🪟 Locate across frames\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://playwright.dev/docs/api/class-page#page-frame-locator\"\u003epage.frameLocator()\u003c/a\u003e and \u003ca href=\"https://playwright.dev/docs/api/class-frame#frame-frame-locator\"\u003eframe.frameLocator()\u003c/a\u003e called without a selector search in any frame of the\nsubtree, so you no longer need to locate the iframe first:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Finds the button in any frame on the page.\r\nawait page.frameLocator().getByRole('button').click();\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eThe rest of the locator resolves inside a single frame, just like a regular locator, and an error is thrown when it\nmatches elements in several frames.\u003c/p\u003e\n\u003ch2\u003e👁️ Visible-only locators\u003c/h2\u003e\n\u003cp\u003eNew \u003ca href=\"https://playwright.dev/docs/api/class-locator#locator-visible\"\u003elocator.visible()\u003c/a\u003e returns a locator that matches only visible elements. It is the recommended\nreplacement for the \u003ccode\u003e:visible\u003c/code\u003e CSS pseudo-class:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003eawait page.locator('button').visible().click();\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003ch2\u003e🧾 Step params and subtitles\u003c/h2\u003e\n\u003cp\u003eSteps now carry structured data for reporters. Playwright API steps report the target locator and call arguments,\nand \u003ca href=\"https://playwright.dev/docs/api/class-test#test-step\"\u003etest.step()\u003c/a\u003e accepts \u003ccode\u003esubtitle\u003c/code\u003e and \u003ccode\u003eparams\u003c/code\u003e options for your own steps:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003eawait test.step('Login', async () =\u0026gt; {\r\n  // ...\r\n}, { subtitle: 'as admin', params: { user: 'admin' } });\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eReporters receive them via \u003ca href=\"https://playwright.dev/docs/api/class-teststep#test-step-subtitle\"\u003etestStep.subtitle\u003c/a\u003e and \u003ca href=\"https://playwright.dev/docs/api/class-teststep#test-step-params\"\u003etestStep.params\u003c/a\u003e. For Playwright API\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/1b025d7e20a026371cd5f98ba0cdce48892737c8\"\u003e\u003ccode\u003e1b025d7\u003c/code\u003e\u003c/a\u003e chore: mark v1.63.0 (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42569\"\u003e#42569\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/0b9956d2247ce88399c3c46a22c1cc0526acb340\"\u003e\u003ccode\u003e0b9956d\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42568\"\u003e#42568\u003c/a\u003e): docs(test): mark test.step subtitle option as since v1.63\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/13dbf102b88305ed96b7791a7843246cd75d4dae\"\u003e\u003ccode\u003e13dbf10\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42552\"\u003e#42552\u003c/a\u003e): docs: release notes for v1.63\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/e93b64ed6f9cf6ac2cc8cb13ad01514b406a7142\"\u003e\u003ccode\u003ee93b64e\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42566\"\u003e#42566\u003c/a\u003e): feat(test): add subtitle option to test.step (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42567\"\u003e#42567\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/2b7a5f2ea1cea04b549c5378498c1b16b6bc6a6f\"\u003e\u003ccode\u003e2b7a5f2\u003c/code\u003e\u003c/a\u003e test: response.body() for content-encoding:identity (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42537\"\u003e#42537\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/648a67c7c1261eefe4113cba2d586417d5e3f2f2\"\u003e\u003ccode\u003e648a67c\u003c/code\u003e\u003c/a\u003e fix(mcp): create parent directories for explicitly named files (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42540\"\u003e#42540\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/7894f5653e7f253c17aa1638c19f63e0d54d5e0e\"\u003e\u003ccode\u003e7894f56\u003c/code\u003e\u003c/a\u003e docs(mcp): clarify how tool file names are resolved (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42538\"\u003e#42538\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/52900a1b99ca51011526afcaf8981970cc1a521a\"\u003e\u003ccode\u003e52900a1\u003c/code\u003e\u003c/a\u003e devops: restore npm publishing from GitHub Actions (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42550\"\u003e#42550\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/8c47f596edebd2460895a5953f2ea67f8b884001\"\u003e\u003ccode\u003e8c47f59\u003c/code\u003e\u003c/a\u003e docs(csharp): fix nonexistent method names in guide examples (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42507\"\u003e#42507\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/bd6e552a63f8cf9b0da0216f392b8e63a08bf1d2\"\u003e\u003ccode\u003ebd6e552\u003c/code\u003e\u003c/a\u003e chore(video): emit frames with real timestamps, drop frame number quantizatio...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/microsoft/playwright/compare/v1.61.1...v1.63.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@testing-library/jest-dom` from 6.9.1 to 7.0.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/testing-library/jest-dom/releases\"\u003e@​testing-library/jest-dom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/testing-library/jest-dom/compare/v7.0.0...v7.0.1\"\u003e7.0.1\u003c/a\u003e (2026-08-09)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003edeclare vitest as an optional peer dependency (\u003ca href=\"https://redirect.github.com/testing-library/jest-dom/issues/733\"\u003e#733\u003c/a\u003e) (\u003ca href=\"https://github.com/testing-library/jest-dom/commit/3782c78b3dc9824675afe0cb8f1722f8c96f494d\"\u003e3782c78\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/testing-library/jest-dom/compare/v6.10.0...v7.0.0\"\u003e7.0.0\u003c/a\u003e (2026-07-20)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eadd toContainAnyBy* and toContainOneBy* query matchers (\u003ca href=\"https://github.com/testing-library/jest-dom/commit/1e39089d850408a583c83495d00d8aa27078933f\"\u003e1e39089\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBREAKING CHANGES\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​testing-library/dom\u003c/code\u003e is now a required peer dependency. The minimum supported\nNode.js version is now 22.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eRepaired release for \u003ca href=\"https://redirect.github.com/testing-library/jest-dom/pull/731\"\u003etesting-library/jest-dom#731\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.10.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/testing-library/jest-dom/compare/v6.9.1...v6.10.0\"\u003e6.10.0\u003c/a\u003e (2026-07-20)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eadd toContainAnyBy* and toContainOneBy* query matchers (\u003ca href=\"https://redirect.github.com/testing-library/jest-dom/issues/731\"\u003e#731\u003c/a\u003e) (\u003ca href=\"https://github.com/testing-library/jest-dom/commit/cae44df901cf8e92e3febc0af6fa667b10be6d6a\"\u003ecae44df\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/jest-dom/commit/3782c78b3dc9824675afe0cb8f1722f8c96f494d\"\u003e\u003ccode\u003e3782c78\u003c/code\u003e\u003c/a\u003e fix: declare vitest as an optional peer dependency (\u003ca href=\"https://redirect.github.com/testing-library/jest-dom/issues/733\"\u003e#733\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/jest-dom/commit/1e39089d850408a583c83495d00d8aa27078933f\"\u003e\u003ccode\u003e1e39089\u003c/code\u003e\u003c/a\u003e feat: add toContainAnyBy* and toContainOneBy* query matchers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/jest-dom/commit/cae44df901cf8e92e3febc0af6fa667b10be6d6a\"\u003e\u003ccode\u003ecae44df\u003c/code\u003e\u003c/a\u003e feat: add toContainAnyBy* and toContainOneBy* query matchers (\u003ca href=\"https://redirect.github.com/testing-library/jest-dom/issues/731\"\u003e#731\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/jest-dom/commit/55c07ce5f1c489b5b9dc31a770a84d83a1178072\"\u003e\u003ccode\u003e55c07ce\u003c/code\u003e\u003c/a\u003e ci: switch release to npm trusted publishing (\u003ca href=\"https://redirect.github.com/testing-library/jest-dom/issues/726\"\u003e#726\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/jest-dom/commit/213256fa8e0aff45e47920a0bc564f708d1f67de\"\u003e\u003ccode\u003e213256f\u003c/code\u003e\u003c/a\u003e docs: move toHaveSelection from the deprecated section (\u003ca href=\"https://redirect.github.com/testing-library/jest-dom/issues/717\"\u003e#717\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/testing-library/jest-dom/compare/v6.9.1...v7.0.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​testing-library/jest-dom\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@testing-library/react` from 16.3.2 to 16.3.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/testing-library/react-testing-library/releases\"\u003e@​testing-library/react's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.3\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/testing-library/react-testing-library/compare/v16.3.2...v16.3.3\"\u003e16.3.3\u003c/a\u003e (2026-08-27)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid act() re-entrant when dispatching events (\u003ca href=\"https://redirect.github.com/testing-library/react-testing-library/issues/1468\"\u003e#1468\u003c/a\u003e) (\u003ca href=\"https://github.com/testing-library/react-testing-library/commit/20ce75f2907ca0e5c5a8ae595c0e9a4e368c7800\"\u003e20ce75f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/react-testing-library/commit/20ce75f2907ca0e5c5a8ae595c0e9a4e368c7800\"\u003e\u003ccode\u003e20ce75f\u003c/code\u003e\u003c/a\u003e fix: Avoid act() re-entrant when dispatching events (\u003ca href=\"https://redirect.github.com/testing-library/react-testing-library/issues/1468\"\u003e#1468\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/react-testing-library/commit/be9d81d91314c9f0bafaa363f70b409b4b31989c\"\u003e\u003ccode\u003ebe9d81d\u003c/code\u003e\u003c/a\u003e docs: fix typos in comments and types (\u003ca href=\"https://redirect.github.com/testing-library/react-testing-library/issues/1446\"\u003e#1446\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/testing-library/react-testing-library/compare/v16.3.2...v16.3.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@types/node` from 26.1.1 to 26.5.1\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@typescript-eslint/eslint-plugin` from 8.63.0 to 8.70.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases\"\u003e@​typescript-eslint/eslint-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.70.0\u003c/h2\u003e\n\u003ch2\u003e8.70.0 (2026-09-07)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-generated-empty-object-type] add rule (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12730\"\u003e#12730\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ewebsite:\u003c/strong\u003e generate per-page social preview cards (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12734\"\u003e#12734\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003euse stable release of pnpm 12 (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12808\"\u003e#12808\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate pnpm to 12.3.4 and dedupe Docusaurus packages (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12829\"\u003e#12829\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [member-ordering] don't report fields that read fields declared before them (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12729\"\u003e#12729\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-unnecessary-condition] no false positive on RHS of a nested logical expression (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12728\"\u003e#12728\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-deprecated] report deprecated imported values used in object shorthand properties (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12780\"\u003e#12780\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eproject-service:\u003c/strong\u003e avoid discarded tsserver logs (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12748\"\u003e#12748\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypescript-estree:\u003c/strong\u003e clarify the parserOptions.project error message (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12817\"\u003e#12817\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBarry \u003ca href=\"https://github.com/barry166\"\u003e\u003ccode\u003e@​barry166\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEvyatar Daud \u003ca href=\"https://github.com/StyleShit\"\u003e\u003ccode\u003e@​StyleShit\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJosh Goldberg\u003c/li\u003e\n\u003cli\u003eJosh Goldberg ✨ \u003ca href=\"https://github.com/JoshuaKGoldberg\"\u003e\u003ccode\u003e@​JoshuaKGoldberg\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eKirk Waiblinger \u003ca href=\"https://github.com/kirkwaiblinger\"\u003e\u003ccode\u003e@​kirkwaiblinger\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUlrich Stark \u003ca href=\"https://github.com/ulrichstark\"\u003e\u003ccode\u003e@​ulrichstark\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e송재욱\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003ev8.69.0\u003c/h2\u003e\n\u003ch2\u003e8.69.0 (2026-08-31)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-misused-promises] add flagUnions option for checkConditionals (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12603\"\u003e#12603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-mixed-enums] use scope analysis instead of type checking for merged namespaces (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12731\"\u003e#12731\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [unified-signatures] compare type parameters by constraint instead of name (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12741\"\u003e#12741\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-meaningless-void-operator] report void on non-call expressions (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12727\"\u003e#12727\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ewebsite:\u003c/strong\u003e respect allowJs playground config (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12744\"\u003e#12744\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAbdu Alim Arlikhozhaev \u003ca href=\"https://github.com/Arlikhozhaev\"\u003e\u003ccode\u003e@​Arlikhozhaev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEvyatar Daud \u003ca href=\"https://github.com/StyleShit\"\u003e\u003ccode\u003e@​StyleShit\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md\"\u003e@​typescript-eslint/eslint-plugin's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.70.0 (2026-09-07)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-generated-empty-object-type] add rule (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12730\"\u003e#12730\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-deprecated] report deprecated imported values used in object shorthand properties (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12780\"\u003e#12780\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-unnecessary-condition] no false positive on RHS of a nested logical expression (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12728\"\u003e#12728\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [member-ordering] don't report fields that read fields declared before them (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12729\"\u003e#12729\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eJosh Goldberg ✨ \u003ca href=\"https://github.com/JoshuaKGoldberg\"\u003e\u003ccode\u003e@​JoshuaKGoldberg\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUlrich Stark \u003ca href=\"https://github.com/ulrichstark\"\u003e\u003ccode\u003e@​ulrichstark\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003e8.69.0 (2026-08-31)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-misused-promises] add flagUnions option for checkConditionals (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12603\"\u003e#12603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-meaningless-void-operator] report void on non-call expressions (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12727\"\u003e#12727\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [unified-signatures] compare type parameters by constraint instead of name (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12741\"\u003e#12741\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-mixed-enums] use scope analysis instead of type checking for merged namespaces (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12731\"\u003e#12731\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAbdu Alim Arlikhozhaev \u003ca href=\"https://github.com/Arlikhozhaev\"\u003e\u003ccode\u003e@​Arlikhozhaev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEvyatar Daud \u003ca href=\"https://github.com/StyleShit\"\u003e\u003ccode\u003e@​StyleShit\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJosh Goldberg ✨\u003c/li\u003e\n\u003cli\u003ewonbeanie \u003ca href=\"https://github.com/wonbeanie\"\u003e\u003ccode\u003e@​wonbeanie\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.69.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003e8.68.0 (2026-08-24)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [strict-void-return] add fix suggestions (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12086\"\u003e#12086\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/7ee76085c22e923c0036b8e0733a3ca7dfd82b60\"\u003e\u003ccode\u003e7ee7608\u003c/code\u003e\u003c/a\u003e chore(release): publish 8.70.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/f66bdcac30c13c7ca8932667494550fd13fde5fc\"\u003e\u003ccode\u003ef66bdca\u003c/code\u003e\u003c/a\u003e test(eslint-plugin): [member-ordering] use \u003ccode\u003eRuleTester\u003c/code\u003e directly in `optional...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/4586535ab24d7d5e9b3ba87e4adb8636f9314aca\"\u003e\u003ccode\u003e4586535\u003c/code\u003e\u003c/a\u003e fix(eslint-plugin): [no-deprecated] report deprecated imported values used in...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/f8e1e4e2f7454ab2ba680cb523f9e3abe6582f81\"\u003e\u003ccode\u003ef8e1e4e\u003c/code\u003e\u003c/a\u003e fix(eslint-plugin): [no-unnecessary-condition] no false positive on RHS of a ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/889cece8bba520fc8c342dade4adf42b5d7f671e\"\u003e\u003ccode\u003e889cece\u003c/code\u003e\u003c/a\u003e fix(eslint-plugin): [member-ordering] don't report fields that read fields de...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/1a5a8b124b905c81a76ba1104a6396e65ad407dd\"\u003e\u003ccode\u003e1a5a8b1\u003c/code\u003e\u003c/a\u003e feat(eslint-plugin): [no-generated-empty-object-type] add rule (\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin/issues/12730\"\u003e#12730\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/9a6e546823e5d8f2dc015df2aa66c0230615e209\"\u003e\u003ccode\u003e9a6e546\u003c/code\u003e\u003c/a\u003e chore(release): publish 8.69.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/513638effe9e7b78566cc153d4d809a1435153f3\"\u003e\u003ccode\u003e513638e\u003c/code\u003e\u003c/a\u003e fix(eslint-plugin): [no-meaningless-void-operator] report void on non-call ex...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/1dba4c50f0599cc212e9d1eca9ec0f21a818f0b5\"\u003e\u003ccode\u003e1dba4c5\u003c/code\u003e\u003c/a\u003e chore(eslint-plugin): fix \u003ccode\u003eeslint-plugin/require-test-error-positions\u003c/code\u003e report...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/a2fccae39c7cb1e516a29b1c746b7767bffa03e2\"\u003e\u003ccode\u003ea2fccae\u003c/code\u003e\u003c/a\u003e fix(eslint-plugin): [unified-signatures] compare type parameters by constrain...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.0/packages/eslint-plugin\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@typescript-eslint/parser` from 8.63.0 to 8.70.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases\"\u003e@​typescript-eslint/parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.70.0\u003c/h2\u003e\n\u003ch2\u003e8.70.0 (2026-09-07)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-generated-empty-object-type] add rule (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12730\"\u003e#12730\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ewebsite:\u003c/strong\u003e generate per-page social preview cards (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12734\"\u003e#12734\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003euse stable release of pnpm 12 (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12808\"\u003e#12808\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate pnpm to 12.3.4 and dedupe Docusaurus packages (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12829\"\u003e#12829\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [member-ordering] don't report fields that read fields declared before them (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12729\"\u003e#12729\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-unnecessary-condition] no false positive on RHS of a nested logical expression (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12728\"\u003e#12728\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-deprecated] report deprecated imported values used in object shorthand properties (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12780\"\u003e#12780\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eproject-service:\u003c/strong\u003e avoid discarded tsserver logs (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12748\"\u003e#12748\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypescript-estree:\u003c/strong\u003e clarify the parserOptions.project error message (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12817\"\u003e#12817\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBarry \u003ca href=\"https://github.com/barry166\"\u003e\u003ccode\u003e@​barry166\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEvyatar Daud \u003ca href=\"https://github.com/StyleShit\"\u003e\u003ccode\u003e@​StyleShit\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJosh Goldberg\u003c/li\u003e\n\u003cli\u003eJosh Goldberg ✨ \u003ca href=\"https://github.com/JoshuaKGoldberg\"\u003e\u003ccode\u003e@​JoshuaKGoldberg\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eKirk Waiblinger \u003ca href=\"https://github.com/kirkwaiblinger\"\u003e\u003ccode\u003e@​kirkwaiblinger\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUlrich Stark \u003ca href=\"https://github.com/ulrichstark\"\u003e\u003ccode\u003e@​ulrichstark\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e송재욱\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003ev8.69.0\u003c/h2\u003e\n\u003ch2\u003e8.69.0 (2026-08-31)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-misused-promises] add flagUnions option for checkConditionals (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12603\"\u003e#12603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-mixed-enums] use scope analysis instead of type checking for merged namespaces (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12731\"\u003e#12731\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [unified-signatures] compare type parameters by constraint instead of name (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12741\"\u003e#12741\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-meaningless-void-operator] report void on non-call expressions (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12727\"\u003e#12727\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ewebsite:\u003c/strong\u003e respect allowJs playground config (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12744\"\u003e#12744\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAbdu Alim Arlikhozhaev \u003ca href=\"https://github.com/Arlikhozhaev\"\u003e\u003ccode\u003e@​Arlikhozhaev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEvyatar Daud \u003ca href=\"https://github.com/StyleShit\"\u003e\u003ccode\u003e@​StyleShit\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md\"\u003e@​typescript-eslint/parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.70.0 (2026-09-07)\u003c/h2\u003e\n\u003cp\u003eThis was a version bump only for parser to align it with other projects, there were no code changes.\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003e8.69.0 (2026-08-31)\u003c/h2\u003e\n\u003cp\u003eThis was a version bump only for parser to align it with other projects, there were no code changes.\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.69.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003e8.68.0 (2026-08-24)\u003c/h2\u003e\n\u003cp\u003eThis was a version bump only for parser to align it with other projects, there were no code changes.\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.68.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003e8.67.0 (2026-08-10)\u003c/h2\u003e\n\u003cp\u003eThis was a version bump only for parser to align it with other projects, there were no code changes.\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.67.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003e8.66.0 (2026-08-03)\u003c/h2\u003e\n\u003cp\u003eThis was a version bump only for parser to align it with other projects, there were no code changes.\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.66.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003e8.65.0 (2026-07-20)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eadd warning when TS 7 is detected (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12529\"\u003e#12529\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eparser:\u003c/strong\u003e add onUnsupportedTypeScriptVersion option to error on unsupported TypeScript versions (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12465\"\u003e#12465\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEvyatar Daud \u003ca href=\"https://github.com/StyleShit\"\u003e\u003ccode\u003e@​StyleShit\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/7ee76085c22e923c0036b8e0733a3ca7dfd82b60\"\u003e\u003ccode\u003e7ee7608\u003c/code\u003e\u003c/a\u003e chore(release): publish 8.70.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/9a6e546823e5d8f2dc015df2aa66c0230615e209\"\u003e\u003ccode\u003e9a6e546\u003c/code\u003e\u003c/a\u003e chore(release): publish 8.69.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/8f4e00a4e8f3bdf93a5e5e8bc568ba1c15a4f896\"\u003e\u003ccode\u003e8f4e00a\u003c/code\u003e\u003c/a\u003e chore(release): publish 8.68.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/55f6d5d4ca39d2fab93db97ced497b956017878d\"\u003e\u003ccode\u003e55f6d5d\u003c/code\u003e\u003c/a\u003e chore: enable source maps (\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser/issues/12677\"\u003e#12677\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/20a261fb8e62351e88176b075090dc9276d26072\"\u003e\u003ccode\u003e20a261f\u003c/code\u003e\u003c/a\u003e chore(release): publish 8.67.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/3b155bb1344fd7ce83086cf2f864a7e8f3b4a217\"\u003e\u003ccode\u003e3b155bb\u003c/code\u003e\u003c/a\u003e chore: use typescript 7 for typechecking (\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser/issues/12601\"\u003e#12601\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/e51b11ba3ab31837762c675f62f0d4dcb1abc4fb\"\u003e\u003ccode\u003ee51b11b\u003c/code\u003e\u003c/a\u003e chore(release): publish 8.66.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/63ba81b6acfa0d663c29aa0013d4672bf3b0426c\"\u003e\u003ccode\u003e63ba81b\u003c/code\u003e\u003c/a\u003e chore(release): publish 8.65.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/eaf457631ac381aadfee747c2d098c8ac4df9d63\"\u003e\u003ccode\u003eeaf4576\u003c/code\u003e\u003c/a\u003e feat: add warning when TS 7 is detected (\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser/issues/12529\"\u003e#12529\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/d8f1044702e3257ee92c0af6681c1455563009db\"\u003e\u003ccode\u003ed8f1044\u003c/code\u003e\u003c/a\u003e feat(parser): add onUnsupportedTypeScriptVersion option to error on unsupport...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.0/packages/parser\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@vitejs/plugin-react` from 6.0.3 to 6.1.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite-plugin-react/releases\"\u003e@​vitejs/plugin-react's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eplugin-react@6.1.1\u003c/h2\u003e\n\u003ch3\u003eAdd \u003ccode\u003ecompiler.logDiagnostics\u003c/code\u003e option\u003c/h3\u003e\n\u003cp\u003eRecoverable React Compiler diagnostics are no longer logged by default. Set \u003ccode\u003ecompiler.logDiagnostics\u003c/code\u003e to \u003ccode\u003etrue\u003c/code\u003e to log them through Vite. Fatal diagnostics are always logged and fail the transform.\u003c/p\u003e\n\u003ch3\u003eRespect environment sourcemap option for React Compiler transform when \u003ccode\u003ebuilder.sharedPlugins\u003c/code\u003e is enabled (\u003ca href=\"https://redirect.github.com/vitejs/vite-plugin-react/pull/1439\"\u003e#1439\u003c/a\u003e)\u003c/h3\u003e\n\u003cp\u003eThe React Compiler transform was using the top-level sourcemap option instead of the environment sourcemap option. This caused a problem when the experimental \u003ccode\u003ebuilder.sharedPlugins\u003c/code\u003e was enabled.\u003c/p\u003e\n\u003ch2\u003eplugin-react@6.1.0\u003c/h2\u003e\n\u003ch3\u003eAdd experimental native React Compiler support (\u003ca href=\"https://redirect.github.com/vitejs/vite-plugin-react/pull/1419\"\u003e#1419\u003c/a\u003e)\u003c/h3\u003e\n\u003cp\u003eAdd experimental native React Compiler support.\u003c/p\u003e\n\u003cp\u003eYou can use it by installing \u003ccode\u003eoxc-transform-react\u003c/code\u003e and enabling it via the \u003ccode\u003ecompiler\u003c/code\u003e option:\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install -D oxc-transform-react\n\u003c/code\u003e\u003c/pre\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003eimport { defineConfig } from 'vite'\nimport react from '@vitejs/plugin-react'\n\u003cp\u003eexport default defineConfig({\u003cbr /\u003e\nplugins: [\u003cbr /\u003e\nreact({ compiler: true })\u003cbr /\u003e\n]\u003cbr /\u003e\n})\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003ch2\u003eplugin-react@6.0.5\u003c/h2\u003e\n\u003ch3\u003eFixed the react compiler preset filter to be linear (\u003ca href=\"https://redirect.github.com/vitejs/vite-plugin-react/pull/1353\"\u003e#1353\u003c/a\u003e)\u003c/h3\u003e\n\u003cp\u003eThe improved filter in v6.0.3 was non-linear and caused a performance regression (\u003ca href=\"https://redirect.github.com/vitejs/vite-plugin-react/issues/1349\"\u003e#1349\u003c/a\u003e). The filter was changed to be linear to avoid that.\u003c/p\u003e\n\u003ch2\u003eplugin-react@6.0.4\u003c/h2\u003e\n\u003ch3\u003eFixed \u003ccode\u003e$RefreshSig$ is not defined\u003c/code\u003e error when running \u003ccode\u003evite dev\u003c/code\u003e with \u003ccode\u003eNODE_ENV=production\u003c/code\u003e\u003c/h3\u003e\n\u003cp\u003eWhen running \u003ccode\u003evite dev\u003c/code\u003e with \u003ccode\u003eNODE_ENV=production\u003c/code\u003e, the app errored with \u003ccode\u003e$RefreshSig$ is not defined\u003c/code\u003e.\nThis error is now fixed.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md\"\u003e@​vitejs/plugin-react's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e6.1.1 (2026-08-28)\u003c/h2\u003e\n\u003ch3\u003eAdd \u003ccode\u003ecompiler.logDiagnostics\u003c/code\u003e option\u003c/h3\u003e\n\u003cp\u003eRecoverable React Compiler diagnostics are no longer logged by default. Set \u003ccode\u003ecompiler.logDiagnostics\u003c/code\u003e to \u003ccode\u003etrue\u003c/code\u003e to log them through Vite. Fatal diagnostics are always logged and fail the transform.\u003c/p\u003e\n\u003ch3\u003eRespect environment sourcemap option for React Compiler transform when \u003ccode\u003ebuilder.sharedPlugins\u003c/code\u003e is enabled (\u003ca href=\"https://redirect.github.com/vitejs/vite-plugin-react/pull/1439\"\u003e#1439\u003c/a\u003e)\u003c/h3\u003e\n\u003cp\u003eThe React Compiler transform was using the top-level sourcemap option instead of the environment sourcemap option. This caused a problem when the experimental \u003ccode\u003ebuilder.sharedPlugins\u003c/code\u003e was enabled.\u003c/p\u003e\n\u003ch2\u003e6.1.0 (2026-08-19)\u003c/h2\u003e\n\u003ch3\u003eAdd experimental native React Compiler support (\u003ca href=\"https://redirect.github.com/vitejs/vite-plugin-react/pull/1419\"\u003e#1419\u003c/a\u003e)\u003c/h3\u003e\n\u003cp\u003eAdd experimental native React Compiler support.\u003c/p\u003e\n\u003cp\u003eYou can use it by installing \u003ccode\u003eoxc-transform-react\u003c/code\u003e and enabling it via the \u003ccode\u003ecompiler\u003c/code\u003e option:\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install -D oxc-transform-react\n\u003c/code\u003e\u003c/pre\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003eimport { defineConfig } from 'vite'\nimport react from '@vitejs/plugin-react'\n\u003cp\u003eexport default defineConfig({\u003cbr /\u003e\nplugins: [\u003cbr /\u003e\nreact({ compiler: true })\u003cbr /\u003e\n]\u003cbr /\u003e\n})\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003ch2\u003e6.0.5 (2026-07-30)\u003c/h2\u003e\n\u003ch3\u003eFixed the react compiler preset filter to be linear (\u003ca href=\"https://redirect.github.com/vitejs/vite-plugin-react/pull/1353\"\u003e#1353\u003c/a\u003e)\u003c/h3\u003e\n\u003cp\u003eThe improved filter in v6.0.3 was non-linear and caused a performance regression (\u003ca href=\"https://redirect.github.com/vitejs/vite-plugin-react/issues/1349\"\u003e#1349\u003c/a\u003e). The filter was changed to be linear to avoid that.\u003c/p\u003e\n\u003ch2\u003e6.0.4 (2026-07-22)\u003c/h2\u003e\n\u003ch3\u003eFixed \u003ccode\u003e$RefreshSig$ is not defined\u003c/code\u003e error when running \u003ccode\u003evite dev\u003c/code\u003e with \u003ccode\u003eNODE_ENV=production\u003c/code\u003e\u003c/h3\u003e\n\u003cp\u003eWhen running \u003ccode\u003evite dev\u003c/code\u003e with \u003ccode\u003eNODE_ENV=production\u003c/code\u003e, the app errored with \u003ccode\u003e$RefreshSig$ is not defined\u003c/code\u003e.\nThis error is now fixed.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite-plugin-react/commit/04cac5020e349f452d76c5a4f6d788ad4b38930a\"\u003e\u003ccode\u003e04cac50\u003c/code\u003e\u003c/a\u003e release: plugin-react@6.1.1 (\u003ca href=\"https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1440\"\u003e#1440\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite-plugin-react/commit/82d35abe4946eddd4e6456802bf2b53444e264f2\"\u003e\u003ccode\u003e82d35ab\u003c/code\u003e\u003c/a\u003e fix(react): respect environment sourcemap option when \u003ccode\u003ebuilder.sharedPlugins\u003c/code\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite-plugin-react/commit/397e8471a559f18a16dd21bd797ac01a369dabdc\"\u003e\u003ccode\u003e397e847\u003c/code\u003e\u003c/a\u003e fix(react): make logging diagnostics an opt-in for React Compiler (\u003ca href=\"https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1431\"\u003e#1431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite-plugin-react/commit/61006e6f52124821c24121a78712f7162ae36f5b\"\u003e\u003ccode\u003e61006e6\u003c/code\u003e\u003c/a\u003e fix(deps): update all non-major dependencies (\u003ca href=\"https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1433\"\u003e#1433\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite-plugin-react/commit/e2a649cbaa7334d6991f843563683975667e1be1\"\u003e\u003ccode\u003ee2a649c\u003c/code\u003e\u003c/a\u003e chore: use \u003ccode\u003edeps.neverBundle\u003c/code\u003e instead of \u003ccode\u003eexternal\u003c/code\u003e in tsdown config (\u003ca href=\"https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1430\"\u003e#1430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite-plugin-react/commit/fb2d6f3635acbb0f3acbd0e9a914f6c620460957\"\u003e\u003ccode\u003efb2d6f3\u003c/code\u003e\u003c/a\u003e fix(deps): update all non-major dependencies (\u003ca href=\"https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1427\"\u003e#1427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite-plugin-react/commit/39b31735bf79c2dd380eedaba7ed849256f92a29\"\u003e\u003ccode\u003e39b3173\u003c/code\u003e\u003c/a\u003e release: plugin-react@6.1.0 (\u003ca href=\"https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1428\"\u003e#1428\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite-plugin-react/commit/f1340b0c760b1c16e1b780eeba46fd933ddd52eb\"\u003e\u003ccode\u003ef1340b0\u003c/code\u003e\u003c/a\u003e feat(react): add native React Compiler support (\u003ca href=\"https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1419\"\u003e#1419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite-plugin-react/commit/9ab698eafc38ffa14861db450291ed2f6f557557\"\u003e\u003ccode\u003e9ab698e\u003c/code\u003e\u003c/a\u003e fix(deps): update all non-major dependencies (\u003ca href=\"https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1375\"\u003e#1375\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite-plugin-react/commit/68c0cb8796ce18bd049c3d05c5210eaf0617eac0\"\u003e\u003ccode\u003e68c0cb8\u003c/code\u003e\u003c/a\u003e release: plugin-react@6.0.5 (\u003ca href=\"https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1362\"\u003e#1362\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.1.1/packages/plugin-react\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@vitest/coverage-v8` from 4.1.10 to 5.0.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitest-dev/vitest/releases\"\u003e@​vitest/coverage-v8's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.0.0\u003c/h2\u003e\n\u003cp\u003eVitest 5 is officially out! This release focuses on performance and brings a lot of new features while fixing long-standing bugs. See our \u003ca href=\"https://vitest.dev/blog/vitest-5.html\"\u003eblog post\u003c/a\u003e for the official announcement.\u003c/p\u003e\n\u003ch3\u003e   🚨 Breaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReplace \u003ccode\u003eloupe.inspect\u003c/code\u003e with pretty-format  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eClaude Opus 5 (1M context)\u003c/strong\u003e and \u003cstrong\u003eOpenAI Codex\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9609\"\u003evitest-dev/vitest#9609\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/3f802da4b\"\u003e\u003c!-- raw HTML omitted --\u003e(3f802)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove quotes from string values in \u003ccode\u003etest.for/each\u003c/code\u003e title \u003ccode\u003e$\u003c/code\u003e variable (take 2)  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10170\"\u003evitest-dev/vitest#10170\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/04d37e9d7\"\u003e\u003c!-- raw HTML omitted --\u003e(04d37)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDefault \u003ccode\u003eattachmentsDir\u003c/code\u003e from \u003ccode\u003e.vitest-attachements/\u003c/code\u003e to \u003ccode\u003e.vitest/attachments/\u003c/code\u003e  -  by \u003ca href=\"https://github.com/MdSadiqMd\"\u003e\u003ccode\u003e@​MdSadiqMd\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10186\"\u003evitest-dev/vitest#10186\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/1ba7338c3\"\u003e\u003c!-- raw HTML omitted --\u003e(1ba73)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove \u003ccode\u003esequential\u003c/code\u003e test/suite options in favor of \u003ccode\u003econcurrent\u003c/code\u003e  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e and \u003cstrong\u003eOpenAI Codex\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10198\"\u003evitest-dev/vitest#10198\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/9229f2edc\"\u003e\u003c!-- raw HTML omitted --\u003e(9229f)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRepresent locator as an object instead of a string  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10212\"\u003evitest-dev/vitest#10212\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/80f07edf6\"\u003e\u003c!-- raw HTML omitted --\u003e(80f07)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eInline \u003ccode\u003eexpect\u003c/code\u003e package  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10221\"\u003evitest-dev/vitest#10221\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/ad16223e7\"\u003e\u003c!-- raw HTML omitted --\u003e(ad162)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove deprecated entry points  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10222\"\u003evitest-dev/vitest#10222\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/994c6ddb9\"\u003e\u003c!-- raw HTML omitted --\u003e(994c6)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRequire Node.js 22 and Vite 6.4  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10178\"\u003evitest-dev/vitest#10178\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/3876283e8\"\u003e\u003c!-- raw HTML omitted --\u003e(38762)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail \u003ccode\u003eexpect.poll\u003c/code\u003e when function didn't resolve in time  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e and \u003cstrong\u003eOpenAI Codex\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10233\"\u003evitest-dev/vitest#10233\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/4df048c11\"\u003e\u003c!-- raw HTML omitted --\u003e(4df04)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThrow an error if hoistable methods are outside the top level scope  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10460\"\u003evitest-dev/vitest#10460\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/d0b4fddcb\"\u003e\u003c!-- raw HTML omitted --\u003e(d0b4f)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etoHaveTextContent\u003c/code\u003e is strict, add \u003ccode\u003etoMatchTextContent\u003c/code\u003e as alternative  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10473\"\u003evitest-dev/vitest#10473\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/18f303079\"\u003e\u003c!-- raw HTML omitted --\u003e(18f30)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDon't lookup config file from ancestor directories  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eOpenAI Codex\u003c/strong\u003e and \u003cstrong\u003eHiroshi Ogawa\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10428\"\u003evitest-dev/vitest#10428\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/945d9090e\"\u003e\u003c!-- raw HTML omitted --\u003e(945d9)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eInline \u003ccode\u003e@vitest/runner\u003c/code\u003e package, do not publish it anymore  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10511\"\u003evitest-dev/vitest#10511\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/6d6e46b1e\"\u003e\u003c!-- raw HTML omitted --\u003e(6d6e4)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAllow mutating happy-dom/jsdom window object  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eHiroshi Ogawa\u003c/strong\u003e and \u003cstrong\u003eOpenAI Codex\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10373\"\u003evitest-dev/vitest#10373\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/206e8cff8\"\u003e\u003c!-- raw HTML omitted --\u003e(206e8)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExpose \u003ccode\u003econcurrencyId\u003c/code\u003e/\u003ccode\u003eworkerId\u003c/code\u003e on TestModule's diagnostics, make id 1-based  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10516\"\u003evitest-dev/vitest#10516\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/bdd985433\"\u003e\u003c!-- raw HTML omitted --\u003e(bdd98)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003escreenshotDirectory\u003c/code\u003e config to \u003ccode\u003ebrowser.expect.toMatchScreenshot\u003c/code\u003e  -  by \u003ca href=\"https://github.com/macarie\"\u003e\u003ccode\u003e@​macarie\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10592\"\u003evitest-dev/vitest#10592\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/a60ded0fb\"\u003e\u003c!-- raw HTML omitted --\u003e(a60de)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@sinonjs/fake-timers\u003c/code\u003e and support mocking \u003ccode\u003eTemporal\u003c/code\u003e  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eHiroshi Ogawa\u003c/strong\u003e and \u003cstrong\u003eOpenCode (gpt-5.6-sol)\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10654\"\u003evitest-dev/vitest#10654\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/f8b1532fe\"\u003e\u003c!-- raw HTML omitted --\u003e(f8b15)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove webdriverio package  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10675\"\u003evitest-dev/vitest#10675\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/5fed68f72\"\u003e\u003c!-- raw HTML omitted --\u003e(5fed6)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eClear mocks by default before each test  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10613\"\u003evitest-dev/vitest#10613\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/0f6463bf2\"\u003e\u003c!-- raw HTML omitted --\u003e(0f646)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDon't emit localStorage warnings on Node 26, fail gracefully when worker fails to start  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10293\"\u003evitest-dev/vitest#10293\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/334edef92\"\u003e\u003c!-- raw HTML omitted --\u003e(334ed)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSeparate config resolution from the server creation  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10554\"\u003evitest-dev/vitest#10554\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/1c0ec3444\"\u003e\u003c!-- raw HTML omitted --\u003e(1c0ec)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eInline projects extend the root config by default  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10750\"\u003evitest-dev/vitest#10750\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/fec001ad3\"\u003e\u003c!-- raw HTML omitted --\u003e(fec00)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEnable mocking Temporal without fake timers  -  by \u003ca href=\"https://github.com/fabon-f\"\u003e\u003ccode\u003e@​fabon-f\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eHiroshi Ogawa\u003c/strong\u003e and \u003cstrong\u003eOpenCode (gpt-5.6-sol)\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10757\"\u003evitest-dev/vitest#10757\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/ac2d46b42\"\u003e\u003c!-- raw HTML omitted --\u003e(ac2d4)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport nested projects  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10846\"\u003evitest-dev/vitest#10846\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/ec367cf2a\"\u003e\u003c!-- raw HTML omitted --\u003e(ec367)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse \u003ccode\u003e\u0026gt;\u003c/code\u003e as separator in \u003ccode\u003e-t\u003c/code\u003e, calculate \u003ccode\u003eonly\u003c/code\u003e once  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10686\"\u003evitest-dev/vitest#10686\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/a0b20bc86\"\u003e\u003c!-- raw HTML omitted --\u003e(a0b20)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the test when an asynchronous assertion is not awaited  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10868\"\u003evitest-dev/vitest#10868\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/86d4a9da9\"\u003e\u003c!-- raw HTML omitted --\u003e(86d4a)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eShare the Vite server between inline projects  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10848\"\u003evitest-dev/vitest#10848\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/d87c96ee4\"\u003e\u003c!-- raw HTML omitted --\u003e(d87c9)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eParse files statically in vitest list by default  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/11088\"\u003evitest-dev/vitest#11088\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/51e949416\"\u003e\u003c!-- raw HTML omitted --\u003e(51e94)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebenchmark\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eRewrite the public API  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10113\"\u003evitest-dev/vitest#10113\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/19f6e8947\"\u003e\u003c!-- raw HTML omitted --\u003e(19f6e)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebrowser\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eIframe scale  -  by \u003ca href=\"https://github.com/macarie\"\u003e\u003ccode\u003e@​macarie\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9745\"\u003evitest-dev/vitest#9745\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/b639852cc\"\u003e\u003c!-- raw HTML omitted --\u003e(b6398)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEnable \u003ccode\u003elocators.exact\u003c/code\u003e by default  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10430\"\u003evitest-dev/vitest#10430\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/e203202f9\"\u003e\u003c!-- raw HTML omitted --\u003e(e2032)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRequire \u003ccode\u003esessionId\u003c/code\u003e for orchestrator html request  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eHiroshi Ogawa\u003c/strong\u003e and \u003cstrong\u003eOpenAI Codex\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10522\"\u003evitest-dev/vitest#10522\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/79b7d8fcc\"\u003e\u003c!-- raw HTML omitted --\u003e(79b7d)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSave failure screenshots in \u003ccode\u003eattachmentsDir\u003c/code\u003e  -  by \u003ca href=\"https://github.com/macarie\"\u003e\u003ccode\u003e@​macarie\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10917\"\u003evitest-dev/vitest#10917\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/3b5bbd8b4\"\u003e\u003c!-- raw HTML omitted --\u003e(3b5bb)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecoverage\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003einclude/exclude\u003c/code\u003e globs too eager  -  by \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9818\"\u003evitest-dev/vitest#9818\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/edacb0fd4\"\u003e\u003c!-- raw HTML omitted --\u003e(edacb)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAllow \u003ccode\u003ethresholds.perFile\u003c/code\u003e to accept an object  -  by \u003ca href=\"https://github.com/vladlenskiy\"\u003e\u003ccode\u003e@​vladlenskiy\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10190\"\u003evitest-dev/vitest#10190\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/13b78d98b\"\u003e\u003c!-- raw HTML omitted --\u003e(13b78)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexpect\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003etoThrow(\u0026quot;\u0026quot;)\u003c/code\u003e behavior by reverting \u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/6710\"\u003e#6710\u003c/a\u003e  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9643\"\u003evitest-dev/vitest#9643\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/6710\"\u003evitest-dev/vitest#6710\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/6c3e4bdbf\"\u003e\u003c!-- raw HTML omitted --\u003e(6c3e4)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emocker\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eDeserialize automock as automock  -  by \u003ca href=\"https://github.com/nami8824\"\u003e\u003ccode\u003e@​nami8824\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10192\"\u003evitest-dev/vitest#10192\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/2f892712d\"\u003e\u003c!-- raw HTML omitted --\u003e(2f892)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ereporters\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eblob\u003c/code\u003e reporter and \u003ccode\u003e--merge-reports\u003c/code\u003e default to \u003ccode\u003e.vitest/blob/\u003c/code\u003e  -  by \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10232\"\u003evitest-dev/vitest#10232\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/d22b029ae\"\u003e\u003c!-- raw HTML omitted --\u003e(d22b0)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWrite json and junit reporter output files to \u003ccode\u003e.vitest\u003c/code\u003e by default  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eHiroshi Ogawa\u003c/strong\u003e, \u003cstrong\u003eOpenCode (gpt-5.6-sol)\u003c/strong\u003e and \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10621\"\u003evitest-dev/vitest#10621\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/58577290a\"\u003e\u003c!-- raw HTML omitted --\u003e(58577)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/f441c6fab25e579c5b7dd3dd50538416f415fbae\"\u003e\u003ccode\u003ef441c6f\u003c/code\u003e\u003c/a\u003e chore: release v5.0.0 (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/11130\"\u003e#11130\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/c4473e48ee046938a9ab6784fe2735257c2c0f72\"\u003e\u003ccode\u003ec4473e4\u003c/code\u003e\u003c/a\u003e fix(coverage): prevent crash on \u003ccode\u003e/@fs/\u003c/code\u003e prepended virtual files (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/11119\"\u003e#11119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/897f51fd2493046c52ec9539b7d02fe3763bd63e\"\u003e\u003ccode\u003e897f51f\u003c/code\u003e\u003c/a\u003e chore: release v5.0.0-rc.4 (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/11107\"\u003e#11107\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/7db80dc27e5948010c00160ed0b86570baad6ce8\"\u003e\u003ccode\u003e7db80dc\u003c/code\u003e\u003c/a\u003e chore: release v5.0.0-rc.3 (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/11089\"\u003e#11089\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/5f6a5e84a5e8cef301e15ac2e8f8e9837b002ec6\"\u003e\u003ccode\u003e5f6a5e8\u003c/code\u003e\u003c/a\u003e feat(coverage): switch to \u003ccode\u003e@vitest/istanbuljs\u003c/code\u003e packages (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/11053\"\u003e#11053\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/c6174a6cf2847b23075ee35ba5151c2184a70594\"\u003e\u003ccode\u003ec6174a6\u003c/code\u003e\u003c/a\u003e fix(coverage): v8 to ignore Vite SSR's generated import bindings (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/11023\"\u003e#11023\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/af83d1b1933b5d74c421d30849717369b828de0b\"\u003e\u003ccode\u003eaf83d1b\u003c/code\u003e\u003c/a\u003e chore: release v5.0.0-rc.2 (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/10976\"\u003e#10976\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/a7fa111fef94bdc80ca9614c4e20b56f3393c920\"\u003e\u003ccode\u003ea7fa111\u003c/code\u003e\u003c/a\u003e chore: release v5.0.0-rc.1 (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/10920\"\u003e#10920\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/0553851f9f299233fbd2e797a76152e98f593ac7\"\u003e\u003ccode\u003e0553851\u003c/code\u003e\u003c/a\u003e chore: add Knip checks (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/10847\"\u003e#10847\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/b7be731900e913c5aae905af03a50fb55f23eac0\"\u003e\u003ccode\u003eb7be731\u003c/code\u003e\u003c/a\u003e chore: release v5.0.0-beta.7 (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/10825\"\u003e#10825\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vitest-dev/vitest/commits/v5.0.0/packages/coverage-v8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `browserslist` from 4.28.8 to 4.28.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/releases\"\u003ebrowserslist's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md\"\u003ebrowserslist's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/12ed5252dabc14fee4e97b465894b2f90910ca62\"\u003e\u003ccode\u003e12ed525\u003c/code\u003e\u003c/a\u003e Release 4.28.9 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/b1d8cf9d7a7dc76f6585425a8360218289194297\"\u003e\u003ccode\u003eb1d8cf9\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/21517b651c915cdbbfb8c122268bc36f5cabb7ef\"\u003e\u003ccode\u003e21517b6\u003c/code\u003e\u003c/a\u003e Improve \u003ccode\u003eor\u003c/code\u003e parsing performance\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/browserslist/browserslist/compare/4.28.8...4.28.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `eslint` from 10.6.0 to 10.10.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/eslint/eslint/releases\"\u003eeslint's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev10.10.0\u003c/h2\u003e\n\u003ch2\u003eFeatures\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/264b4346d1963701df0c398b4aeb2f6e8b2af93e\"\u003e\u003ccode\u003e264b434\u003c/code\u003e\u003c/a\u003e feat: add \u003ccode\u003ed\u003c/code\u003e and \u003ccode\u003ev\u003c/code\u003e flags to \u003ccode\u003eno-unexpected-multiline\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21305\"\u003e#21305\u003c/a\u003e) (Gihyeon Jeong / 정기현)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/c6cc6c592f30901345d94ef75e0d42c1894fae6c\"\u003e\u003ccode\u003ec6cc6c5\u003c/code\u003e\u003c/a\u003e feat: check \u003ccode\u003eObject.prototype\u003c/code\u003e property names in \u003ccode\u003enew-cap\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21269\"\u003e#21269\u003c/a\u003e) (crimsonjay0)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/5661fa65fde9fd4c14f0b730e3cee6a42fc657c1\"\u003e\u003ccode\u003e5661fa6\u003c/code\u003e\u003c/a\u003e feat: no-extra-bind false negatives with class fields and static blocks (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21260\"\u003e#21260\u003c/a\u003e) (synthex-byte)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/bb47dc6da2399a8f76c0c0c3273e6bc314c480e5\"\u003e\u003ccode\u003ebb47dc6\u003c/code\u003e\u003c/a\u003e fix: update dependency file-entry-cache to v11 (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/20801\"\u003e#20801\u003c/a\u003e) (Milos Djermanovic)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/427ac0a014066c36aa57fa8fa9af20fd9fb591e1\"\u003e\u003ccode\u003e427ac0a\u003c/code\u003e\u003c/a\u003e fix: use format strings in debug calls (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21247\"\u003e#21247\u003c/a\u003e) (Francesco Trotta)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/9d8153223dbf47b9aecdc1474202aaee4845f146\"\u003e\u003ccode\u003e9d81532\u003c/code\u003e\u003c/a\u003e fix: support \u003ccode\u003e__proto__\u003c/code\u003e in \u003ccode\u003e/* exported */\u003c/code\u003e comments (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21261\"\u003e#21261\u003c/a\u003e) (sethamus)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/87e0a082438264ad90b87fd74165ab4fd90f63ef\"\u003e\u003ccode\u003e87e0a08\u003c/code\u003e\u003c/a\u003e fix: prefer-object-has-own autofix breaks when Object is shadowed (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21282\"\u003e#21282\u003c/a\u003e) (김채영)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/8e2cb142217f2efee1d10dcc02bfb75145ae775d\"\u003e\u003ccode\u003e8e2cb14\u003c/code\u003e\u003c/a\u003e fix: \u003ccode\u003enew-cap\u003c/code\u003e false positive for \u003ccode\u003eUTC\u003c/code\u003e calls with \u003ccode\u003eproperties: false\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21275\"\u003e#21275\u003c/a\u003e) (Pixel)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/9f4a364ab0ade048dfce1f37792b1d461d866e55\"\u003e\u003ccode\u003e9f4a364\u003c/code\u003e\u003c/a\u003e fix: Ignore static imports in no-unreachable (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21276\"\u003e#21276\u003c/a\u003e) (Taha Kotil)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/2417cad57d7d1bc4cf3ecf0f0575cfb10ff2011c\"\u003e\u003ccode\u003e2417cad\u003c/code\u003e\u003c/a\u003e docs: Update README (GitHub Actions Bot)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/9cecb8a0a2348070abf72321965d41919c7cc626\"\u003e\u003ccode\u003e9cecb8a\u003c/code\u003e\u003c/a\u003e docs: document \u003ccode\u003e\\c\u003c/code\u003e control letter escapes in no-control-regex (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21286\"\u003e#21286\u003c/a\u003e) (한국)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/8724829f69f8ed80c876e3a5a017da199ce78739\"\u003e\u003ccode\u003e8724829\u003c/code\u003e\u003c/a\u003e docs: update compat table links (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21263\"\u003e#21263\u003c/a\u003e) (fnx)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/5634542be580750ffb1a5766470f9e9c72719696\"\u003e\u003ccode\u003e5634542\u003c/code\u003e\u003c/a\u003e docs: Clarify eqeqeq suggestion behavior (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21256\"\u003e#21256\u003c/a\u003e) (Müslüm Yılmaz)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eChores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/b3d876b46083d67899eb1d9613118c1c583632a2\"\u003e\u003ccode\u003eb3d876b\u003c/code\u003e\u003c/a\u003e chore: disable npm au...\n\n_Description has been truncated_","html_url":"https://github.com/Brooklyn20i/rodney-brain/pull/157","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Brooklyn20i%2Frodney-brain/issues/157","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/157/packages"},{"uuid":"5436754351","node_id":"PR_kwDORRCW3s8AAAABDS0yww","number":6,"state":"open","title":"Bump fast-uri from 3.1.0 to 3.1.7","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-12T23:34:53.000Z","updated_at":"2026-09-12T23:36:53.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"fast-uri","old_version":"3.1.0","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"}],"path":null,"ecosystem":"npm"},"body":"Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.0 to 3.1.7.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.0...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=fast-uri\u0026package-manager=npm_and_yarn\u0026previous-version=3.1.0\u0026new-version=3.1.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/CallingCrow/btt-app/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/CallingCrow/btt-app/pull/6","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/CallingCrow%2Fbtt-app/issues/6","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/6/packages"},{"uuid":"5436705271","node_id":"PR_kwDOUYYxZs8AAAABDSySQQ","number":1,"state":"closed","title":"build(deps): bump the npm_and_yarn group across 1 directory with 11 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-12T23:24:46.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-12T23:24:02.000Z","updated_at":"2026-09-12T23:24:48.000Z","time_to_close":44,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"npm_and_yarn","update_count":11,"packages":[{"name":"next","old_version":"16.2.6","new_version":"16.3.5","repository_url":"https://github.com/vercel/next.js"},{"name":"vite","old_version":"8.0.13","new_version":"8.3.0","repository_url":"https://github.com/vitejs/vite"},{"name":"@babel/core","old_version":"7.29.0","new_version":"7.29.7","repository_url":"https://github.com/babel/babel"},{"name":"brace-expansion","old_version":"1.1.14","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"fast-uri","old_version":"3.1.2","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"js-yaml","old_version":"4.1.1","new_version":"4.3.2","repository_url":"https://github.com/nodeca/js-yaml"},{"name":"sharp","old_version":"0.34.5","new_version":"0.35.4","repository_url":"https://github.com/lovell/sharp"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 7 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [next](https://github.com/vercel/next.js) | `16.2.6` | `16.3.5` |\n| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.0.13` | `8.3.0` |\n| [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) | `7.29.0` | `7.29.7` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.14` | `1.1.18` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.2` | `3.1.7` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.1` | `4.3.2` |\n| [sharp](https://github.com/lovell/sharp) | `0.34.5` | `0.35.4` |\n\n\nUpdates `next` from 16.2.6 to 16.3.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003enext's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.5\u003c/h2\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does not include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003enext/image: Skip 0-byte entries when initializing disk LRU cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98185\"\u003e#98185\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enext/image: Reject empty images when reading/writing to the disk cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98186\"\u003e#98186\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEmit whole-app server NFTs when \u003ccode\u003eoutput: 'standalone'\u003c/code\u003e is used with an adapter (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98167\"\u003e#98167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd CSP nonce to script tags of loading and template files (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98403\"\u003e#98403\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003euse cache\u003c/code\u003e prerender signal retention (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98448\"\u003e#98448\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.4\u003c/h2\u003e\n\u003cp\u003eFollow-up release to \u003ca href=\"https://github.com/vercel/next.js/releases/tag/v16.3.3\"\u003ev16.3.3\u003c/a\u003e re-enabling AVIF Image Optimization (\u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97949\"\u003e#97949\u003c/a\u003e).\u003c/p\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003etestmode: Fix infinite recursion in testmode passthrough fetch (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97691\"\u003e#97691\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix build error when aliasing typescript to \u003ccode\u003e@​typescript/typescript6\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97997\"\u003e#97997\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix unset crossOrigin in Turbopack manifests (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97930\"\u003e#97930\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.3\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eCritical:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36\"\u003eUnauthenticated Remote Code Execution on windows-hosted servers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4\"\u003eUnauthenticated Remote Code Execution in Image Optimization API when AVIF files are used\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.2\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Scope app-entry export validation to files inside the app directory (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97357\"\u003e#97357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[backport] Fix catch-all index page being served for every other slug (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97416\"\u003e#97416\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: don't trace embedded WASM loader helpers (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97353\"\u003e#97353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97463\"\u003e#97463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: retain conditions when replacing resolve request keys (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97453\"\u003e#97453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Fix Turbopack worker chunk loading with asset prefix (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97419\"\u003e#97419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97603\"\u003e#97603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/lubieowoce\"\u003e\u003ccode\u003e@​lubieowoce\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[16.x] Turbopack: don't strip async-module runtime from shared runtime chunks by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96653\"\u003evercel/next.js#96653\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/ca2c75eb7f8d9dd012a8bb83c06132149fe221f9\"\u003e\u003ccode\u003eca2c75e\u003c/code\u003e\u003c/a\u003e v16.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/14fb290de65077e9f1e22ef56d8de6cc1e63d436\"\u003e\u003ccode\u003e14fb290\u003c/code\u003e\u003c/a\u003e [backport] Fix use cache prerender signal retention (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98448\"\u003e#98448\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/2b1f28dbe1de344807ec0946a85171bc890a6047\"\u003e\u003ccode\u003e2b1f28d\u003c/code\u003e\u003c/a\u003e [16.3.x] Add CSP nonce to script tags of loading and template files (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98403\"\u003e#98403\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/4b56cee3f01d3b249edcd798b51895d5126a4170\"\u003e\u003ccode\u003e4b56cee\u003c/code\u003e\u003c/a\u003e [16.3.x] Backport docs fixes (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98317\"\u003e#98317\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/5568a02a7d47f9cb088e58350f2c2e68d9e93a00\"\u003e\u003ccode\u003e5568a02\u003c/code\u003e\u003c/a\u003e [backport] docs: local development: Rewrite docker section, add Windows Dev D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/93249ab2144132abfd4a8d611dad5b5978107ee2\"\u003e\u003ccode\u003e93249ab\u003c/code\u003e\u003c/a\u003e [16.3.X] Emit whole-app server NFTs when \u003ccode\u003eoutput: 'standalone'\u003c/code\u003e is used with ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/6549fd7c4e15a8883b0ad1c2ef67dec287a44f12\"\u003e\u003ccode\u003e6549fd7\u003c/code\u003e\u003c/a\u003e [16.3.x] next/image: reject empty image on read/write to disk cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98186\"\u003e#98186\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/d9eac96e7526ff0b9cb51db9801f06e741fe1960\"\u003e\u003ccode\u003ed9eac96\u003c/code\u003e\u003c/a\u003e [16.3.x] next/image: skip 0-byte entries when initializing disk LRU cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/9\"\u003e#9\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/84b35feccb2b53a563e41ad2dfe7a5fe08c58d3f\"\u003e\u003ccode\u003e84b35fe\u003c/code\u003e\u003c/a\u003e [test] Fix 16.3 deploy test assertions (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98133\"\u003e#98133\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/14f9c1ac4e084a44633c354476ddeaf70969cd90\"\u003e\u003ccode\u003e14f9c1a\u003c/code\u003e\u003c/a\u003e [16.3.x][ci] Run flake detection and new deploy tests when merged and on back...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/compare/v16.2.6...v16.3.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `vite` from 8.0.13 to 8.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/releases\"\u003evite's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ecreate-vite@8.3.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/create-vite@8.3.0/packages/create-vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.3.0\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e avoid settling seen preload dependencies for performance (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23446\"\u003e#23446\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/e6f6b3e3119256daa837b2dc399058c8aa45b470\"\u003ee6f6b3e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ehandle CRLF line endings in code frame positions (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23219\"\u003e#23219\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/9913672bee9c34a2df7fff4c2538783cd4f43b4e\"\u003e9913672\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eonly treat whole \u003ccode\u003enode_modules\u003c/code\u003e path segments as dependencies (fix \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/17467\"\u003e#17467\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23437\"\u003e#23437\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/ef0dc17ada53d1169ae5a89cb8f6482831466755\"\u003eef0dc17\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance Improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eproxy:\u003c/strong\u003e pre-compile context matchers at server creation (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23263\"\u003e#23263\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8abf700eeb2411d8402d08f8e2696effafdbe774\"\u003e8abf700\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev8.3.0-beta.1\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003edevtools:\u003c/strong\u003e enable dev server integration (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23333\"\u003e#23333\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/68aeb8a3b5a5a2ccd505288999bae1a5e6942ee1\"\u003e68aeb8a\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e keep hash placeholders as-is in \u003ccode\u003eresolveFileUrl\u003c/code\u003e hook (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23422\"\u003e#23422\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/e8d6a4d3399c739772080d70c7f3c4d548a637c9\"\u003ee8d6a4d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebundled-dev:\u003c/strong\u003e mark payload delivered on client report (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23373\"\u003e#23373\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/a6d43bc9e3464faa4d49f090e75e1ab334ffb7b0\"\u003ea6d43bc\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update all non-major dependencies (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23445\"\u003e#23445\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/fc7c104e74d35a97fa313d5dd6f1b5e7d5b26159\"\u003efc7c104\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ehtml:\u003c/strong\u003e don't inline preload link targets (fix \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/13355\"\u003e#13355\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23387\"\u003e#23387\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/12e709ca4df1059747db1cb7c5d1cd71aba79a24\"\u003e12e709c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eresolve the actual package root in findNearestMainPackageData for nested package.json (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23356\"\u003e#23356\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8492422b8f110625a90c702f42f30784e8cf19dc\"\u003e8492422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eshortcuts extend error (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23447\"\u003e#23447\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/4ec58d159df4a1b4799356a1fda62db88ed14752\"\u003e4ec58d1\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMiscellaneous Chores\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eintroducing \u003ccode\u003e@e18e/eslint-plugin\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23357\"\u003e#23357\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/f79413353995a2344879014410a9128b1b9f8e9a\"\u003ef794133\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eremove unnecessary comment (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23448\"\u003e#23448\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/b919a1a8b5a7c694667f993d677973f42d349458\"\u003eb919a1a\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev8.3.0-beta.0\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eaccept Rolldown watch options in \u003ccode\u003eserver.watch\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23133\"\u003e#23133\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/1b5cfe3d3777d4ceb7f35fcee9d3c4279316a084\"\u003e1b5cfe3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd closeServer and closePreviewServer hooks (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23110\"\u003e#23110\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/e17d2d565b0288f169c7995adb2b192f917548e7\"\u003ee17d2d5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd top-level \u003ccode\u003etsconfig\u003c/code\u003e option (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23310\"\u003e#23310\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/93164c3530a7b4fc7bbedfb986d6afa9546cdef3\"\u003e93164c3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd warning for unsupported hooks in plugin returned from \u003ccode\u003eapplyToEnvironment\u003c/code\u003e hook (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23191\"\u003e#23191\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/fdef04f112aadfea40ad3c448d96a49a04c168bd\"\u003efdef04f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecli:\u003c/strong\u003e support naming the CPU profile via --profile [name] (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23042\"\u003e#23042\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/a500deeb6f52d93ca501a0fc612a5392b939f2f5\"\u003ea500dee\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003econfig:\u003c/strong\u003e warn on named imports from JSON modules (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23378\"\u003e#23378\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/472385e6ec4b21e3167c7abf9769883d1c9675f8\"\u003e472385e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecss:\u003c/strong\u003e minify style tag (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23183\"\u003e#23183\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8156684572bdcf73e9d8568ed67971f0467fab60\"\u003e8156684\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esearched params attached to workers are now preserved (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22280\"\u003e#22280\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/517b97f57ab9473e7417da856eb641d76870a56e\"\u003e517b97f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport subpath imports in dynamic import statements (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23185\"\u003e#23185\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/b78e2f1bc1cba404c4bd9faf518d26ec85e89fc7\"\u003eb78e2f1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003eimport.meta.ROLLDOWN_FILE_URL_*\u003c/code\u003e for assets in JS (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22888\"\u003e#22888\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/4366ac468343252df6d5706361a6348afa66f9cc\"\u003e4366ac4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003eimport.meta.ROLLDOWN_FILE_URL_*\u003c/code\u003e for other plugins (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22894\"\u003e#22894\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/e38f29ee48bea5ea3178faec5b78708e86f38afb\"\u003ee38f29e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md\"\u003evite's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v8.2.2...v8.3.0\"\u003e8.3.0\u003c/a\u003e (2026-09-10)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e avoid settling seen preload dependencies for performance (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23446\"\u003e#23446\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/e6f6b3e3119256daa837b2dc399058c8aa45b470\"\u003ee6f6b3e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edevtools:\u003c/strong\u003e enable dev server integration (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23333\"\u003e#23333\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/68aeb8a3b5a5a2ccd505288999bae1a5e6942ee1\"\u003e68aeb8a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eaccept Rolldown watch options in \u003ccode\u003eserver.watch\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23133\"\u003e#23133\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/1b5cfe3d3777d4ceb7f35fcee9d3c4279316a084\"\u003e1b5cfe3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd closeServer and closePreviewServer hooks (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23110\"\u003e#23110\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/e17d2d565b0288f169c7995adb2b192f917548e7\"\u003ee17d2d5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd top-level \u003ccode\u003etsconfig\u003c/code\u003e option (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23310\"\u003e#23310\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/93164c3530a7b4fc7bbedfb986d6afa9546cdef3\"\u003e93164c3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd warning for unsupported hooks in plugin returned from \u003ccode\u003eapplyToEnvironment\u003c/code\u003e hook (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23191\"\u003e#23191\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/fdef04f112aadfea40ad3c448d96a49a04c168bd\"\u003efdef04f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecli:\u003c/strong\u003e support naming the CPU profile via --profile [name] (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23042\"\u003e#23042\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/a500deeb6f52d93ca501a0fc612a5392b939f2f5\"\u003ea500dee\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003econfig:\u003c/strong\u003e warn on named imports from JSON modules (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23378\"\u003e#23378\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/472385e6ec4b21e3167c7abf9769883d1c9675f8\"\u003e472385e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecss:\u003c/strong\u003e minify style tag (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23183\"\u003e#23183\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8156684572bdcf73e9d8568ed67971f0467fab60\"\u003e8156684\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esearched params attached to workers are now preserved (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22280\"\u003e#22280\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/517b97f57ab9473e7417da856eb641d76870a56e\"\u003e517b97f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport subpath imports in dynamic import statements (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23185\"\u003e#23185\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/b78e2f1bc1cba404c4bd9faf518d26ec85e89fc7\"\u003eb78e2f1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003eimport.meta.ROLLDOWN_FILE_URL_*\u003c/code\u003e for assets in JS (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22888\"\u003e#22888\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/4366ac468343252df6d5706361a6348afa66f9cc\"\u003e4366ac4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003eimport.meta.ROLLDOWN_FILE_URL_*\u003c/code\u003e for other plugins (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22894\"\u003e#22894\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/e38f29ee48bea5ea3178faec5b78708e86f38afb\"\u003ee38f29e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eworker:\u003c/strong\u003e remove worker chunk if it's detected that it's not referenced (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22473\"\u003e#22473\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/924997a4bdda9115faee9bdb622fcec4fc8357f0\"\u003e924997a\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ehandle CRLF line endings in code frame positions (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23219\"\u003e#23219\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/9913672bee9c34a2df7fff4c2538783cd4f43b4e\"\u003e9913672\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eonly treat whole \u003ccode\u003enode_modules\u003c/code\u003e path segments as dependencies (fix \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/17467\"\u003e#17467\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23437\"\u003e#23437\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/ef0dc17ada53d1169ae5a89cb8f6482831466755\"\u003eef0dc17\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e keep hash placeholders as-is in \u003ccode\u003eresolveFileUrl\u003c/code\u003e hook (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23422\"\u003e#23422\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/e8d6a4d3399c739772080d70c7f3c4d548a637c9\"\u003ee8d6a4d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebundled-dev:\u003c/strong\u003e mark payload delivered on client report (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23373\"\u003e#23373\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/a6d43bc9e3464faa4d49f090e75e1ab334ffb7b0\"\u003ea6d43bc\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update all non-major dependencies (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23445\"\u003e#23445\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/fc7c104e74d35a97fa313d5dd6f1b5e7d5b26159\"\u003efc7c104\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ehtml:\u003c/strong\u003e don't inline preload link targets (fix \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/13355\"\u003e#13355\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23387\"\u003e#23387\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/12e709ca4df1059747db1cb7c5d1cd71aba79a24\"\u003e12e709c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eresolve the actual package root in findNearestMainPackageData for nested package.json (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23356\"\u003e#23356\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8492422b8f110625a90c702f42f30784e8cf19dc\"\u003e8492422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eshortcuts extend error (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23447\"\u003e#23447\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/4ec58d159df4a1b4799356a1fda62db88ed14752\"\u003e4ec58d1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003econfig:\u003c/strong\u003e close bundles when generation fails (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23256\"\u003e#23256\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/6bacc956df5a76cc5653b9de4493453b953439fd\"\u003e6bacc95\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecss:\u003c/strong\u003e keep newline-separated srcset candidates intact (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23265\"\u003e#23265\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/4f9d2f4dadc83191200de7d2154c957a711e8c3d\"\u003e4f9d2f4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update all non-major dependencies (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23337\"\u003e#23337\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/d55081581ddd4d55667fef38e85d02ab7f879f15\"\u003ed550815\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update all non-major dependencies (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23404\"\u003e#23404\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/238ad811c7fb9e4730cbd317d0657867ed3447b3\"\u003e238ad81\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update rolldown-related dependencies (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23338\"\u003e#23338\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/76e8082c56a2872dc8017c5672bc36cba8dcf75d\"\u003e76e8082\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update rolldown-related dependencies (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23405\"\u003e#23405\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/b88256607e3a051b7bcb0b338b3c4665926b55a8\"\u003eb882566\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edev:\u003c/strong\u003e run closeBundle after buildEnd failure (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23165\"\u003e#23165\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8cb872e7fb65b03f6068923c6aa7fcf3e71baf21\"\u003e8cb872e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ehmr:\u003c/strong\u003e handle \u003ccode\u003eimport.meta.hot.invalidate\u003c/code\u003e in virtual module (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23171\"\u003e#23171\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/616296895bd135386d35069a479a5f188c7de298\"\u003e6162968\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eutils:\u003c/strong\u003e handle dot in srcset density descriptor (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23346\"\u003e#23346\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/b50e1b4a3d66128a4076e19769b2e29657985516\"\u003eb50e1b4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eutils:\u003c/strong\u003e match timestamp query parameter with proper delimiters (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23364\"\u003e#23364\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/41f3c6fff88ade015669cac5c42db946e0b6f5c9\"\u003e41f3c6f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance Improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eproxy:\u003c/strong\u003e pre-compile context matchers at server creation (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23263\"\u003e#23263\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8abf700eeb2411d8402d08f8e2696effafdbe774\"\u003e8abf700\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMiscellaneous Chores\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eintroducing \u003ccode\u003e@e18e/eslint-plugin\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23357\"\u003e#23357\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/f79413353995a2344879014410a9128b1b9f8e9a\"\u003ef794133\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eremove unnecessary comment (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23448\"\u003e#23448\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/b919a1a8b5a7c694667f993d677973f42d349458\"\u003eb919a1a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edelete unused \u003ccode\u003ePluginContainerOptions\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23382\"\u003e#23382\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/ee644014aab61e546742b862a7d7b0d6c7d67a7b\"\u003eee64401\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse oxfmt \u003ccode\u003esortImports\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23319\"\u003e#23319\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/97ad042170f4c71b518239723b733dd98e8e3e76\"\u003e97ad042\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/95e8923f35d0252c9f6eb2d5e358c084542706f1\"\u003e\u003ccode\u003e95e8923\u003c/code\u003e\u003c/a\u003e release: v7.3.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/9d39d373a7b4e0a93322b70b9dbeb202af06af3e\"\u003e\u003ccode\u003e9d39d37\u003c/code\u003e\u003c/a\u003e feat: add \u003ccode\u003eignoreOutdatedRequests\u003c/code\u003e option to \u003ccode\u003eoptimizeDeps\u003c/code\u003e (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/21364\"\u003e#21364\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/acf7e05eaeb18e98f5e19e2d3e648950726f20d1\"\u003e\u003ccode\u003eacf7e05\u003c/code\u003e\u003c/a\u003e release: v7.3.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/cff26ec0fc13373d7125a5eac6cb01fe63fee4b1\"\u003e\u003ccode\u003ecff26ec\u003c/code\u003e\u003c/a\u003e feat(deps): update esbuild from ^0.25.0 to ^0.27.0 (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/21183\"\u003e#21183\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/317b3b272f9ef6faa647a51ab3b0768fecc1071d\"\u003e\u003ccode\u003e317b3b2\u003c/code\u003e\u003c/a\u003e release: v7.2.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/721f16343d9555ae8fc71a2e5354b22e12ff0dc3\"\u003e\u003ccode\u003e721f163\u003c/code\u003e\u003c/a\u003e fix: plugin shortcut support (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/21211\"\u003e#21211\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/bda5dbb648fa7cf877ea9c76ba8a7da226b65cce\"\u003e\u003ccode\u003ebda5dbb\u003c/code\u003e\u003c/a\u003e release: v7.2.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/3aa7527fb4fc7dafe3ab57c41d637d2985c7bb6e\"\u003e\u003ccode\u003e3aa7527\u003c/code\u003e\u003c/a\u003e release: v7.2.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/72e398a46d8d2f54fbcbeb9ff0dceab346aeb642\"\u003e\u003ccode\u003e72e398a\u003c/code\u003e\u003c/a\u003e fix(deps): update all non-major dependencies (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/21175\"\u003e#21175\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/3765f7baea36234bf3816eeed38776d27bfd3649\"\u003e\u003ccode\u003e3765f7b\u003c/code\u003e\u003c/a\u003e fix: shortcuts not rebound after server restart (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/21166\"\u003e#21166\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vitejs/vite/commits/create-vite@8.3.0/packages/vite\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@babel/core` from 7.29.0 to 7.29.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/babel/babel/releases\"\u003e@​babel/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.7 (2026-05-25)\u003c/h2\u003e\n\u003cp\u003eRe-release all packages with npm provenance attestations\u003c/p\u003e\n\u003ch2\u003ev7.29.6 (2026-05-25)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18014\"\u003e#18014\u003c/a\u003e Catchup source map position in preserveFormat (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18001\"\u003e#18001\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e, \u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17998\"\u003e#17998\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 3\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMateusz Burzyński (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.5 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:house:  Internal\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@babel/*\u003c/code\u003e dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.4 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17974\"\u003e#17974\u003c/a\u003e [7.x backport]fix(systemjs): improve module string name support (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 1\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.3 (2026-04-30)\u003c/h2\u003e\n\u003ch4\u003e:eyeglasses: Spec Compliance\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17923\"\u003e#17923\u003c/a\u003e Support flow extends bound (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-helper-create-class-features-plugin\u003c/code\u003e, \u003ccode\u003ebabel-plugin-proposal-decorators\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17931\"\u003e#17931\u003c/a\u003e fix(decorators): replace super within all removed static elements (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-register\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17915\"\u003e#17915\u003c/a\u003e Fix thread synchronization issues in \u003ccode\u003e@babel/register\u003c/code\u003e (\u003ca href=\"https://github.com/liuxingbaoyu\"\u003e\u003ccode\u003e@​liuxingbaoyu\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-compat-data\u003c/code\u003e, \u003ccode\u003ebabel-plugin-bugfix-safari-rest-destructuring-rhs-array\u003c/code\u003e, \u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17788\"\u003e#17788\u003c/a\u003e Add bugfix plugin for Safari array rest destructuring bug (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:nail_care: Polish\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/4fba7541180bf5f58256d8e358b544e3831ad090\"\u003e\u003ccode\u003e4fba754\u003c/code\u003e\u003c/a\u003e v7.29.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/04ea6b27fdac8f40c3481aec2080ac9678779509\"\u003e\u003ccode\u003e04ea6b2\u003c/code\u003e\u003c/a\u003e v7.29.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/99f498a9b9fa0b900d603fbe8f6601bb3b9e42bb\"\u003e\u003ccode\u003e99f498a\u003c/code\u003e\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/18001\"\u003e#18001\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/feba0a3654c596bd369d1ef1231f5d56666d56dc\"\u003e\u003ccode\u003efeba0a3\u003c/code\u003e\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17998\"\u003e#17998\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/babel/babel/commits/v7.29.7/packages/babel-core\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.14 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24\"\u003e\u003ccode\u003e2203f4f\u003c/code\u003e\u003c/a\u003e 1.1.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd\"\u003e\u003ccode\u003e0b09384\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-uri` from 3.1.2 to 3.1.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `js-yaml` from 4.1.1 to 4.3.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md\"\u003ejs-yaml's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.3.2 - 2026-08-26\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Hard-limit merge sequence size to 100.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Count empty mappings in merge sequences toward \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e\nto limit CPU usage, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/797\"\u003e#797\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.3.1 - 2026-07-31\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Remove quadratic complexity from \u003ccode\u003e!!omap\u003c/code\u003e duplicate key detection.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.3.0 - 2026-06-27\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Added \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e (10000) loader option to limit the total number of\nkeys processed by YAML merge (\u003ccode\u003e\u0026lt;\u0026lt;\u003c/code\u003e) across one \u003ccode\u003eload()\u003c/code\u003e / \u003ccode\u003eloadAll()\u003c/code\u003e call.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRestore umd builds back to es5.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRemoved\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e replaced with \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e for limiting YAML merge\nprocessing.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[4.2.0] - 2026-06-01\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003edocs/safety.md\u003c/code\u003e with notes about processing untrusted YAML.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003emaxDepth\u003c/code\u003e (100) loader option. Not a problem, but gives a better\nexception instead of RangeError on stack overflow.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e (20) loader option. Not a problem after \u003ccode\u003emerge\u003c/code\u003e fix,\nbut an additional restriction for safety.\u003c/li\u003e\n\u003cli\u003eAdded sourcemaps to \u003ccode\u003edist/\u003c/code\u003e builds.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStop resolving numbers with underscores as numeric scalars, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/627\"\u003e#627\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eSwitched dev toolchains to Vite / neostandard.\u003c/li\u003e\n\u003cli\u003eUpdated demo.\u003c/li\u003e\n\u003cli\u003eReorganized tests.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edist/\u003c/code\u003e files are no longer kept in the repository.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix parsing of properties on the first implicit block mapping key, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/62\"\u003e#62\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix trailing whitespace handling when folding flow scalar lines, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/307\"\u003e#307\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eReject top-level block scalars without content indentation, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/280\"\u003e#280\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eEnsure numbers survive round-trip, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/737\"\u003e#737\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix test coverage for issue \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/221\"\u003e#221\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix flow scalar trailing whitespace folding, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/307\"\u003e#307\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/79ca68d90f333fbe6d9e42827527e62636200191\"\u003e\u003ccode\u003e79ca68d\u003c/code\u003e\u003c/a\u003e 4.3.2 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/d90b6612a5a84385bdcb556c44578eac76dc0f6b\"\u003e\u003ccode\u003ed90b661\u003c/code\u003e\u003c/a\u003e Backport merge limits from v5.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/86e91b815b8794c3c73a179c1770871e37ec2df8\"\u003e\u003ccode\u003e86e91b8\u003c/code\u003e\u003c/a\u003e 4.3.1 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/c3cc4b0bb9ddb9af2dd9b61e0d56f5ce7983cd4a\"\u003e\u003ccode\u003ec3cc4b0\u003c/code\u003e\u003c/a\u003e Backport quadratic complexity fix for !!omap\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/33d05b5d29a8c21360f620f7e1c1706e24522eda\"\u003e\u003ccode\u003e33d05b5\u003c/code\u003e\u003c/a\u003e 4.3.0 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/663bfab6db2b4a146a9366fd685f069345be4ddb\"\u003e\u003ccode\u003e663bfab\u003c/code\u003e\u003c/a\u003e Drop demo publish, to not override new v5 one.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/1cb8c7b94bf75e15116869c1c0482dcb22785986\"\u003e\u003ccode\u003e1cb8c7b\u003c/code\u003e\u003c/a\u003e Add v4-legacy tag for publish\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/02f27afad532763263cd2b6be35c24ee8e1f6157\"\u003e\u003ccode\u003e02f27af\u003c/code\u003e\u003c/a\u003e Restore umd builds back to es5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/8be84edaf15e7c394fa3b813179d1bcc280e87fb\"\u003e\u003ccode\u003e8be84ed\u003c/code\u003e\u003c/a\u003e Fix es5 compatibility\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/59423c6f8cdc78742ac00e25a4dd39ef16b702e4\"\u003e\u003ccode\u003e59423c6\u003c/code\u003e\u003c/a\u003e Replace \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e option with \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e (more robust). Ba...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodeca/js-yaml/compare/4.1.1...4.3.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.4.31 to 8.5.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003epostcss-scss\u003c/code\u003e commend regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed reading any file via user-generated CSS.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eopts.unsafeMap\u003c/code\u003e to disable checks.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed nested brackets parsing performance (by \u003ca href=\"https://github.com/offset\"\u003e\u003ccode\u003e@​offset\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.10\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed XSS via unescaped \u003ccode\u003e\u0026lt;/style\u0026gt;\u003c/code\u003e in non-bundler cases (by \u003ca href=\"https://github.com/TharVid\"\u003e\u003ccode\u003e@​TharVid\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8\"\u003e\u003ccode\u003e7beca13\u003c/code\u003e\u003c/a\u003e Does no load source map file without opts.from\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/decea51421682341401575b3740709fda0e12930\"\u003e\u003ccode\u003edecea51\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/c18e30d126395d42a0726aa00e03a8f1088985ae\"\u003e\u003ccode\u003ec18e30d\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/98a39ad73d163a90be924d5126c771262110f1fc\"\u003e\u003ccode\u003e98a39ad\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/a3e48c492ddec0e4879d513b8b995fee887af352\"\u003e\u003ccode\u003ea3e48c4\u003c/code\u003e\u003c/a\u003e Release 8.5.22 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f49d6911795f53b2cfe023bb686bf1144ec30618\"\u003e\u003ccode\u003ef49d691\u003c/code\u003e\u003c/a\u003e Fix custom property losing its semicolon before a comment (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2117\"\u003e#2117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/28e0daf8f2fe5ba9e19ea3f8c27c8fe176f9419e\"\u003e\u003ccode\u003e28e0daf\u003c/code\u003e\u003c/a\u003e Release 8.5.21 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3d2b4e43e38274f233b5609d09687cadad8215d9\"\u003e\u003ccode\u003e3d2b4e4\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.4.31...8.5.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `sharp` from 0.34.5 to 0.35.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lovell/sharp/releases\"\u003esharp's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.35.4\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\"\u003ehttps://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.35.4-rc.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpgrade to libvips v8.18.6 for upstream bug fixes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7f1a0a22cc285fe180766f4935d50b55af6e8432\"\u003e\u003ccode\u003e7f1a0a2\u003c/code\u003e\u003c/a\u003e Release v0.35.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/f927818924bc5a9493d822a4e8b23ec5857c52e1\"\u003e\u003ccode\u003ef927818\u003c/code\u003e\u003c/a\u003e Upgrade to sharp-libvips v1.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e80209240d005c71e1173a50dd9cd4db4ce2a9e6\"\u003e\u003ccode\u003ee802092\u003c/code\u003e\u003c/a\u003e Prerelease v0.35.4-rc.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e13eb2f97a0a22f1ef726e8d0cd33f7c56835945\"\u003e\u003ccode\u003ee13eb2f\u003c/code\u003e\u003c/a\u003e CI: Fix wasm32 build (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4589\"\u003e#4589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/a82a0b3d58bc25854ad1e925e6eb0a50725d1489\"\u003e\u003ccode\u003ea82a0b3\u003c/code\u003e\u003c/a\u003e Upgrade to libvips v8.18.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/8044fe43e36d0ea7f8beb89f79a37bb0f3342e84\"\u003e\u003ccode\u003e8044fe4\u003c/code\u003e\u003c/a\u003e Bound resize dimensions to coordinate limit\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/147f8591a153bc4a1e199c3fe3150fac2931b30c\"\u003e\u003ccode\u003e147f859\u003c/code\u003e\u003c/a\u003e Docs: changelog entries for \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4578\"\u003e#4578\u003c/a\u003e \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ee5bfb853de75a611c64381783b04032a3a897d8\"\u003e\u003ccode\u003eee5bfb8\u003c/code\u003e\u003c/a\u003e Tests: use yauzl directly rather than via extract-zip wrapper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7a7788928f8a2a429f45039010a87cee35401694\"\u003e\u003ccode\u003e7a77889\u003c/code\u003e\u003c/a\u003e Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4588\"\u003e#4588\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ea5bef24c187b2c7ee3fe3cad3b45c8cb67a46fd\"\u003e\u003ccode\u003eea5bef2\u003c/code\u003e\u003c/a\u003e Improve support for input Streams finishing before output is requested (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/lovell/sharp/compare/v0.34.5...v0.35.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.24.8 to 7.29.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.28.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e7 security advisories\u003c/strong\u003e, all shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 7.28.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^7.28.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe v7 line is \u003cstrong\u003enot\u003c/strong\u003e affected by GHSA-38rv-x7px-6hhq (CVE-2026-9675), which is\nan 8.x-only regression.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on GHSA-hm92-r4w5-c3mj:\u003c/strong\u003e this fix shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e, not the\nearlier 7.2x line — the vulnerable single-pool code was still present through\n\u003ccode\u003ev7.27.2\u003c/code\u003e. The per-origin pool fix is\n\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5041\"\u003e#5041\u003c/a\u003e).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAdvisory\u003c/th\u003e\n\u003cth\u003eCVE\u003c/th\u003e\n\u003cth\u003eSeverity (CVSS)\u003c/th\u003e\n\u003cth\u003eFixed in\u003c/th\u003e\n\u003cth\u003eFix commit\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-12151\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8cb10f98\"\u003e\u003ccode\u003e8cb10f98\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g\"\u003eGHSA-vmh5-mc38-953g\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9697\u003c/td\u003e\n\u003ctd\u003eHigh (7.4)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/04201f89\"\u003e\u003ccode\u003e04201f89\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj\"\u003eGHSA-hm92-r4w5-c3mj\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6734\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6\"\u003eGHSA-pr7r-676h-xcf6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9678\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/85a24055\"\u003e\u003ccode\u003e85a24055\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv\"\u003eGHSA-p88m-4jfj-68fv\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9679\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m\"\u003eGHSA-g8m3-5g58-fq7m\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-11525\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52\"\u003eGHSA-35p6-xmwp-9g52\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6733\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ea8930cf\"\u003e\u003ccode\u003eea8930cf\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493...\n\n_Description has been truncated_","html_url":"https://github.com/franklinburrus/thefileswithdub/pull/1","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/franklinburrus%2Fthefileswithdub/issues/1","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1/packages"},{"uuid":"5435847057","node_id":"PR_kwDOQfaW688AAAABDSHh_Q","number":42,"state":"closed","title":"build(deps): bump the npm_and_yarn group across 2 directories with 7 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-12T21:06:17.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-12T20:33:51.000Z","updated_at":"2026-09-12T21:06:19.000Z","time_to_close":1946,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"npm_and_yarn","update_count":7,"packages":[{"name":"js-yaml","old_version":"3.15.1","new_version":"3.15.2","repository_url":"https://github.com/nodeca/js-yaml"},{"name":"adm-zip","old_version":"0.5.18","new_version":"0.6.1","repository_url":"https://github.com/cthackers/adm-zip"},{"name":"fast-uri","old_version":"3.1.5","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"postcss-selector-parser","old_version":"6.1.2","new_version":"6.1.4","repository_url":"https://github.com/postcss/postcss-selector-parser"},{"name":"postcss-selector-parser","old_version":"7.1.1","new_version":"7.1.6","repository_url":"https://github.com/postcss/postcss-selector-parser"},{"name":"svgo","old_version":"3.3.4","new_version":"3.3.5","repository_url":"https://github.com/svg/svgo"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 5 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `3.15.1` | `3.15.2` |\n| [adm-zip](https://github.com/cthackers/adm-zip) | `0.5.18` | `0.6.1` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.5` | `3.1.7` |\n| [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) | `6.1.2` | `6.1.4` |\n| [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) | `7.1.1` | `7.1.6` |\n| [svgo](https://github.com/svg/svgo) | `3.3.4` | `3.3.5` |\n\nBumps the npm_and_yarn group with 3 updates in the /docs directory: [js-yaml](https://github.com/nodeca/js-yaml), [svgo](https://github.com/svg/svgo) and [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro).\n\nUpdates `js-yaml` from 3.15.1 to 3.15.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md\"\u003ejs-yaml's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.15.2 - 2026-08-26\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Hard-limit merge sequence size to 100.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Count empty mappings in merge sequences toward \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e\nto limit CPU usage, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/797\"\u003e#797\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/5c45bd6e960603c13644f5cc8b572ca257723b36\"\u003e\u003ccode\u003e5c45bd6\u003c/code\u003e\u003c/a\u003e 3.15.2 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/5a708f9f4f22e78b87ebe363848cfa4fa4818c0d\"\u003e\u003ccode\u003e5a708f9\u003c/code\u003e\u003c/a\u003e dist rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/3485bc06ff8a0251505f44a00414d90df2466639\"\u003e\u003ccode\u003e3485bc0\u003c/code\u003e\u003c/a\u003e Backport merge limits from v5.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/f34812f1cea794f8c21e0a4e1f3a2584b720f305\"\u003e\u003ccode\u003ef34812f\u003c/code\u003e\u003c/a\u003e Update .gitignore\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodeca/js-yaml/compare/3.15.1...3.15.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `adm-zip` from 0.5.18 to 0.6.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cthackers/adm-zip/releases\"\u003eadm-zip's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.6.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cthackers/adm-zip/compare/v0.6.0...v0.6.1\"\u003ehttps://github.com/cthackers/adm-zip/compare/v0.6.0...v0.6.1\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dev dependencies\u003c/li\u003e\n\u003cli\u003eFixed uncaught crash in async decompression on malformed DEFLATE data\u003c/li\u003e\n\u003cli\u003eFixed addLocalFolder following symlinks out of the archived folder\u003c/li\u003e\n\u003cli\u003eStripped setuid/setgid/sticky bits from extracted file permissions\u003c/li\u003e\n\u003cli\u003eEnforced the decompression size cap on the async path and for size 0\u003c/li\u003e\n\u003cli\u003eRejected archives with duplicate entry names\u003c/li\u003e\n\u003cli\u003eBlocked extraction from writing through symlinks inside the target\u003c/li\u003e\n\u003cli\u003eRouted malformed-header parse errors through the async callback\u003c/li\u003e\n\u003cli\u003eRejected zip entries whose declared data extent runs past the buffer\u003c/li\u003e\n\u003cli\u003eFixed addLocalFolderPromise hanging on empty folders and swallowing errors\u003c/li\u003e\n\u003cli\u003eFixed addLocalFolderAsync2 mangling local paths on Windows\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.6.0\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cthackers/adm-zip/compare/v0.5.18...v0.6.0\"\u003ehttps://github.com/cthackers/adm-zip/compare/v0.5.18...v0.6.0\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eThis release fixes a security vulnerability (CVE-2026-39244), resolves several long-standing bugs, ships built-in TypeScript types, and includes two behavior changes worth reading before you upgrade.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eextractEntryTo(dirEntry, target, maintainEntryPath = false) now preserves subdirectories instead of flattening files into the target folder by basename (which also silently overwrote same-named files). (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/306\"\u003e#306\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eExtraction no longer fails when the modification time can't be set — utimes is now best-effort. (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/379\"\u003e#379\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMinimum Node.js is now 14 (the code already required it; engines was incorrectly \u0026gt;=12).\u003c/li\u003e\n\u003cli\u003eCVE-2026-39244 — a crafted archive declaring a huge uncompressed size could force an unbounded Buffer.alloc and OOM the process; allocation is now bounded by the data actually present. Reported by Daniel Púa (devploit), Anh Hong, and José Antonio Zamudio Amaya. (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/568\"\u003e#568\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHardened entry-name lookup against object injection (\u003cstrong\u003eproto\u003c/strong\u003e names). Prototype-less table.\u003c/li\u003e\n\u003cli\u003eData-descriptor regression rejecting valid archives (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/548\"\u003e#548\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/533\"\u003e#533\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/554\"\u003e#554\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDirectory permissions not restored on extract (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/530\"\u003e#530\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eInfinite recursion on symlink loops in addLocalFolder (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/541\"\u003e#541\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUncaught process crash in writeFileToAsync on write failure (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/470\"\u003e#470\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/459\"\u003e#459\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/402\"\u003e#402\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEmpty name on directory entries (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/466\"\u003e#466\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etest() always returned false for archives with files\u003c/li\u003e\n\u003cli\u003e~6× faster entry sorting for large archives\u003c/li\u003e\n\u003cli\u003eBuilt-in TypeScript definitions (types.d.ts) — you can drop \u003ccode\u003e@​types/adm-zip\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cthackers/adm-zip/blob/master/history.md\"\u003eadm-zip's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e0.6.0 / 2026-07-10\u003c/h1\u003e\n\u003cp\u003eSecurity\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed CVE-2026-39244: a crafted archive declaring a huge uncompressed size could force an unbounded \u003ccode\u003eBuffer.alloc\u003c/code\u003e (memory exhaustion / DoS) before any validation. Allocation is now bounded by the data actually present — STORED output is sized from the real bytes, DEFLATED output is grown by the inflater and capped at the declared size (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/568\"\u003e#568\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHardened the internal entry-name lookup table against object injection: entry names come from untrusted archives, and a name such as \u003ccode\u003e__proto__\u003c/code\u003e previously resolved to \u003ccode\u003eObject.prototype\u003c/code\u003e, crashing \u003ccode\u003eaddFile\u003c/code\u003e and hiding the entry from \u003ccode\u003egetEntry\u003c/code\u003e/\u003ccode\u003ereadFile\u003c/code\u003e. The table is now prototype-less\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eBug fixes\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a regression (0.5.15) that rejected valid archives using a data descriptor (general-purpose bit 3). The payload is now validated against the authoritative central-directory CRC instead of requiring/parsing the trailing descriptor (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/548\"\u003e#548\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/533\"\u003e#533\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/554\"\u003e#554\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eextractAllTo\u003c/code\u003e/\u003ccode\u003eextractAllToAsync\u003c/code\u003e not restoring directory permissions with \u003ccode\u003ekeepOriginalPermission\u003c/code\u003e; directory modes are applied after their contents are written, deepest path first, and no longer lock the extractor out of a restrictive directory (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/530\"\u003e#530\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed infinite recursion in \u003ccode\u003eaddLocalFolder\u003c/code\u003e when a folder contains a symlink pointing back to an ancestor (e.g. workspace \u003ccode\u003enode_modules\u003c/code\u003e); the walk now tracks resolved real paths and skips already-visited directories (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/541\"\u003e#541\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed an uncaught exception (\u003ccode\u003eERR_INVALID_ARG_TYPE\u003c/code\u003e) that crashed the process when \u003ccode\u003ewriteFileToAsync\u003c/code\u003e could not open the target file (bad permissions, invalid filename, exhausted file descriptors); write failures are now reported through the callback and write errors are no longer silently swallowed (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/470\"\u003e#470\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/459\"\u003e#459\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/402\"\u003e#402\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed directory entries reporting an empty \u003ccode\u003ename\u003c/code\u003e (e.g. \u003ccode\u003ea/b/c/\u003c/code\u003e now returns \u003ccode\u003ec\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/466\"\u003e#466\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eextractEntryTo\u003c/code\u003e flattening subdirectories when \u003ccode\u003emaintainEntryPath\u003c/code\u003e is false; the structure below the extracted directory is now preserved instead of collapsing (and overwriting) files by basename (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/306\"\u003e#306\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a failed \u003ccode\u003eutimes\u003c/code\u003e aborting extraction; setting the modification time is now best-effort and never fails extraction of already-written content (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/379\"\u003e#379\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003etest()\u003c/code\u003e always returning false for any archive containing a file (it indexed the entries array with an entry object instead of reading the entry); it now correctly verifies each entry's CRC\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003ePerformance\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFaster entry sorting when writing archives with many entries: names are decoded once instead of on every comparison (about 6× faster sort for large archives)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAdded\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eBundled TypeScript type definitions (\u003ccode\u003etypes.d.ts\u003c/code\u003e), so \u003ccode\u003e@types/adm-zip\u003c/code\u003e is no longer required\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNotes\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eBehavior change: \u003ccode\u003eextractEntryTo(dir, target, /* maintainEntryPath */ false)\u003c/code\u003e now preserves subdirectories beneath the extracted directory rather than flattening them\u003c/li\u003e\n\u003cli\u003eBehavior change: extraction no longer fails when the modification time cannot be set\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e0.5.4 / 2021-03-08\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eFixed relative paths\u003c/li\u003e\n\u003cli\u003eAdded zipcrypto encryption\u003c/li\u003e\n\u003cli\u003eLower verMade for macOS when generating zip file\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e0.5.3 / 2021-02-07\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eFixed filemode when unzipping\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e0.5.2 / 2021-01-27\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eFixed path traversal issue (GHSL-2020-198)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e0.5.1 / 2020-11-27\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eIncremented version (cthackers)\u003c/li\u003e\n\u003cli\u003eFixed outFileName (cthackers)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e0.5.0 / 2020-11-19\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eAdded extra parameter to extractEntryTo so target filename can be renamed (cthackers)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cthackers/adm-zip/commit/cb2cf9ba4c7c865db426e2de1997cb41194d9872\"\u003e\u003ccode\u003ecb2cf9b\u003c/code\u003e\u003c/a\u003e Fixed addLocalFolderAsync2 mangling local paths on Windows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cthackers/adm-zip/commit/54902b60f0f1d6d6e8157e81e0f18c5001941ccc\"\u003e\u003ccode\u003e54902b6\u003c/code\u003e\u003c/a\u003e Fixed addLocalFolderPromise hanging on empty folders and swallowing errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cthackers/adm-zip/commit/73131bdce50fa6ed201c48b468082ef456894f2e\"\u003e\u003ccode\u003e73131bd\u003c/code\u003e\u003c/a\u003e Fixed CI\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cthackers/adm-zip/commit/758898d71508e8a016691d5843b5f7ce2d1b208a\"\u003e\u003ccode\u003e758898d\u003c/code\u003e\u003c/a\u003e Rejected zip entries whose declared data extent runs past the buffer\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cthackers/adm-zip/commit/74b6e9f402c4c7cde4e33f3c87ff8f15ddcd6121\"\u003e\u003ccode\u003e74b6e9f\u003c/code\u003e\u003c/a\u003e Routed malformed-header parse errors through the async callback\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cthackers/adm-zip/commit/eaa35fa73df6108a3d6ebc9b9073371740735265\"\u003e\u003ccode\u003eeaa35fa\u003c/code\u003e\u003c/a\u003e Blocked extraction from writing through symlinks inside the target\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cthackers/adm-zip/commit/1e015e3e713aee426bf3d5c1bc1b555c90f4f3e6\"\u003e\u003ccode\u003e1e015e3\u003c/code\u003e\u003c/a\u003e Increment version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cthackers/adm-zip/commit/05101d47b3b983b705cc3e66fc34366118ba7b99\"\u003e\u003ccode\u003e05101d4\u003c/code\u003e\u003c/a\u003e Rejected archives with duplicate entry names\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cthackers/adm-zip/commit/491600683dacb6cb9fe0718a0eeb9cb5eb49afa6\"\u003e\u003ccode\u003e4916006\u003c/code\u003e\u003c/a\u003e Enforced the decompression size cap on the async path and for size 0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cthackers/adm-zip/commit/6a63c339b83c52915483efacda517660a7a7bf87\"\u003e\u003ccode\u003e6a63c33\u003c/code\u003e\u003c/a\u003e Stripped setuid/setgid/sticky bits from extracted file permissions\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/cthackers/adm-zip/compare/v0.5.18...v0.6.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-uri` from 3.1.5 to 3.1.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss-selector-parser` from 6.1.2 to 6.1.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss-selector-parser/releases\"\u003epostcss-selector-parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e6.1.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: tolerate non-node children when serializing selectors\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e6.1.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://github.com/advisories/GHSA-w9m9-85wc-3x92\"\u003eCVE-2026-9358\u003c/a\u003e (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 via backport of (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/pull/316\"\u003e#316\u003c/a\u003e by \u003ca href=\"https://github.com/MoOx\"\u003e\u003ccode\u003e@​MoOx\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md\"\u003epostcss-selector-parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog of \u003ccode\u003epostcss-selector-parser\u003c/code\u003e\u003c/h1\u003e\n\u003ch2\u003e7.1.6 - 2026-09-03\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: parse flat selectors in linear time, closing a CPU exhaustion vulnerability (\u003ca href=\"https://github.com/advisories/GHSA-rj75-hqrm-r3gf\"\u003eGHSA-rj75-hqrm-r3gf\u003c/a\u003e, reported by Wayde Shi)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.5 - 2026-08-07\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: don't treat a non-prefix token before \u003ccode\u003e|\u003c/code\u003e as a namespace (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/pull/324\"\u003e#324\u003c/a\u003e by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix: preserve whitespace before a \u003ccode\u003e*\u003c/code\u003e namespace in attribute selectors (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/pull/325\"\u003e#325\u003c/a\u003e by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix: TypeError on unclosed \u003ccode\u003e[\u003c/code\u003e, \u003ccode\u003e(\u003c/code\u003e and trailing \u003ccode\u003e|\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/pull/330\"\u003e#330\u003c/a\u003e by \u003ca href=\"https://github.com/theRizwan\"\u003e\u003ccode\u003e@​theRizwan\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.4 - 2026-06-11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: tolerate non-node children when serializing selectors\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.3 - 2026-06-11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (clone/walk)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.2 - 2026-06-09\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://github.com/advisories/GHSA-w9m9-85wc-3x92\"\u003eCVE-2026-9358\u003c/a\u003e (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/pull/316\"\u003e#316\u003c/a\u003e by \u003ca href=\"https://github.com/MoOx\"\u003e\u003ccode\u003e@​MoOx\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eperf: replace startsWith with strict equality (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/issues/308\"\u003e#308\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(types): add walkUniversal declaration (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/issues/311\"\u003e#311\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: insert(Before|After) support multiple new node\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFeat: make insertions during iteration safe (major)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/4a7e4e3685db8ab8e52e51ecdbe8162a8568f70c\"\u003e\u003ccode\u003e4a7e4e3\u003c/code\u003e\u003c/a\u003e 7.1.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/e2021c523d5ef1bf27836aef3bd724a28ba7894f\"\u003e\u003ccode\u003ee2021c5\u003c/code\u003e\u003c/a\u003e fix: tolerate non-node children when serializing selectors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/7893b741fa87d0401e39c3a7f00d89cf7408ad32\"\u003e\u003ccode\u003e7893b74\u003c/code\u003e\u003c/a\u003e 7.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/5bc698cef66f8abd12610dc623e5d67cbc0f869d\"\u003e\u003ccode\u003e5bc698c\u003c/code\u003e\u003c/a\u003e Improve fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (clo...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/db3232710d7270b34e50b4ffae493ac19204f570\"\u003e\u003ccode\u003edb32327\u003c/code\u003e\u003c/a\u003e run oxfmt\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/16e2581b40894504cf2b979fc0ebf7d0b2f39366\"\u003e\u003ccode\u003e16e2581\u003c/code\u003e\u003c/a\u003e simplify deps (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/issues/319\"\u003e#319\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/b185e2057871669f9c571ad82e4350799e0a2329\"\u003e\u003ccode\u003eb185e20\u003c/code\u003e\u003c/a\u003e Add description in package.json + full repo url\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/de415f19aac008f0e731590222f3a963193be05c\"\u003e\u003ccode\u003ede415f1\u003c/code\u003e\u003c/a\u003e Add Tidelift security notice\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/c4f2c8c04a8107e4e401f257ef00592b59633774\"\u003e\u003ccode\u003ec4f2c8c\u003c/code\u003e\u003c/a\u003e CI: make Node 14 test job lockfile-v3 compatible (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/issues/318\"\u003e#318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/4e93663bfe861f9fc3173db603c8fadb70f8090a\"\u003e\u003ccode\u003e4e93663\u003c/code\u003e\u003c/a\u003e Fix test run on node \u0026lt; 20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss-selector-parser/compare/v6.1.2...6.1.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~moox\"\u003emoox\u003c/a\u003e, a new releaser for postcss-selector-parser since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss-selector-parser` from 7.1.1 to 7.1.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss-selector-parser/releases\"\u003epostcss-selector-parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e6.1.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: tolerate non-node children when serializing selectors\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e6.1.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://github.com/advisories/GHSA-w9m9-85wc-3x92\"\u003eCVE-2026-9358\u003c/a\u003e (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 via backport of (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/pull/316\"\u003e#316\u003c/a\u003e by \u003ca href=\"https://github.com/MoOx\"\u003e\u003ccode\u003e@​MoOx\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md\"\u003epostcss-selector-parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog of \u003ccode\u003epostcss-selector-parser\u003c/code\u003e\u003c/h1\u003e\n\u003ch2\u003e7.1.6 - 2026-09-03\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: parse flat selectors in linear time, closing a CPU exhaustion vulnerability (\u003ca href=\"https://github.com/advisories/GHSA-rj75-hqrm-r3gf\"\u003eGHSA-rj75-hqrm-r3gf\u003c/a\u003e, reported by Wayde Shi)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.5 - 2026-08-07\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: don't treat a non-prefix token before \u003ccode\u003e|\u003c/code\u003e as a namespace (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/pull/324\"\u003e#324\u003c/a\u003e by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix: preserve whitespace before a \u003ccode\u003e*\u003c/code\u003e namespace in attribute selectors (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/pull/325\"\u003e#325\u003c/a\u003e by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix: TypeError on unclosed \u003ccode\u003e[\u003c/code\u003e, \u003ccode\u003e(\u003c/code\u003e and trailing \u003ccode\u003e|\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/pull/330\"\u003e#330\u003c/a\u003e by \u003ca href=\"https://github.com/theRizwan\"\u003e\u003ccode\u003e@​theRizwan\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.4 - 2026-06-11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: tolerate non-node children when serializing selectors\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.3 - 2026-06-11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (clone/walk)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.2 - 2026-06-09\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://github.com/advisories/GHSA-w9m9-85wc-3x92\"\u003eCVE-2026-9358\u003c/a\u003e (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/pull/316\"\u003e#316\u003c/a\u003e by \u003ca href=\"https://github.com/MoOx\"\u003e\u003ccode\u003e@​MoOx\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eperf: replace startsWith with strict equality (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/issues/308\"\u003e#308\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(types): add walkUniversal declaration (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/issues/311\"\u003e#311\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: insert(Before|After) support multiple new node\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFeat: make insertions during iteration safe (major)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/4a7e4e3685db8ab8e52e51ecdbe8162a8568f70c\"\u003e\u003ccode\u003e4a7e4e3\u003c/code\u003e\u003c/a\u003e 7.1.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/e2021c523d5ef1bf27836aef3bd724a28ba7894f\"\u003e\u003ccode\u003ee2021c5\u003c/code\u003e\u003c/a\u003e fix: tolerate non-node children when serializing selectors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/7893b741fa87d0401e39c3a7f00d89cf7408ad32\"\u003e\u003ccode\u003e7893b74\u003c/code\u003e\u003c/a\u003e 7.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/5bc698cef66f8abd12610dc623e5d67cbc0f869d\"\u003e\u003ccode\u003e5bc698c\u003c/code\u003e\u003c/a\u003e Improve fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (clo...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/db3232710d7270b34e50b4ffae493ac19204f570\"\u003e\u003ccode\u003edb32327\u003c/code\u003e\u003c/a\u003e run oxfmt\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/16e2581b40894504cf2b979fc0ebf7d0b2f39366\"\u003e\u003ccode\u003e16e2581\u003c/code\u003e\u003c/a\u003e simplify deps (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/issues/319\"\u003e#319\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/b185e2057871669f9c571ad82e4350799e0a2329\"\u003e\u003ccode\u003eb185e20\u003c/code\u003e\u003c/a\u003e Add description in package.json + full repo url\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/de415f19aac008f0e731590222f3a963193be05c\"\u003e\u003ccode\u003ede415f1\u003c/code\u003e\u003c/a\u003e Add Tidelift security notice\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/c4f2c8c04a8107e4e401f257ef00592b59633774\"\u003e\u003ccode\u003ec4f2c8c\u003c/code\u003e\u003c/a\u003e CI: make Node 14 test job lockfile-v3 compatible (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/issues/318\"\u003e#318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/4e93663bfe861f9fc3173db603c8fadb70f8090a\"\u003e\u003ccode\u003e4e93663\u003c/code\u003e\u003c/a\u003e Fix test run on node \u0026lt; 20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss-selector-parser/compare/v6.1.2...6.1.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~moox\"\u003emoox\u003c/a\u003e, a new releaser for postcss-selector-parser since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `svgo` from 3.3.4 to 3.3.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/svg/svgo/releases\"\u003esvgo's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.3.5\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBackport the \u003ccode\u003eremoveScriptElement\u003c/code\u003e hardening from SVGO v4 in \u003ca href=\"https://redirect.github.com/svg/svgo/issues/2269\"\u003e#2269\u003c/a\u003e:\n\u003cul\u003e\n\u003cli\u003ereject executable \u003ccode\u003edata:\u003c/code\u003e URLs and legacy \u003ccode\u003evbscript:\u003c/code\u003e URLs\u003c/li\u003e\n\u003cli\u003esanitize executable HTML inside \u003ccode\u003e\u0026lt;foreignObject\u0026gt;\u003c/code\u003e elements\u003c/li\u003e\n\u003cli\u003ehandle namespace-prefixed SVG anchors and URL schemes containing ASCII tabs or newlines\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThis addresses \u003ca href=\"https://github.com/svg/svgo/security/advisories/GHSA-4vpr-x523-8j87\"\u003eGHSA-4vpr-x523-8j87\u003c/a\u003e and \u003ca href=\"https://github.com/svg/svgo/security/advisories/GHSA-w27v-7q3p-w38r\"\u003eGHSA-w27v-7q3p-w38r\u003c/a\u003e for the v3 release line.\u003c/p\u003e\n\u003ch2\u003eSupport\u003c/h2\u003e\n\u003cp\u003eSVGO v3 is not officially supported; please consider upgrading to SVGO v4. This security fix has been backported, but there is no commitment to backport more complex changes in the future.\u003c/p\u003e\n\u003cp\u003eSee the \u003ca href=\"https://svgo.dev/docs/migrations/migration-from-v3-to-v4/\"\u003emigration guide from v3 to v4\u003c/a\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/svg/svgo/commit/438059032950dde2c2d36ce45f912085947e60d0\"\u003e\u003ccode\u003e4380590\u003c/code\u003e\u003c/a\u003e ci: configure v3 publish tag in package metadata (\u003ca href=\"https://redirect.github.com/svg/svgo/issues/2271\"\u003e#2271\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/svg/svgo/commit/4c84fe7ef022f05350404a469ca66321e0afcb47\"\u003e\u003ccode\u003e4c84fe7\u003c/code\u003e\u003c/a\u003e ci: publish v3 with npm trusted publishing (\u003ca href=\"https://redirect.github.com/svg/svgo/issues/2270\"\u003e#2270\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/svg/svgo/commit/994a9f00d79ddec68ce19a1ce9eb8ca08d747e4f\"\u003e\u003ccode\u003e994a9f0\u003c/code\u003e\u003c/a\u003e fix(removeScriptElement): backport security hardening to v3 (\u003ca href=\"https://redirect.github.com/svg/svgo/issues/2269\"\u003e#2269\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/svg/svgo/compare/v3.3.4...v3.3.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for svgo since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `js-yaml` from 4.3.0 to 4.3.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md\"\u003ejs-yaml's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.15.2 - 2026-08-26\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Hard-limit merge sequence size to 100.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Count empty mappings in merge sequences toward \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e\nto limit CPU usage, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/797\"\u003e#797\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/5c45bd6e960603c13644f5cc8b572ca257723b36\"\u003e\u003ccode\u003e5c45bd6\u003c/code\u003e\u003c/a\u003e 3.15.2 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/5a708f9f4f22e78b87ebe363848cfa4fa4818c0d\"\u003e\u003ccode\u003e5a708f9\u003c/code\u003e\u003c/a\u003e dist rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/3485bc06ff8a0251505f44a00414d90df2466639\"\u003e\u003ccode\u003e3485bc0\u003c/code\u003e\u003c/a\u003e Backport merge limits from v5.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/f34812f1cea794f8c21e0a4e1f3a2584b720f305\"\u003e\u003ccode\u003ef34812f\u003c/code\u003e\u003c/a\u003e Update .gitignore\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodeca/js-yaml/compare/3.15.1...3.15.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `svgo` from 4.0.2 to 4.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/svg/svgo/releases\"\u003esvgo's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.3.5\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBackport the \u003ccode\u003eremoveScriptElement\u003c/code\u003e hardening from SVGO v4 in \u003ca href=\"https://redirect.github.com/svg/svgo/issues/2269\"\u003e#2269\u003c/a\u003e:\n\u003cul\u003e\n\u003cli\u003ereject executable \u003ccode\u003edata:\u003c/code\u003e URLs and legacy \u003ccode\u003evbscript:\u003c/code\u003e URLs\u003c/li\u003e\n\u003cli\u003esanitize executable HTML inside \u003ccode\u003e\u0026lt;foreignObject\u0026gt;\u003c/code\u003e elements\u003c/li\u003e\n\u003cli\u003ehandle namespace-prefixed SVG anchors and URL schemes containing ASCII tabs or newlines\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThis addresses \u003ca href=\"https://github.com/svg/svgo/security/advisories/GHSA-4vpr-x523-8j87\"\u003eGHSA-4vpr-x523-8j87\u003c/a\u003e and \u003ca href=\"https://github.com/svg/svgo/security/advisories/GHSA-w27v-7q3p-w38r\"\u003eGHSA-w27v-7q3p-w38r\u003c/a\u003e for the v3 release line.\u003c/p\u003e\n\u003ch2\u003eSupport\u003c/h2\u003e\n\u003cp\u003eSVGO v3 is not officially supported; please consider upgrading to SVGO v4. This security fix has been backported, but there is no commitment to backport more complex changes in the future.\u003c/p\u003e\n\u003cp\u003eSee the \u003ca href=\"https://svgo.dev/docs/migrations/migration-from-v3-to-v4/\"\u003emigration guide from v3 to v4\u003c/a\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/svg/svgo/commit/438059032950dde2c2d36ce45f912085947e60d0\"\u003e\u003ccode\u003e4380590\u003c/code\u003e\u003c/a\u003e ci: configure v3 publish tag in package metadata (\u003ca href=\"https://redirect.github.com/svg/svgo/issues/2271\"\u003e#2271\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/svg/svgo/commit/4c84fe7ef022f05350404a469ca66321e0afcb47\"\u003e\u003ccode\u003e4c84fe7\u003c/code\u003e\u003c/a\u003e ci: publish v3 with npm trusted publishing (\u003ca href=\"https://redirect.github.com/svg/svgo/issues/2270\"\u003e#2270\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/svg/svgo/commit/994a9f00d79ddec68ce19a1ce9eb8ca08d747e4f\"\u003e\u003ccode\u003e994a9f0\u003c/code\u003e\u003c/a\u003e fix(removeScriptElement): backport security hardening to v3 (\u003ca href=\"https://redirect.github.com/svg/svgo/issues/2269\"\u003e#2269\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/svg/svgo/compare/v3.3.4...v3.3.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for svgo since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `astro` from 7.2.4 to 7.3.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/withastro/astro/releases\"\u003eastro's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eastro@7.3.2\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17896\"\u003e#17896\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/a548223607b9bb146d5d90ddda495343f9a2a739\"\u003e\u003ccode\u003ea548223\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e/\u003ccode\u003e\u0026lt;style\u0026gt;\u003c/code\u003e rendering in MDX so that only literal content (including content injected by remark/rehype plugins) is treated as trusted markup. A dynamic value passed as a \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e/\u003ccode\u003e\u0026lt;style\u0026gt;\u003c/code\u003e child (e.g. \u003ccode\u003e\u0026lt;script\u0026gt;{value}\u0026lt;/script\u0026gt;\u003c/code\u003e) is now escaped like any other element's content instead of being rendered raw. Use \u003ccode\u003eset:html\u003c/code\u003e to explicitly opt a dynamic value back into raw rendering.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17931\"\u003e#17931\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/c1a6a89efa577b8388f04c4b42d655913bb4b886\"\u003e\u003ccode\u003ec1a6a89\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes the dev toolbar returning a 504 \u0026quot;Outdated Optimize Dep\u0026quot; error when a workspace-linked package imports a dependency that Vite's initial scan did not discover\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17908\"\u003e#17908\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/42e9188c4ba7360e5ab8ea4cd7f13d6abcf31879\"\u003e\u003ccode\u003e42e9188\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes i18n fallback routing replacing the first substring match instead of the actual locale segment, which mangled paths like \u003ccode\u003e/energy/en/about\u003c/code\u003e into \u003ccode\u003e/esergy/en/about\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17936\"\u003e#17936\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/4b92ddc6ab0795ac78c30aedfe43b081dcf5b6b0\"\u003e\u003ccode\u003e4b92ddc\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes sessions breaking in dev mode with the Cloudflare adapter when middleware is present\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated dependencies [\u003ca href=\"https://github.com/withastro/astro/commit/a548223607b9bb146d5d90ddda495343f9a2a739\"\u003e\u003ccode\u003ea548223\u003c/code\u003e\u003c/a\u003e]:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​astrojs/markdown-satteri\u003c/code\u003e\u003ca href=\"https://github.com/0\"\u003e\u003ccode\u003e@​0\u003c/code\u003e\u003c/a\u003e.4.1\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eastro@7.3.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17899\"\u003e#17899\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/03896405717471f7d6ff54986ed6beaec0cac94f\"\u003e\u003ccode\u003e0389640\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ematipico\"\u003e\u003ccode\u003e@​ematipico\u003c/code\u003e\u003c/a\u003e! - Fixes an error that prevented projects using \u003ccode\u003eastro:assets\u003c/code\u003e from starting or building\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eastro@7.3.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17767\"\u003e#17767\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/ce7c91f77dbd7be03c04bc13f87af9d01fef6cef\"\u003e\u003ccode\u003ece7c91f\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Adds \u003ccode\u003e--ignore-lock\u003c/code\u003e flag to \u003ccode\u003eastro preview\u003c/code\u003e, allowing multiple preview servers to run simultaneously on different ports. This is useful for E2E testing workflows (e.g., Playwright) that need to run several preview servers at once.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17818\"\u003e#17818\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/c0b65811dfa0dafa1aa04b7d6d67fd09250ff8c1\"\u003e\u003ccode\u003ec0b6581\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/florian-lefebvre\"\u003e\u003ccode\u003e@​florian-lefebvre\u003c/code\u003e\u003c/a\u003e! - Adds a \u003ccode\u003elogger\u003c/code\u003e parameter to image services hooks\u003c/p\u003e\n\u003cp\u003eCustom image services now receive Astro's runtime logger as an extra argument. Messages logged with it are routed through the destination configured in \u003ccode\u003elogger\u003c/code\u003e and respect your log level, instead of being written straight to the console:\u003c/p\u003e\n\u003cpre lang=\"ts\"\u003e\u003ccode\u003eimport type { LocalImageService } from 'astro';\n\u003cp\u003econst service: LocalImageService = {\n// ...\nasync transform(inputBuffer, transform, imageConfig, logger) {\nlogger.warn(\u003ccode\u003eCould not optimize \u0026amp;quot;${transform.src}\u0026amp;quot;. Passing it through unchanged.\u003c/code\u003e);\nreturn { data: inputBuffer, format: 'png' };\n},\n};\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eAstro's built-in Sharp service now uses this logger for the warnings it emits when it encounters an unexpected or unsupported source format.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17818\"\u003e#17818\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/c0b65811dfa0dafa1aa04b7d6d67fd09250ff8c1\"\u003e\u003ccode\u003ec0b6581\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/florian-lefebvre\"\u003e\u003ccode\u003e@​florian-lefebvre\u003c/code\u003e\u003c/a\u003e! - Adds \u003ccode\u003elogger\u003c/code\u003e to the context object passed to cache providers\u003c/p\u003e\n\u003cp\u003eCustom cache providers now receive Astro's runtime logger on the context passed to \u003ccode\u003eonRequest()\u003c/code\u003e. Messages logged with it are routed through the destination configured in \u003ccode\u003elogger\u003c/code\u003e and respect your log level, instead of being written straight to the console:\u003c/p\u003e\n\u003cpre lang=\"ts\"\u003e\u003ccode\u003eimport type { CacheProvider } from 'astro';\n\u003cp\u003econst provider: CacheProvider = {\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md\"\u003eastro's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e7.3.2\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17896\"\u003e#17896\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/a548223607b9bb146d5d90ddda495343f9a2a739\"\u003e\u003ccode\u003ea548223\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e/\u003ccode\u003e\u0026lt;style\u0026gt;\u003c/code\u003e rendering in MDX so that only literal content (including content injected by remark/rehype plugins) is treated as trusted markup. A dynamic value passed as a \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e/\u003ccode\u003e\u0026lt;style\u0026gt;\u003c/code\u003e child (e.g. \u003ccode\u003e\u0026lt;script\u0026gt;{value}\u0026lt;/script\u0026gt;\u003c/code\u003e) is now escaped like any other element's content instead of being rendered raw. Use \u003ccode\u003eset:html\u003c/code\u003e to explicitly opt a dynamic value back into raw rendering.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17931\"\u003e#17931\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/c1a6a89efa577b8388f04c4b42d655913bb4b886\"\u003e\u003ccode\u003ec1a6a89\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes the dev toolbar returning a 504 \u0026quot;Outdated Optimize Dep\u0026quot; error when a workspace-linked package imports a dependency that Vite's initial scan did not discover\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17908\"\u003e#17908\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/42e9188c4ba7360e5ab8ea4cd7f13d6abcf31879\"\u003e\u003ccode\u003e42e9188\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes i18n fallback routing replacing the first substring match instead of the actual locale segment, which mangled paths like \u003ccode\u003e/energy/en/about\u003c/code\u003e into \u003ccode\u003e/esergy/en/about\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17936\"\u003e#17936\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/4b92ddc6ab0795ac78c30aedfe43b081dcf5b6b0\"\u003e\u003ccode\u003e4b92ddc\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes sessions breaking in dev mode with the Cloudflare adapter when middleware is present\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated dependencies [\u003ca href=\"https://github.com/withastro/astro/commit/a548223607b9bb146d5d90ddda495343f9a2a739\"\u003e\u003ccode\u003ea548223\u003c/code\u003e\u003c/a\u003e]:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​astrojs/markdown-satteri\u003c/code\u003e\u003ca href=\"https://github.com/0\"\u003e\u003ccode\u003e@​0\u003c/code\u003e\u003c/a\u003e.4.1\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.3.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17899\"\u003e#17899\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/03896405717471f7d6ff54986ed6beaec0cac94f\"\u003e\u003ccode\u003e0389640\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ematipico\"\u003e\u003ccode\u003e@​ematipico\u003c/code\u003e\u003c/a\u003e! - Fixes an error that prevented projects using \u003ccode\u003eastro:assets\u003c/code\u003e from starting or building\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.3.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17767\"\u003e#17767\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/ce7c91f77dbd7be03c04bc13f87af9d01fef6cef\"\u003e\u003ccode\u003ece7c91f\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Adds \u003ccode\u003e--ignore-lock\u003c/code\u003e flag to \u003ccode\u003eastro preview\u003c/code\u003e, allowing multiple preview servers to run simultaneously on different ports. This is useful for E2E testing workflows (e.g., Playwright) that need to run several preview servers at once.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17818\"\u003e#17818\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/c0b65811dfa0dafa1aa04b7d6d67fd09250ff8c1\"\u003e\u003ccode\u003ec0b6581\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/florian-lefebvre\"\u003e\u003ccode\u003e@​florian-lefebvre\u003c/code\u003e\u003c/a\u003e! - Adds a \u003ccode\u003elogger\u003c/code\u003e parameter to image services hooks\u003c/p\u003e\n\u003cp\u003eCustom image services now receive Astro's runtime logger as an extra argument. Messages logged with it are routed through the destination configured in \u003ccode\u003elogger\u003c/code\u003e and respect your log level, instead of being written straight to the console:\u003c/p\u003e\n\u003cpre lang=\"ts\"\u003e\u003ccode\u003eimport type { LocalImageService } from 'astro';\n\u003cp\u003econst service: LocalImageService = {\n// ...\nasync transform(inputBuffer, transform, imageConfig, logger) {\nlogger.warn(\u003ccode\u003eCould not optimize \u0026amp;quot;${transform.src}\u0026amp;quot;. Passing it through unchanged.\u003c/code\u003e);\nreturn { data: inputBuffer, format: 'png' };\n},\n};\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eAstro's built-in Sharp service now uses this logger for the warnings it emits when it encounters an unexpected or unsupported source format.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17818\"\u003e#17818\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/c0b65811dfa0dafa1aa04b7d6d67fd09250ff8c1\"\u003e\u003ccode\u003ec0b6581\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/florian-lefebvre\"\u003e\u003ccode\u003e@​florian-lefebvre\u003c/code\u003e\u003c/a\u003e! - Adds \u003ccode\u003elogger\u003c/code\u003e to the context object passed to cache providers\u003c/p\u003e\n\u003cp\u003eCustom cache providers now receive Astro's runtime logger on the context passed to \u003ccode\u003eonRequest()\u003c/code\u003e. Messages logged with it are routed through the destination configured in \u003ccode\u003elogger\u003c/code\u003e and respect your log level, instead of being written straight to the console:\u003c/p\u003e\n\u003cpre lang=\"ts\"\u003e\u003ccode\u003e\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/aa4949e425144e0d276d2ff70f01209e90fdfbe8\"\u003e\u003ccode\u003eaa4949e\u003c/code\u003e\u003c/a\u003e [ci] release (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17915\"\u003e#17915\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/42e9188c4ba7360e5ab8ea4cd7f13d6abcf31879\"\u003e\u003ccode\u003e42e9188\u003c/code\u003e\u003c/a\u003e fix(i18n): replace locale segment by index in fallback routing (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17907\"\u003e#17907\u003c/a\u003e) (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17908\"\u003e#17908\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/4b92ddc6ab0795ac78c30aedfe43b081dcf5b6b0\"\u003e\u003ccode\u003e4b92ddc\u003c/code\u003e\u003c/a\u003e Guard setFetchHandler call in non-runnable dev entrypoint to fix sessions + m...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/c1a6a89efa577b8388f04c4b42d655913bb4b886\"\u003e\u003ccode\u003ec1a6a89\u003c/code\u003e\u003c/a\u003e fix: include .astro files in client optimizeDeps entries to prevent 504 on la...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/a548223607b9bb146d5d90ddda495343f9a2a739\"\u003e\u003ccode\u003ea548223\u003c/code\u003e\u003c/a\u003e Only treat literal script/style content as raw in MDX rendering (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17896\"\u003e#17896\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/92f23cc121d3a1a03c6fb901a519309662b333de\"\u003e\u003ccode\u003e92f23cc\u003c/code\u003e\u003c/a\u003e [ci] release (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17900\"\u003e#17900\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/03896405717471f7d6ff54986ed6beaec0cac94f\"\u003e\u003ccode\u003e0389640\u003c/code\u003e\u003c/a\u003e fix: dont use internal paths (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17899\"\u003e#17899\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/f800de13ffab9542f8d1bd13a8f4481c5f5c083a\"\u003e\u003ccode\u003ef800de1\u003c/code\u003e\u003c/a\u003e [ci] release (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17881\"\u003e#17881\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/1e0b7e6023128ad25a79ac125f6d33e5936a3def\"\u003e\u003ccode\u003e1e0b7e6\u003c/code\u003e\u003c/a\u003e [ci] format\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/4671a5c2d215545d8d7f763381ec1084dce9b7d1\"\u003e\u003ccode\u003e4671a5c\u003c/code\u003e\u003c/a\u003e chore(deps): update react to v19 in \u003ccode\u003e0-css\u003c/code\u003e fixture (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17888\"\u003e#17888\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/withastro/astro/commits/astro@7.3.2/packages/astro\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `sharp` from 0.35.3 to 0.35.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lovell/sharp/releases\"\u003esharp's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.35.4\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\"\u003ehttps://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.35.4-rc.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpgrade to libvips v8.18.6 for upstream bug fixes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7f1a0a22cc285fe180766f4935d50b55af6e8432\"\u003e\u003ccode\u003e7f1a0a2\u003c/code\u003e\u003c/a\u003e Release v0.35.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/f927818924bc5a9493d822a4e8b23ec5857c52e1\"\u003e\u003ccode\u003ef927818\u003c/code\u003e\u003c/a\u003e Upgrade to sharp-libvips v1.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e80209240d005c71e1173a50dd9cd4db4ce2a9e6\"\u003e\u003ccode\u003ee802092\u003c/code\u003e\u003c/a\u003e Prerelease v0.35.4-rc.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e13eb2f97a0a22f1ef726e8d0cd33f7c56835945\"\u003e\u003ccode\u003ee13eb2f\u003c/code\u003e\u003c/a\u003e CI: Fix wasm32 build (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4589\"\u003e#4589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/a82a0b3d58bc25854ad1e925e6eb0a50725d1489\"\u003e\u003ccode\u003ea82a0b3\u003c/code\u003e\u003c/a\u003e Upgrade to libvips v8.18.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/8044fe43e36d0ea7f8beb89f79a37bb0f3342e84\"\u003e\u003ccode\u003e8044fe4\u003c/code\u003e\u003c/a\u003e Bound resize dimensions to coordinate limit\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/147f8591a153bc4a1e199c3fe3150fac2931b30c\"\u003e\u003ccode\u003e147f859\u003c/code\u003e\u003c/a\u003e Docs: changelog entries for \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4578\"\u003e#4578\u003c/a\u003e \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ee5bfb853de75a611c64381783b04032a3a897d8\"\u003e\u003ccode\u003eee5bfb8\u003c/code\u003e\u003c/a\u003e Tests: use yauzl directly rather than via extract-zip wrapper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7a7788928f8a2a429f45039010a87cee35401694\"\u003e\u003ccode\u003e7a77889\u003c/code\u003e\u003c/a\u003e Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4588\"\u003e#4588\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ea5bef24c187b2c7ee3fe3cad3b45c8cb67a46fd\"\u003e\u003ccode\u003eea5bef2\u003c/code\u003e\u003c/a\u003e Improve support for input Streams finishing before output is requested (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/lovell/sharp/compare/v0.35.3...v0.35.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/courtneyr-dev/post-formats-for-block-themes/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/courtneyr-dev/post-formats-for-block-themes/pull/42","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/courtneyr-dev%2Fpost-formats-for-block-themes/issues/42","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/42/packages"},{"uuid":"5435504881","node_id":"PR_kwDOUYQOzc8AAAABDR2olg","number":11,"state":"closed","title":"Bump fast-uri from 3.1.2 to 3.1.7 in /site","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-12T22:33:54.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-12T19:23:44.000Z","updated_at":"2026-09-12T22:33:56.000Z","time_to_close":11410,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"fast-uri","old_version":"3.1.2","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"}],"path":"/site","ecosystem":"npm"},"body":"Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.2 to 3.1.7.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=fast-uri\u0026package-manager=npm_and_yarn\u0026previous-version=3.1.2\u0026new-version=3.1.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/sridharrajarao-site/gridrudder/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/sridharrajarao-site/gridrudder/pull/11","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/sridharrajarao-site%2Fgridrudder/issues/11","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/11/packages"},{"uuid":"5434890359","node_id":"PR_kwDOTio6sM8AAAABDRYj8w","number":31,"state":"closed","title":"chore(deps): bump fast-uri from 3.1.5 to 3.1.7 in /frontend","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":"2026-09-13T09:32:21.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-12T17:24:16.000Z","updated_at":"2026-09-13T09:32:28.000Z","time_to_close":58085,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"fast-uri","old_version":"3.1.5","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"}],"path":"/frontend","ecosystem":"npm"},"body":"Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.5 to 3.1.7.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=fast-uri\u0026package-manager=npm_and_yarn\u0026previous-version=3.1.5\u0026new-version=3.1.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/KahMeng15/hellomyphotos/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/KahMeng15/hellomyphotos/pull/31","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/KahMeng15%2Fhellomyphotos/issues/31","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/31/packages"},{"uuid":"5433614534","node_id":"PR_kwDOUSRYj88AAAABDQZfUw","number":12,"state":"open","title":"chore: bump fast-uri from 3.1.5 to 3.1.7","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-12T13:38:25.000Z","updated_at":"2026-09-12T13:38:41.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore","packages":[{"name":"fast-uri","old_version":"3.1.5","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"}],"path":null,"ecosystem":"npm"},"body":"Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.5 to 3.1.7.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=fast-uri\u0026package-manager=npm_and_yarn\u0026previous-version=3.1.5\u0026new-version=3.1.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/coreone-io/coretalk/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/coreone-io/coretalk/pull/12","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/coreone-io%2Fcoretalk/issues/12","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/12/packages"},{"uuid":"5432757500","node_id":"PR_kwDOTLRUms8AAAABDPxCNw","number":154,"state":"open","title":"chore(deps): bump fast-uri from 3.1.3 to 3.1.7","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-12T10:32:37.000Z","updated_at":"2026-09-12T10:32:58.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"fast-uri","old_version":"3.1.3","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"}],"path":null,"ecosystem":"npm"},"body":"Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.3 to 3.1.7.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=fast-uri\u0026package-manager=npm_and_yarn\u0026previous-version=3.1.3\u0026new-version=3.1.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/rubicon/forgejo-mcp/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/rubicon/forgejo-mcp/pull/154","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/rubicon%2Fforgejo-mcp/issues/154","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/154/packages"},{"uuid":"5432533456","node_id":"PR_kwDORz5mi88AAAABDPmMJw","number":27,"state":"open","title":"chore(deps): bump the npm_and_yarn group across 1 directory with 10 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-12T09:44:06.000Z","updated_at":"2026-09-12T09:44:21.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":10,"packages":[{"name":"ws","old_version":"6.2.3","new_version":"6.2.6","repository_url":"https://github.com/websockets/ws"},{"name":"@babel/core","old_version":"7.29.0","new_version":"7.29.7","repository_url":"https://github.com/babel/babel"},{"name":"brace-expansion","old_version":"1.1.13","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"@humanfs/node","old_version":"0.16.7","new_version":"0.16.8","repository_url":"https://github.com/humanwhocodes/humanfs"},{"name":"js-yaml","old_version":"3.14.2","new_version":"3.15.2","repository_url":"https://github.com/nodeca/js-yaml"},{"name":"@xmldom/xmldom","old_version":"0.8.11","new_version":"0.8.15","repository_url":"https://github.com/xmldom/xmldom"},{"name":"fast-uri","old_version":"3.1.0","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"nanoid","old_version":"3.3.11","new_version":"3.3.19","repository_url":"https://github.com/ai/nanoid"},{"name":"postcss","old_version":"8.4.49","new_version":"8.5.28","repository_url":"https://github.com/postcss/postcss"},{"name":"shell-quote","old_version":"1.8.3","new_version":"1.10.0","repository_url":"https://github.com/ljharb/shell-quote"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 10 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [ws](https://github.com/websockets/ws) | `6.2.3` | `6.2.6` |\n| [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) | `7.29.0` | `7.29.7` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.13` | `1.1.18` |\n| [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node) | `0.16.7` | `0.16.8` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `3.14.2` | `3.15.2` |\n| [@xmldom/xmldom](https://github.com/xmldom/xmldom) | `0.8.11` | `0.8.15` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.0` | `3.1.7` |\n| [nanoid](https://github.com/ai/nanoid) | `3.3.11` | `3.3.19` |\n| [postcss](https://github.com/postcss/postcss) | `8.4.49` | `8.5.28` |\n| [shell-quote](https://github.com/ljharb/shell-quote) | `1.8.3` | `1.10.0` |\n\n\nUpdates `ws` from 6.2.3 to 6.2.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/websockets/ws/releases\"\u003ews's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e6.2.6\u003c/h2\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug introduced in version 6.2.5 that prevented the fragment counter\nfrom resetting (899bf9e5).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e6.2.5\u003c/h2\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eBackported a2f4e7c0 and f197ac65 to the v6.x release line (58ddc8c3, 4f19c0cd).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e6.2.4\u003c/h2\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eBackported 2b2abd45 to the 6.x release line (a76e2111).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/dd3ae14c767e1fc7446439a6853bec43f2a3d8bc\"\u003e\u003ccode\u003edd3ae14\u003c/code\u003e\u003c/a\u003e [dist] 6.2.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/899bf9e56fcfc6da108dbbec08d4940349c8e9fd\"\u003e\u003ccode\u003e899bf9e\u003c/code\u003e\u003c/a\u003e [fix] Reset the fragment counter when the message is complete\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/1a0afaf201c10f374a8ed375c986efa2ff93efc5\"\u003e\u003ccode\u003e1a0afaf\u003c/code\u003e\u003c/a\u003e [dist] 6.2.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/4f19c0cd9e7dce6b345ae425363353ef7abadf17\"\u003e\u003ccode\u003e4f19c0c\u003c/code\u003e\u003c/a\u003e [fix] Lower default values of \u003ccode\u003emaxBufferedChunks\u003c/code\u003e and \u003ccode\u003emaxFragments\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/58ddc8c3f7c9531c0c7c0293d1b4f742a72e1121\"\u003e\u003ccode\u003e58ddc8c\u003c/code\u003e\u003c/a\u003e [fix] Count empty fragments toward the limit (\u003ca href=\"https://redirect.github.com/websockets/ws/issues/2329\"\u003e#2329\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/86d3e8a5fb0246ed373860c5fbb0de88824a27f7\"\u003e\u003ccode\u003e86d3e8a\u003c/code\u003e\u003c/a\u003e [dist] 6.2.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/a76e2111c91d7e031c00148a73db90db059bf989\"\u003e\u003ccode\u003ea76e211\u003c/code\u003e\u003c/a\u003e [security] Limit retained message parts\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/websockets/ws/compare/6.2.3...6.2.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@babel/core` from 7.29.0 to 7.29.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/babel/babel/releases\"\u003e@​babel/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.7 (2026-05-25)\u003c/h2\u003e\n\u003cp\u003eRe-release all packages with npm provenance attestations\u003c/p\u003e\n\u003ch2\u003ev7.29.6 (2026-05-25)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18014\"\u003e#18014\u003c/a\u003e Catchup source map position in preserveFormat (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18001\"\u003e#18001\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e, \u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17998\"\u003e#17998\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 3\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMateusz Burzyński (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.5 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:house:  Internal\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@babel/*\u003c/code\u003e dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.4 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17974\"\u003e#17974\u003c/a\u003e [7.x backport]fix(systemjs): improve module string name support (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 1\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.3 (2026-04-30)\u003c/h2\u003e\n\u003ch4\u003e:eyeglasses: Spec Compliance\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17923\"\u003e#17923\u003c/a\u003e Support flow extends bound (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-helper-create-class-features-plugin\u003c/code\u003e, \u003ccode\u003ebabel-plugin-proposal-decorators\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17931\"\u003e#17931\u003c/a\u003e fix(decorators): replace super within all removed static elements (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-register\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17915\"\u003e#17915\u003c/a\u003e Fix thread synchronization issues in \u003ccode\u003e@babel/register\u003c/code\u003e (\u003ca href=\"https://github.com/liuxingbaoyu\"\u003e\u003ccode\u003e@​liuxingbaoyu\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-compat-data\u003c/code\u003e, \u003ccode\u003ebabel-plugin-bugfix-safari-rest-destructuring-rhs-array\u003c/code\u003e, \u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17788\"\u003e#17788\u003c/a\u003e Add bugfix plugin for Safari array rest destructuring bug (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:nail_care: Polish\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/4fba7541180bf5f58256d8e358b544e3831ad090\"\u003e\u003ccode\u003e4fba754\u003c/code\u003e\u003c/a\u003e v7.29.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/04ea6b27fdac8f40c3481aec2080ac9678779509\"\u003e\u003ccode\u003e04ea6b2\u003c/code\u003e\u003c/a\u003e v7.29.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/99f498a9b9fa0b900d603fbe8f6601bb3b9e42bb\"\u003e\u003ccode\u003e99f498a\u003c/code\u003e\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/18001\"\u003e#18001\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/feba0a3654c596bd369d1ef1231f5d56666d56dc\"\u003e\u003ccode\u003efeba0a3\u003c/code\u003e\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17998\"\u003e#17998\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/babel/babel/commits/v7.29.7/packages/babel-core\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.13 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24\"\u003e\u003ccode\u003e2203f4f\u003c/code\u003e\u003c/a\u003e 1.1.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd\"\u003e\u003ccode\u003e0b09384\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/10c05fcf3699b1a29ef5e611c011af3d3c97e6e3\"\u003e\u003ccode\u003e10c05fc\u003c/code\u003e\u003c/a\u003e 1.1.14\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.13...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@humanfs/node` from 0.16.7 to 0.16.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/humanwhocodes/humanfs/releases\"\u003e@​humanfs/node's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003enode: v0.16.8\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/compare/node-v0.16.7...node-v0.16.8\"\u003e0.16.8\u003c/a\u003e (2026-04-17)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eInclude type dependencies at runtime (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e956ce7a\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/humanwhocodes/humanfs/issues/145\"\u003e#145\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe following workspace dependencies were updated\n\u003cul\u003e\n\u003cli\u003edependencies\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​humanfs/core\u003c/code\u003e bumped from ^0.19.1 to ^0.19.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/humanwhocodes/humanfs/blob/main/packages/node/CHANGELOG.md\"\u003e@​humanfs/node's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/compare/node-v0.16.7...node-v0.16.8\"\u003e0.16.8\u003c/a\u003e (2026-04-17)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEnsure symlinks are copied as symlinks in \u003ccode\u003ecopy()\u003c/code\u003e and \u003ccode\u003ecopyAll()\u003c/code\u003e (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/22bbaa4487a3e6c1197ca619840de4615d0c3404\"\u003e22bbaa44\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eInclude type dependencies at runtime (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e956ce7a\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/humanwhocodes/humanfs/issues/145\"\u003e#145\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe following workspace dependencies were updated\n\u003cul\u003e\n\u003cli\u003edependencies\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​humanfs/core\u003c/code\u003e bumped from ^0.19.1 to ^0.19.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/e96070e897f017ae8abd2b0676d98d14e49665cc\"\u003e\u003ccode\u003ee96070e\u003c/code\u003e\u003c/a\u003e chore: release main (\u003ca href=\"https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node/issues/146\"\u003e#146\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/22bbaa4487a3e6c1197ca619840de4615d0c3404\"\u003e\u003ccode\u003e22bbaa4\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e\u003ccode\u003e956ce7a\u003c/code\u003e\u003c/a\u003e fix: Include type dependencies at runtime\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/humanwhocodes/humanfs/commits/node-v0.16.8/packages/node\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `js-yaml` from 3.14.2 to 3.15.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md\"\u003ejs-yaml's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.15.2 - 2026-08-26\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Hard-limit merge sequence size to 100.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Count empty mappings in merge sequences toward \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e\nto limit CPU usage, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/797\"\u003e#797\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.15.1 - 2026-07-31\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Remove quadratic complexity from \u003ccode\u003e!!omap\u003c/code\u003e duplicate key detection.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.15.0 - 2026-06-27\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e (10000) loader option to limit the total number of\nkeys processed by YAML merge (\u003ccode\u003e\u0026lt;\u0026lt;\u003c/code\u003e) across one \u003ccode\u003esafeLoad()\u003c/code\u003e / \u003ccode\u003esafeLoadAll()\u003c/code\u003e\ncall.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/5c45bd6e960603c13644f5cc8b572ca257723b36\"\u003e\u003ccode\u003e5c45bd6\u003c/code\u003e\u003c/a\u003e 3.15.2 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/5a708f9f4f22e78b87ebe363848cfa4fa4818c0d\"\u003e\u003ccode\u003e5a708f9\u003c/code\u003e\u003c/a\u003e dist rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/3485bc06ff8a0251505f44a00414d90df2466639\"\u003e\u003ccode\u003e3485bc0\u003c/code\u003e\u003c/a\u003e Backport merge limits from v5.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/f34812f1cea794f8c21e0a4e1f3a2584b720f305\"\u003e\u003ccode\u003ef34812f\u003c/code\u003e\u003c/a\u003e Update .gitignore\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/ab85ae2c622bc6d8cdbceccafe9f9b7df80463ed\"\u003e\u003ccode\u003eab85ae2\u003c/code\u003e\u003c/a\u003e 3.15.1 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/30a5e7647a4454f7bac969bfbbe7eac9921a4279\"\u003e\u003ccode\u003e30a5e76\u003c/code\u003e\u003c/a\u003e dist rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/22a8071ef032117bc6249c330b240ac3aa2d3ded\"\u003e\u003ccode\u003e22a8071\u003c/code\u003e\u003c/a\u003e Backport quadratic complexity fix for !!omap\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/c34b6c40027a769eb0d67958ae615268a1d55f54\"\u003e\u003ccode\u003ec34b6c4\u003c/code\u003e\u003c/a\u003e 3.15.0 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/21e13d363f33501c7ee6ca988b88c29084999f72\"\u003e\u003ccode\u003e21e13d3\u003c/code\u003e\u003c/a\u003e dist rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/4165c62630d64fe4f25fb0d03139c7e137b24b1c\"\u003e\u003ccode\u003e4165c62\u003c/code\u003e\u003c/a\u003e Add v3-legacy tag for publish\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodeca/js-yaml/compare/3.14.2...3.15.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@xmldom/xmldom` from 0.8.11 to 0.8.15\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/xmldom/xmldom/releases\"\u003e@​xmldom/xmldom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.8.15\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/xmldom/xmldom/compare/0.8.14...0.8.15\"\u003eCommits\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity: parsing a deeply or repeatedly namespaced document no longer consumes quadratic memory; the in-scope namespace map is inherited through the prototype chain instead of being copied for every prefix-declaring element (O(N) instead of O(N²)), preventing a denial-of-service reachable from \u003ccode\u003eDOMParser.parseFromString\u003c/code\u003e with default options. Serialized output is byte-identical. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-965w-775f-mr7g\"\u003e\u003ccode\u003eGHSA-965w-775f-mr7g\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: attribute de-duplication during parsing is now O(M) instead of O(M²); the \u003ccode\u003eNamedNodeMap\u003c/code\u003e parse-time dedup path uses a null-prototype membership index, so a well-formed document with a hostile number of duplicate attributes can no longer wedge the parse. Attribute order and duplicate resolution (last value wins, first position kept) are byte-identical, preserving the XML \u003ca href=\"https://www.w3.org/TR/xml/#uniqattspec\"\u003eno-duplicate-attributes well-formedness constraint\u003c/a\u003e. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-8344-3jmq-59r6\"\u003e\u003ccode\u003eGHSA-8344-3jmq-59r6\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: trimming trailing whitespace from an XML end tag (\u003ca href=\"https://www.w3.org/TR/xml/#NT-ETag\"\u003e\u003ccode\u003eETag\u003c/code\u003e\u003c/a\u003e) is now anchored so it runs in linear time instead of backtracking quadratically on a long whitespace run, preventing a ReDoS reachable from \u003ccode\u003eDOMParser.parseFromString\u003c/code\u003e. Trimmed output is byte-identical. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-x4fp-j954-r2f4\"\u003e\u003ccode\u003eGHSA-x4fp-j954-r2f4\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: malformed-input recovery is now linear instead of quadratic — the malformed tag-name scan terminates at an embedded \u003ccode\u003e\u0026lt;\u003c/code\u003e, and \u003ccode\u003eNode.prototype.normalize()\u003c/code\u003e merges adjacent text nodes in O(K) instead of O(K²) (also reachable programmatically), per \u003ca href=\"https://dom.spec.whatwg.org/#dom-node-normalize\"\u003e\u003ccode\u003enormalize()\u003c/code\u003e\u003c/a\u003e in the WHATWG DOM spec. DOM output is unchanged; only the reported error text differs. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-93r5-fhx6-vmg9\"\u003e\u003ccode\u003eGHSA-93r5-fhx6-vmg9\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: \u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e under \u003ccode\u003e{ requireWellFormed: true }\u003c/code\u003e now rejects a DocType \u003ccode\u003ename\u003c/code\u003e that is not a valid XML \u003ca href=\"https://www.w3.org/TR/xml/#NT-Name\"\u003e\u003ccode\u003eName\u003c/code\u003e\u003c/a\u003e, throwing \u003ccode\u003eInvalidStateError\u003c/code\u003e — matching the sibling \u003ccode\u003epublicId\u003c/code\u003e/\u003ccode\u003esystemId\u003c/code\u003e/\u003ccode\u003einternalSubset\u003c/code\u003e checks and preventing XML injection via \u003ccode\u003eDocumentType.name\u003c/code\u003e. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-27p8-2357-5qqv\"\u003e\u003ccode\u003eGHSA-27p8-2357-5qqv\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: \u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e under \u003ccode\u003e{ requireWellFormed: true }\u003c/code\u003e now validates a processing-instruction target as an XML \u003ca href=\"https://www.w3.org/TR/xml-names/#NT-NCName\"\u003e\u003ccode\u003eNCName\u003c/code\u003e\u003c/a\u003e and rejects a case-insensitive \u003ccode\u003exml\u003c/code\u003e, throwing \u003ccode\u003eInvalidStateError\u003c/code\u003e — a check \u003ccode\u003e0.8.x\u003c/code\u003e did not previously perform, preventing PI-target injection via \u003ccode\u003e\u0026gt;\u003c/code\u003e, \u003ccode\u003e?\u003c/code\u003e, or whitespace. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-c7q8-3ch8-vqpv\"\u003e\u003ccode\u003eGHSA-c7q8-3ch8-vqpv\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: \u003ccode\u003eDocument.createEntityReference()\u003c/code\u003e now rejects an invalid XML \u003ca href=\"https://www.w3.org/TR/xml/#NT-Name\"\u003e\u003ccode\u003eName\u003c/code\u003e\u003c/a\u003e at creation, and \u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e under \u003ccode\u003e{ requireWellFormed: true }\u003c/code\u003e validates an \u003ccode\u003eEntityReference\u003c/code\u003e \u003ccode\u003enodeName\u003c/code\u003e as an XML \u003ccode\u003eName\u003c/code\u003e, throwing \u003ccode\u003eInvalidStateError\u003c/code\u003e — preventing XML injection via an entity-reference name. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-6gmq-8vp8-gcm6\"\u003e\u003ccode\u003eGHSA-6gmq-8vp8-gcm6\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: the parser now reports a not-well-formed end tag whose valid name is followed by trailing content as a recoverable \u003ccode\u003eerror\u003c/code\u003e instead of accepting it silently, per the XML \u003ca href=\"https://www.w3.org/TR/xml/#NT-ETag\"\u003e\u003ccode\u003eETag\u003c/code\u003e\u003c/a\u003e production; parsing recovers to the byte-identical DOM. Consumers that want strict rejection can escalate the reported \u003ccode\u003eerror\u003c/code\u003e to fatal via the parser's \u003ccode\u003eerrorHandler\u003c/code\u003e. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-6h8r-xr42-gp59\"\u003e\u003ccode\u003eGHSA-6h8r-xr42-gp59\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThank you,\n\u003ca href=\"https://github.com/ericchiang\"\u003e\u003ccode\u003e@​ericchiang\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/bhaswanthc\"\u003e\u003ccode\u003e@​bhaswanthc\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/arpitjain099\"\u003e\u003ccode\u003e@​arpitjain099\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/Paranoidgrinch\"\u003e\u003ccode\u003e@​Paranoidgrinch\u003c/code\u003e\u003c/a\u003e,\nfor your contributions\u003c/p\u003e\n\u003ch2\u003e0.8.14\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/xmldom/xmldom/compare/0.8.13...0.8.14\"\u003eCommits\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity: \u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e now also rejects invalid element and attribute names when \u003ccode\u003e{ requireWellFormed: true }\u003c/code\u003e is passed, throwing \u003ccode\u003eInvalidStateError\u003c/code\u003e for a name that is not a valid XML \u003ca href=\"https://www.w3.org/TR/xml-names/#NT-QName\"\u003e\u003ccode\u003eQName\u003c/code\u003e\u003c/a\u003e (this covers the namespace prefix, which surfaces in the element qualified name or in a synthesized \u003ccode\u003exmlns:\u003c/code\u003e declaration). This prevents XML injection via \u003ccode\u003ecreateElement()\u003c/code\u003e / \u003ccode\u003esetAttribute()\u003c/code\u003e, extending the existing \u003ccode\u003erequireWellFormed\u003c/code\u003e checks to the serialized name set. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-w2rr-34g9-rvrj\"\u003e\u003ccode\u003eGHSA-w2rr-34g9-rvrj\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-4w3w-2rp5-g8jm\"\u003e\u003ccode\u003eGHSA-4w3w-2rp5-g8jm\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThank you,\n\u003ca href=\"https://github.com/bhaswanthc\"\u003e\u003ccode\u003e@​bhaswanthc\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/jmestwa-coder\"\u003e\u003ccode\u003e@​jmestwa-coder\u003c/code\u003e\u003c/a\u003e,\nfor your contributions\u003c/p\u003e\n\u003ch2\u003e0.8.13\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/xmldom/xmldom/compare/0.8.12...0.8.13\"\u003eCommits\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity: \u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e (and \u003ccode\u003eNode.toString()\u003c/code\u003e, \u003ccode\u003eNodeList.toString()\u003c/code\u003e) now accept a \u003ccode\u003erequireWellFormed\u003c/code\u003e option (fourth argument, after \u003ccode\u003eisHtml\u003c/code\u003e and \u003ccode\u003enodeFilter\u003c/code\u003e). When \u003ccode\u003e{ requireWellFormed: true }\u003c/code\u003e is passed, the serializer throws \u003ccode\u003eInvalidStateError\u003c/code\u003e for injection-prone node content, preventing XML injection via attacker-controlled node data. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-j759-j44w-7fr8\"\u003e\u003ccode\u003eGHSA-j759-j44w-7fr8\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-x6wf-f3px-wcqx\"\u003e\u003ccode\u003eGHSA-x6wf-f3px-wcqx\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-f6ww-3ggp-fr8h\"\u003e\u003ccode\u003eGHSA-f6ww-3ggp-fr8h\u003c/code\u003e\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003eComment: throws when \u003ccode\u003edata\u003c/code\u003e contains \u003ccode\u003e--\u0026gt;\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eProcessingInstruction: throws when \u003ccode\u003edata\u003c/code\u003e contains \u003ccode\u003e?\u0026gt;\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eDocumentType: throws when \u003ccode\u003epublicId\u003c/code\u003e fails \u003ccode\u003ePubidLiteral\u003c/code\u003e, \u003ccode\u003esystemId\u003c/code\u003e fails \u003ccode\u003eSystemLiteral\u003c/code\u003e, or \u003ccode\u003einternalSubset\u003c/code\u003e contains \u003ccode\u003e]\u0026gt;\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSecurity: DOM traversal operations (\u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e, \u003ccode\u003eNode.prototype.normalize()\u003c/code\u003e, \u003ccode\u003eNode.prototype.cloneNode(true)\u003c/code\u003e, \u003ccode\u003eDocument.prototype.importNode(node, true)\u003c/code\u003e, \u003ccode\u003enode.textContent\u003c/code\u003e getter, \u003ccode\u003egetElementsByTagName()\u003c/code\u003e / \u003ccode\u003egetElementsByTagNameNS()\u003c/code\u003e / \u003ccode\u003egetElementsByClassName()\u003c/code\u003e / \u003ccode\u003egetElementById()\u003c/code\u003e) are now iterative. Previously, deeply nested DOM trees would exhaust the JavaScript call stack and throw an unrecoverable \u003ccode\u003eRangeError\u003c/code\u003e. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-2v35-w6hq-6mfw\"\u003e\u003ccode\u003eGHSA-2v35-w6hq-6mfw\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThank you,\n\u003ca href=\"https://github.com/Jvr2022\"\u003e\u003ccode\u003e@​Jvr2022\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/praveen-kv\"\u003e\u003ccode\u003e@​praveen-kv\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/TharVid\"\u003e\u003ccode\u003e@​TharVid\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/decsecre583\"\u003e\u003ccode\u003e@​decsecre583\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/tlsbollei\"\u003e\u003ccode\u003e@​tlsbollei\u003c/code\u003e\u003c/a\u003e,\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/xmldom/xmldom/blob/master/CHANGELOG.md\"\u003e@​xmldom/xmldom's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/xmldom/xmldom/compare/0.8.14...0.8.15\"\u003e0.8.15\u003c/a\u003e\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity: parsing a deeply or repeatedly namespaced document no longer consumes quadratic memory; the in-scope namespace map is inherited through the prototype chain instead of being copied for every prefix-declaring element (O(N) instead of O(N²)), preventing a denial-of-service reachable from \u003ccode\u003eDOMParser.parseFromString\u003c/code\u003e with default options. Serialized output is byte-identical. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-965w-775f-mr7g\"\u003e\u003ccode\u003eGHSA-965w-775f-mr7g\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: attribute de-duplication during parsing is now O(M) instead of O(M²); the \u003ccode\u003eNamedNodeMap\u003c/code\u003e parse-time dedup path uses a null-prototype membership index, so a well-formed document with a hostile number of duplicate attributes can no longer wedge the parse. Attribute order and duplicate resolution (last value wins, first position kept) are byte-identical, preserving the XML \u003ca href=\"https://www.w3.org/TR/xml/#uniqattspec\"\u003eno-duplicate-attributes well-formedness constraint\u003c/a\u003e. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-8344-3jmq-59r6\"\u003e\u003ccode\u003eGHSA-8344-3jmq-59r6\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: trimming trailing whitespace from an XML end tag (\u003ca href=\"https://www.w3.org/TR/xml/#NT-ETag\"\u003e\u003ccode\u003eETag\u003c/code\u003e\u003c/a\u003e) is now anchored so it runs in linear time instead of backtracking quadratically on a long whitespace run, preventing a ReDoS reachable from \u003ccode\u003eDOMParser.parseFromString\u003c/code\u003e. Trimmed output is byte-identical. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-x4fp-j954-r2f4\"\u003e\u003ccode\u003eGHSA-x4fp-j954-r2f4\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: malformed-input recovery is now linear instead of quadratic — the malformed tag-name scan terminates at an embedded \u003ccode\u003e\u0026lt;\u003c/code\u003e, and \u003ccode\u003eNode.prototype.normalize()\u003c/code\u003e merges adjacent text nodes in O(K) instead of O(K²) (also reachable programmatically), per \u003ca href=\"https://dom.spec.whatwg.org/#dom-node-normalize\"\u003e\u003ccode\u003enormalize()\u003c/code\u003e\u003c/a\u003e in the WHATWG DOM spec. DOM output is unchanged; only the reported error text differs. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-93r5-fhx6-vmg9\"\u003e\u003ccode\u003eGHSA-93r5-fhx6-vmg9\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: \u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e under \u003ccode\u003e{ requireWellFormed: true }\u003c/code\u003e now rejects a DocType \u003ccode\u003ename\u003c/code\u003e that is not a valid XML \u003ca href=\"https://www.w3.org/TR/xml/#NT-Name\"\u003e\u003ccode\u003eName\u003c/code\u003e\u003c/a\u003e, throwing \u003ccode\u003eInvalidStateError\u003c/code\u003e — matching the sibling \u003ccode\u003epublicId\u003c/code\u003e/\u003ccode\u003esystemId\u003c/code\u003e/\u003ccode\u003einternalSubset\u003c/code\u003e checks and preventing XML injection via \u003ccode\u003eDocumentType.name\u003c/code\u003e. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-27p8-2357-5qqv\"\u003e\u003ccode\u003eGHSA-27p8-2357-5qqv\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: \u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e under \u003ccode\u003e{ requireWellFormed: true }\u003c/code\u003e now validates a processing-instruction target as an XML \u003ca href=\"https://www.w3.org/TR/xml-names/#NT-NCName\"\u003e\u003ccode\u003eNCName\u003c/code\u003e\u003c/a\u003e and rejects a case-insensitive \u003ccode\u003exml\u003c/code\u003e, throwing \u003ccode\u003eInvalidStateError\u003c/code\u003e — a check \u003ccode\u003e0.8.x\u003c/code\u003e did not previously perform, preventing PI-target injection via \u003ccode\u003e\u0026gt;\u003c/code\u003e, \u003ccode\u003e?\u003c/code\u003e, or whitespace. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-c7q8-3ch8-vqpv\"\u003e\u003ccode\u003eGHSA-c7q8-3ch8-vqpv\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: \u003ccode\u003eDocument.createEntityReference()\u003c/code\u003e now rejects an invalid XML \u003ca href=\"https://www.w3.org/TR/xml/#NT-Name\"\u003e\u003ccode\u003eName\u003c/code\u003e\u003c/a\u003e at creation, and \u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e under \u003ccode\u003e{ requireWellFormed: true }\u003c/code\u003e validates an \u003ccode\u003eEntityReference\u003c/code\u003e \u003ccode\u003enodeName\u003c/code\u003e as an XML \u003ccode\u003eName\u003c/code\u003e, throwing \u003ccode\u003eInvalidStateError\u003c/code\u003e — preventing XML injection via an entity-reference name. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-6gmq-8vp8-gcm6\"\u003e\u003ccode\u003eGHSA-6gmq-8vp8-gcm6\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: the parser now reports a not-well-formed end tag whose valid name is followed by trailing content as a recoverable \u003ccode\u003eerror\u003c/code\u003e instead of accepting it silently, per the XML \u003ca href=\"https://www.w3.org/TR/xml/#NT-ETag\"\u003e\u003ccode\u003eETag\u003c/code\u003e\u003c/a\u003e production; parsing recovers to the byte-identical DOM. Consumers that want strict rejection can escalate the reported \u003ccode\u003eerror\u003c/code\u003e to fatal via the parser's \u003ccode\u003eerrorHandler\u003c/code\u003e. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-6h8r-xr42-gp59\"\u003e\u003ccode\u003eGHSA-6h8r-xr42-gp59\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThank you,\n\u003ca href=\"https://github.com/ericchiang\"\u003e\u003ccode\u003e@​ericchiang\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/bhaswanthc\"\u003e\u003ccode\u003e@​bhaswanthc\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/arpitjain099\"\u003e\u003ccode\u003e@​arpitjain099\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/Paranoidgrinch\"\u003e\u003ccode\u003e@​Paranoidgrinch\u003c/code\u003e\u003c/a\u003e,\nfor your contributions\u003c/p\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/xmldom/xmldom/compare/0.9.10...0.9.11\"\u003e0.9.11\u003c/a\u003e\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity: \u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e now also rejects invalid element and attribute names when \u003ccode\u003e{ requireWellFormed: true }\u003c/code\u003e is passed, throwing \u003ccode\u003eInvalidStateError\u003c/code\u003e for a name that is not a valid XML \u003ca href=\"https://www.w3.org/TR/xml-names/#NT-QName\"\u003e\u003ccode\u003eQName\u003c/code\u003e\u003c/a\u003e (this covers the namespace prefix, which surfaces in the element qualified name or in a synthesized \u003ccode\u003exmlns:\u003c/code\u003e declaration). This prevents XML injection via \u003ccode\u003ecreateElement()\u003c/code\u003e / \u003ccode\u003esetAttribute()\u003c/code\u003e, extending the existing \u003ccode\u003erequireWellFormed\u003c/code\u003e checks to the serialized name set. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-w2rr-34g9-rvrj\"\u003e\u003ccode\u003eGHSA-w2rr-34g9-rvrj\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-4w3w-2rp5-g8jm\"\u003e\u003ccode\u003eGHSA-4w3w-2rp5-g8jm\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: the processing-instruction grammar regex no longer backtracks quadratically on an unterminated processing instruction (\u003ccode\u003e\u0026lt;?…\u003c/code\u003e with no closing \u003ccode\u003e?\u0026gt;\u003c/code\u003e), preventing a denial-of-service (ReDoS) reachable from \u003ccode\u003eDOMParser.parseFromString\u003c/code\u003e with default options. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-g53g-w8rj-fmg7\"\u003e\u003ccode\u003eGHSA-g53g-w8rj-fmg7\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eCharacterData\u003c/code\u003e \u003ccode\u003enodeValue\u003c/code\u003e and \u003ccode\u003edata\u003c/code\u003e are now kept in sync \u003ca href=\"https://redirect.github.com/xmldom/xmldom/pull/990\"\u003e\u003ccode\u003e[#990](https://github.com/xmldom/xmldom/issues/990)\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChore\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eupdated dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThank you,\n\u003ca href=\"https://github.com/bhaswanthc\"\u003e\u003ccode\u003e@​bhaswanthc\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/jmestwa-coder\"\u003e\u003ccode\u003e@​jmestwa-coder\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/stevenobiajulu\"\u003e\u003ccode\u003e@​stevenobiajulu\u003c/code\u003e\u003c/a\u003e,\nfor your contributions\u003c/p\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/xmldom/xmldom/compare/0.8.13...0.8.14\"\u003e0.8.14\u003c/a\u003e\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity: \u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e now also rejects invalid element and attribute names when \u003ccode\u003e{ requireWellFormed: true }\u003c/code\u003e is passed, throwing \u003ccode\u003eInvalidStateError\u003c/code\u003e for a name that is not a valid XML \u003ca href=\"https://www.w3.org/TR/xml-names/#NT-QName\"\u003e\u003ccode\u003eQName\u003c/code\u003e\u003c/a\u003e (this covers the namespace prefix, which surfaces in the element qualified name or in a synthesized \u003ccode\u003exmlns:\u003c/code\u003e declaration). This prevents XML injection via \u003ccode\u003ecreateElement()\u003c/code\u003e / \u003ccode\u003esetAttribute()\u003c/code\u003e, extending the existing \u003ccode\u003erequireWellFormed\u003c/code\u003e checks to the serialized name set. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-w2rr-34g9-rvrj\"\u003e\u003ccode\u003eGHSA-w2rr-34g9-rvrj\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-4w3w-2rp5-g8jm\"\u003e\u003ccode\u003eGHSA-4w3w-2rp5-g8jm\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThank you,\n\u003ca href=\"https://github.com/bhaswanthc\"\u003e\u003ccode\u003e@​bhaswanthc\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/jmestwa-coder\"\u003e\u003ccode\u003e@​jmestwa-coder\u003c/code\u003e\u003c/a\u003e,\nfor your contributions\u003c/p\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/xmldom/xmldom/compare/0.9.9...0.9.10\"\u003e0.9.10\u003c/a\u003e\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/xmldom/xmldom/commit/b5b8fb5b579ae1183b34e74b3bc39d7eb50a226a\"\u003e\u003ccode\u003eb5b8fb5\u003c/code\u003e\u003c/a\u003e 0.8.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/xmldom/xmldom/commit/327508ea98d169285b2c0559836332a9879de213\"\u003e\u003ccode\u003e327508e\u003c/code\u003e\u003c/a\u003e docs: add 0.8.15 CHANGELOG entry\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/xmldom/xmldom/commit/f40ccb861eee0acbf5ee4feb9a34932e87b329c9\"\u003e\u003ccode\u003ef40ccb8\u003c/code\u003e\u003c/a\u003e fix: prevent quadratic malformed-tag recovery and normalize() adjacent-text m...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/xmldom/xmldom/commit/3abb0934f5a8a84d83a1f9cde0f2bd04c08b2a09\"\u003e\u003ccode\u003e3abb093\u003c/code\u003e\u003c/a\u003e fix: prevent end-tag whitespace-trim ReDoS via anchored trim (GHSA-x4fp-j954-...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/xmldom/xmldom/commit/2c548f200cfec991cd5846627ef8f03542309213\"\u003e\u003ccode\u003e2c548f2\u003c/code\u003e\u003c/a\u003e fix: prevent quadratic attribute de-duplication via null-prototype membership...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/xmldom/xmldom/commit/08a74b47c7f29d2e9b3212682856b959040d1838\"\u003e\u003ccode\u003e08a74b4\u003c/code\u003e\u003c/a\u003e test: characterize NamedNodeMap attribute de-duplication before the index ref...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/xmldom/xmldom/commit/954370f58c046223faf95ba77efcbc8ce014409d\"\u003e\u003ccode\u003e954370f\u003c/code\u003e\u003c/a\u003e fix: prevent quadratic namespace-map memory consumption via prototype-chain i...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/xmldom/xmldom/commit/4430189660b0d380ee9c9ee7550a1358688e8828\"\u003e\u003ccode\u003e4430189\u003c/code\u003e\u003c/a\u003e fix: report not-well-formed end-tag trailing content (GHSA-6h8r-xr42-gp59)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/xmldom/xmldom/commit/6c3fb5ffeafe7901ec928ce9010988dd716c94a0\"\u003e\u003ccode\u003e6c3fb5f\u003c/code\u003e\u003c/a\u003e fix: prevent XML injection via unsafe EntityReference name (GHSA-6gmq-8vp8-gcm6)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/xmldom/xmldom/commit/3b694872bcb5c7e3cbadba961a4be2488750ce5b\"\u003e\u003ccode\u003e3b69487\u003c/code\u003e\u003c/a\u003e fix: prevent XML injection via unsafe processing instruction target serializa...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/xmldom/xmldom/compare/0.8.11...0.8.15\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~karfau\"\u003ekarfau\u003c/a\u003e, a new releaser for \u003ccode\u003e@​xmldom/xmldom\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-uri` from 3.1.0 to 3.1.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.0...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nanoid` from 3.3.11 to 3.3.19\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/releases\"\u003enanoid's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed breaking Nano ID by requesting big ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/blob/main/CHANGELOG.md\"\u003enanoid's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID (by \u003ca href=\"https://github.com/geoffrey-diederichs\"\u003e\u003ccode\u003e@​geoffrey-diederichs\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed breaking Nano ID by requesting big ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/eb63bd6775188dc35d143bf24868be094f19b5ee\"\u003e\u003ccode\u003eeb63bd6\u003c/code\u003e\u003c/a\u003e Release 3.3.19 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9067e0361a643ab2c94ddd67606efbf275f6c0dd\"\u003e\u003ccode\u003e9067e03\u003c/code\u003e\u003c/a\u003e Sync CJS and ESM\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9ad98052b316c5e707f8098ace509d2ae165e54d\"\u003e\u003ccode\u003e9ad9805\u003c/code\u003e\u003c/a\u003e Release 3.3.18 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/55e50a0621ec084b4bb4000ea4e86e1191bd3da8\"\u003e\u003ccode\u003e55e50a0\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e10f8d40ce9d1ab47f66d65a16b48086432730d0\"\u003e\u003ccode\u003ee10f8d4\u003c/code\u003e\u003c/a\u003e Update index.native.js (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/606\"\u003e#606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/73d67168136b36fd3b644159b0cff149da4905d9\"\u003e\u003ccode\u003e73d6716\u003c/code\u003e\u003c/a\u003e Release 3.3.17 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/f9d13f150847d117877adee3460a46eceb0cf49b\"\u003e\u003ccode\u003ef9d13f1\u003c/code\u003e\u003c/a\u003e Sync 0 size behaviour with PostCSS 5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9760e112757cf7d46a79abd7a133bc4958757bb8\"\u003e\u003ccode\u003e9760e11\u003c/code\u003e\u003c/a\u003e Release 3.3.16 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66d\"\u003e\u003ccode\u003ee835c9b\u003c/code\u003e\u003c/a\u003e fix(non-secure): clamp negative size to prevent infinite loop (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/601\"\u003e#601\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/96dd086eb24396a275fa93ee78d73b2fece35809\"\u003e\u003ccode\u003e96dd086\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ai/nanoid/compare/3.3.11...3.3.19\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for nanoid since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.4.49 to 8.5.28\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.28\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes types regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed removing any comments starting with \u003ccode\u003e/*#\u003c/code\u003e (by \u003ca href=\"https://github.com/dylanpulver\"\u003e\u003ccode\u003e@​dylanpulver\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e*\u003c/code\u003e hack before a comment in Custom Properties (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed empty values in the middle of \u003ccode\u003elist.comma()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed whitespace-only values in \u003ccode\u003elist.space()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed rule’s end position on space before semicolon (by \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/romainmenke\"\u003e\u003ccode\u003e@​romainmenke\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed Chinese text in deprecation warning (by \u003ca href=\"https://github.com/Jesse205\"\u003e\u003ccode\u003e@​Jesse205\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.28\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes types regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed removing any comments starting with \u003ccode\u003e/*#\u003c/code\u003e (by \u003ca href=\"https://github.com/dylanpulver\"\u003e\u003ccode\u003e@​dylanpulver\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e*\u003c/code\u003e hack before a comment in Custom Properties (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed empty values in the middle of \u003ccode\u003elist.comma()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed whitespace-only values in \u003ccode\u003elist.space()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed rule’s end position on space before semicolon (by \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/romainmenke\"\u003e\u003ccode\u003e@​romainmenke\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed Chinese text in deprecation warning (by \u003ca href=\"https://github.com/Jesse205\"\u003e\u003ccode\u003e@​Jesse205\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/e544bffc4f4b3966d8ec69c41744b3ed65afc64a\"\u003e\u003ccode\u003ee544bff\u003c/code\u003e\u003c/a\u003e Release 8.5.28 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f8fc2525717a6a7216659f7be43c525f60c6a15a\"\u003e\u003ccode\u003ef8fc252\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/5039fd78962d285abea5d7b3aebef32f053781ce\"\u003e\u003ccode\u003e5039fd7\u003c/code\u003e\u003c/a\u003e Add missed release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/ae40ca499cf6a9afdbb264c0ec09e71fe934e2af\"\u003e\u003ccode\u003eae40ca4\u003c/code\u003e\u003c/a\u003e Release 8.5.27 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/62b1626bb7fbb28eda616d002cbd525d239b18ba\"\u003e\u003ccode\u003e62b1626\u003c/code\u003e\u003c/a\u003e Fix linter\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/1dba9384515a2dbc64517697c2f738b6d5c3f9a4\"\u003e\u003ccode\u003e1dba938\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3e82edc9f037faa41647342dceceba9b841f9881\"\u003e\u003ccode\u003e3e82edc\u003c/code\u003e\u003c/a\u003e Keep non-annotation comments when the processor has no plugins (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2150\"\u003e#2150\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/6d23bc362203118478bc8051b81f2910907ebe6e\"\u003e\u003ccode\u003e6d23bc3\u003c/code\u003e\u003c/a\u003e Fix link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/508e9976be81536292e7666741e1c35e876b9a6a\"\u003e\u003ccode\u003e508e997\u003c/code\u003e\u003c/a\u003e Add GitHub Sponsors link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/e993739dc49b6055f7dfc59b161d75702f0b2b8b\"\u003e\u003ccode\u003ee993739\u003c/code\u003e\u003c/a\u003e Add CodeRabbit sponsor (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2145\"\u003e#2145\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.4.49...8.5.28\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `shell-quote` from 1.8.3 to 1.10.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md\"\u003eshell-quote's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.9.0...v1.10.0\"\u003ev1.10.0\u003c/a\u003e - 2026-07-10\u003c/h2\u003e\n\u003ch3\u003eMerged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[New] \u003ccode\u003eparse\u003c/code\u003e: add opt-in \u003ccode\u003esplitUnquoted\u003c/code\u003e option for shell field-splitting of unquoted expansions \u003ca href=\"https://redirect.github.com/ljharb/shell-quote/pull/1\"\u003e\u003ccode\u003e[#1](https://github.com/ljharb/shell-quote/issues/1)\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: match nested \u003ccode\u003e${...}\u003c/code\u003e braces so nested parameter expansion is consumed as one substitution \u003ca href=\"https://github.com/ljharb/shell-quote/commit/c0842c8a7a034066da2496a75e91cbe500ff736c\"\u003e\u003ccode\u003ec0842c8\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003eparse\u003c/code\u003e: pin single-quote literalness and unmatched-quote handling \u003ca href=\"https://github.com/ljharb/shell-quote/commit/a0d03e35c8ede24016502c4433b8f5d6b3100a62\"\u003e\u003ccode\u003ea0d03e3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] remove the space in js code fences so evalmd evaluates them \u003ca href=\"https://github.com/ljharb/shell-quote/commit/2116fa36aeea77fe8d561b0db46b1f9b26b8cf1b\"\u003e\u003ccode\u003e2116fa3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003equote\u003c/code\u003e: pin conservative escaping of \u003ccode\u003e=\u003c/code\u003e, \u003ccode\u003e@\u003c/code\u003e, \u003ccode\u003e^\u003c/code\u003e, \u003ccode\u003e,\u003c/code\u003e, \u003ccode\u003e:\u003c/code\u003e, \u003ccode\u003e!\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/1c36f3ff77d26d200620c1027e5c271050120b8e\"\u003e\u003ccode\u003e1c36f3f\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] document that \u003ccode\u003equote\u003c/code\u003e outputs POSIX quoting, not \u003ccode\u003ecmd.exe\u003c/code\u003e/PowerShell \u003ca href=\"https://github.com/ljharb/shell-quote/commit/100e96e0ffadcca97d63dda15651c70b9f83507c\"\u003e\u003ccode\u003e100e96e\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] document \u003ccode\u003eparse\u003c/code\u003e's supported parameter-expansion subset \u003ca href=\"https://github.com/ljharb/shell-quote/commit/e1c75cd6e4a3c60003792c7f2802587d328622cb\"\u003e\u003ccode\u003ee1c75cd\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: a backslash inside single quotes must not escape the closing quote \u003ca href=\"https://github.com/ljharb/shell-quote/commit/5d460a332b54b83153297fe7d1964330b28fa491\"\u003e\u003ccode\u003e5d460a3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] fix stale example outputs \u003ca href=\"https://github.com/ljharb/shell-quote/commit/2de86f5d44f44d3ac9df36413d8a05f3534cdec6\"\u003e\u003ccode\u003e2de86f5\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003equote\u003c/code\u003e: pin that a backslash with whitespace is not doubled in single quotes (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/14\"\u003e#14\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/190e236bcf1d81caa8e40e8ea3bb11998575be71\"\u003e\u003ccode\u003e190e236\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] \u003ccode\u003equote\u003c/code\u003e: use output verbatim; do not re-quote it (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/1b364683b1e9e8d078fd3017cde82cf10c9c04a5\"\u003e\u003ccode\u003e1b36468\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Refactor] \u003ccode\u003eparse\u003c/code\u003e: fix swapped \u003ccode\u003eSINGLE_QUOTE\u003c/code\u003e/\u003ccode\u003eDOUBLE_QUOTE\u003c/code\u003e variable names \u003ca href=\"https://github.com/ljharb/shell-quote/commit/801af5c935b27d6dcda63b3975d5e92a7b6f887f\"\u003e\u003ccode\u003e801af5c\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[types] fix an error TS v6 ignores but v7 fails on \u003ca href=\"https://github.com/ljharb/shell-quote/commit/59bbf8b81bf3236842deb72805744d489f650eba\"\u003e\u003ccode\u003e59bbf8b\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@arethetypeswrong/cli\u003c/code\u003e, \u003ccode\u003eevalmd\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/a04d47516e1cd5b1b4d3f720ddf97561ed0082fc\"\u003e\u003ccode\u003ea04d475\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@arethetypeswrong/ci\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/d390f9a92b97a04b1f799298634e90dc581021e6\"\u003e\u003ccode\u003ed390f9a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003equote\u003c/code\u003e: the tilde test escapes every \u003ccode\u003e~\u003c/code\u003e, not just a leading one (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/9\"\u003e#9\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/617d119795c7b44d6e49a4d41f80195c4aa5735c\"\u003e\u003ccode\u003e617d119\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.4...v1.9.0\"\u003ev1.9.0\u003c/a\u003e - 2026-06-24\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[New] add types \u003ca href=\"https://github.com/ljharb/shell-quote/commit/dca6e21a02df4cc1a83ed1b5baa4d82df134170a\"\u003e\u003ccode\u003edca6e21\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9aa9e8f60991f8c4053a29e476795d891ff851ad\"\u003e\u003ccode\u003e9aa9e8f\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: finalize tokens in linear time (GHSA-395f-4hp3-45gv) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7ff5488599d01c323514f02f5efb74088dd134ec\"\u003e\u003ccode\u003e7ff5488\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] update workflows \u003ca href=\"https://github.com/ljharb/shell-quote/commit/75e849741ffaf2d3aa53ae0e18ef6bf9929ef478\"\u003e\u003ccode\u003e75e8497\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] Windows + node 4/6/7: pin eslint to 9 before install, since npm 2/3 cannot stage eslint 10\u003ccode\u003e@types/esrecurse\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/3fb739de44b81c69431947d54fbfc18998dd6d72\"\u003e\u003ccode\u003e3fb739d\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] retry \u003ccode\u003enpm install\u003c/code\u003e on Windows to survive npm 2/3 staging-rename flake \u003ca href=\"https://github.com/ljharb/shell-quote/commit/abe0163293c82963fa8a16cfaa87181846d5aced\"\u003e\u003ccode\u003eabe0163\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] Windows + node 5/7: install deps with a modern node \u003ca href=\"https://github.com/ljharb/shell-quote/commit/b4bafa2e7e58d53d9839b1c24976f61e54b43326\"\u003e\u003ccode\u003eb4bafa2\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003equote\u003c/code\u003e: escape leading \u003ccode\u003e~\u003c/code\u003e to prevent shell tilde-expansion \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7a76c1a12d8461c2234a1c655b943cee84cbff91\"\u003e\u003ccode\u003e7a76c1a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003etape\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7184b4458b65c17b931e126d8cb5f586c6717dc8\"\u003e\u003ccode\u003e7184b44\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] apparently \u003ccode\u003ejackspeak\u003c/code\u003e is no longer in the graph \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9ba368a4057b9f498b0fef23b5b15543ef81b98c\"\u003e\u003ccode\u003e9ba368a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.3...v1.8.4\"\u003ev1.8.4\u003c/a\u003e - 2026-05-22\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] \u003ccode\u003equote\u003c/code\u003e: validate object-token shapes \u003ca href=\"https://github.com/ljharb/shell-quote/commit/4378a6e613db5948168684864e49b42b83134d2d\"\u003e\u003ccode\u003e4378a6e\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003enpmignore\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/22ebec04349065a45ad8afc8cc8d53c4624634a6\"\u003e\u003ccode\u003e22ebec0\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] increase coverage \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9f3caa31900cc6ee64858b31134144c648ce206d\"\u003e\u003ccode\u003e9f3caa3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] replace runkit CI badge with shields.io check-runs badge \u003ca href=\"https://github.com/ljharb/shell-quote/commit/3344a047dd1e95f71c4ca27522cbfd05c56277e0\"\u003e\u003ccode\u003e3344a04\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/699c5113d135f4d4591574bebf173334ffa453d4\"\u003e\u003ccode\u003e699c511\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/64988d9a0e73a2ae710488952e3614958ef289d4\"\u003e\u003ccode\u003e64988d9\u003c/code\u003e\u003c/a\u003e v1.10.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/617d119795c7b44d6e49a4d41f80195c4aa5735c\"\u003e\u003ccode\u003e617d119\u003c/code\u003e\u003c/a\u003e [Tests] \u003ccode\u003equote\u003c/code\u003e: the tilde test escapes every \u003ccode\u003e~\u003c/code\u003e, not just a leading one (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/9\"\u003e#9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/59bbf8b81bf3236842deb72805744d489f650eba\"\u003e\u003ccode\u003e59bbf8b\u003c/code\u003e\u003c/a\u003e [types] fix an error TS v6 ignores but v7 fails on\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/190e236bcf1d81caa8e40e8ea3bb11998575be71\"\u003e\u003ccode\u003e190e236\u003c/code\u003e\u003c/a\u003e [Tests] \u003ccode\u003equote\u003c/code\u003e: pin that a backslash with whitespace is not doubled in singl...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/a04d47516e1cd5b1b4d3f720ddf97561ed0082fc\"\u003e\u003ccode\u003ea04d475\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003e@arethetypeswrong/cli\u003c/code\u003e, \u003ccode\u003eevalmd\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/b9545b39f4de17aa169410823c98acf58387e474\"\u003e\u003ccode\u003eb9545b3\u003c/code\u003e\u003c/a\u003e [New] \u003ccode\u003eparse\u003c/code\u003e: add opt-in \u003ccode\u003esplitUnquoted\u003c/code\u003e option for shell field-splitting of...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/1b364683b1e9e8d078fd3017cde82cf10c9c04a5\"\u003e\u003ccode\u003e1b36468\u003c/code\u003e\u003c/a\u003e [readme] \u003ccode\u003equote\u003c/code\u003e: use output verbatim; do not re-quote it (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/1c36f3ff77d26d200620c1027e5c271050120b8e\"\u003e\u003ccode\u003e1c36f3f\u003c/code\u003e\u003c/a\u003e [Tests] \u003ccode\u003equote\u003c/code\u003e: pin conservative escaping of \u003ccode\u003e=\u003c/code\u003e, \u003ccode\u003e@\u003c/code\u003e, \u003ccode\u003e^\u003c/code\u003e, \u003ccode\u003e,\u003c/code\u003e, \u003ccode\u003e:\u003c/code\u003e, \u003ccode\u003e!\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/e1c75cd6e4a3c60003792c7f2802587d328622cb\"\u003e\u003ccode\u003ee1c75cd\u003c/code\u003e\u003c/a\u003e [readme] document \u003ccode\u003eparse\u003c/code\u003e's supported parameter-expansion subset\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/c0842c8a7a034066da2496a75e91cbe500ff736c\"\u003e\u003ccode\u003ec0842c8\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003eparse\u003c/code\u003e: match nested \u003ccode\u003e${...}\u003c/code\u003e braces so nested parameter expansion is ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.3...v1.10.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/alvarolorentedev/opencode-mobile/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/alvarolorentedev/opencode-mobile/pull/27","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/alvarolorentedev%2Fopencode-mobile/issues/27","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/27/packages"},{"uuid":"5430398047","node_id":"PR_kwDOS7WM1s8AAAABDN8dFA","number":13,"state":"open","title":"chore(deps): bump the npm-minor-patch group with 72 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-12T01:37:52.000Z","updated_at":"2026-09-12T01:39:55.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm-minor-patch","update_count":72,"packages":[{"name":"@applemusic-like-lyrics/vue","old_version":"0.5.1","new_version":"0.5.2","repository_url":"https://github.com/amll-dev/applemusic-like-lyrics"},{"name":"@neteasecloudmusicapienhanced/api","old_version":"4.35.1","new_version":"4.40.1","repository_url":"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced"},{"name":"@sansenjian/qq-music-api","old_version":"2.4.0","new_version":"2.6.0","repository_url":"https://github.com/sansenjian/qq-music-api"},{"name":"@sentry/node","old_version":"10.57.0","new_version":"10.73.0","repository_url":"https://github.com/getsentry/sentry-javascript"},{"name":"@sentry/vue","old_version":"10.57.0","new_version":"10.73.0","repository_url":"https://github.com/getsentry/sentry-javascript"},{"name":"@simplewebauthn/server","old_version":"13.3.1","new_version":"13.3.3","repository_url":"https://github.com/MasterKale/SimpleWebAuthn"},{"name":"@types/pg","old_version":"8.20.0","new_version":"8.23.1","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"axios","old_version":"1.17.0","new_version":"1.20.0","repository_url":"https://github.com/axios/axios"},{"name":"dayjs","old_version":"1.11.21","new_version":"1.11.23","repository_url":"https://github.com/iamkun/dayjs"},{"name":"jszip","old_version":"3.10.1","new_version":"3.10.2","repository_url":"https://github.com/Stuk/jszip"},{"name":"multer","old_version":"2.1.1","new_version":"2.3.0","repository_url":"https://github.com/expressjs/multer"},{"name":"@types/multer","old_version":"2.1.0","new_version":"2.2.0","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"sass","old_version":"1.101.0","new_version":"1.104.0","repository_url":"https://github.com/sass/dart-sass"},{"name":"tsx","old_version":"4.22.4","new_version":"4.23.13","repository_url":"https://github.com/privatenumber/tsx"},{"name":"zod","old_version":"4.4.3","new_version":"4.5.4","repository_url":"https://github.com/colinhacks/zod"},{"name":"prettier","old_version":"3.8.4","new_version":"3.9.6","repository_url":"https://github.com/prettier/prettier"},{"name":"@applemusic-like-lyrics/core","old_version":"0.5.1","new_version":"0.5.2","repository_url":"https://github.com/amll-dev/applemusic-like-lyrics"},{"name":"@babel/plugin-transform-modules-systemjs","old_version":"7.29.7","new_version":"7.29.8","repository_url":"https://github.com/babel/babel"},{"name":"@babel/plugin-transform-regenerator","old_version":"7.29.7","new_version":"7.29.8","repository_url":"https://github.com/babel/babel"},{"name":"@babel/plugin-transform-spread","old_version":"7.29.7","new_version":"7.29.8","repository_url":"https://github.com/babel/babel"},{"name":"@neteasecloudmusicapienhanced/unblockmusic-utils","old_version":"0.3.3","new_version":"0.4.4","repository_url":"https://github.com/NeteaseCloudMusicApiEnhanced/UnblockNeteaseMusic-utils"},{"name":"@opentelemetry/api-logs","old_version":"0.214.0","new_version":"0.220.0","repository_url":"https://github.com/open-telemetry/opentelemetry-js"},{"name":"@opentelemetry/core","old_version":"2.8.0","new_version":"2.11.0","repository_url":"https://github.com/open-telemetry/opentelemetry-js"},{"name":"@opentelemetry/instrumentation","old_version":"0.214.0","new_version":"0.220.0","repository_url":"https://github.com/open-telemetry/opentelemetry-js"},{"name":"@opentelemetry/resources","old_version":"2.8.0","new_version":"2.11.0","repository_url":"https://github.com/open-telemetry/opentelemetry-js"},{"name":"@opentelemetry/sdk-trace-base","old_version":"2.8.0","new_version":"2.11.0","repository_url":"https://github.com/open-telemetry/opentelemetry-js"},{"name":"@opentelemetry/semantic-conventions","old_version":"1.41.1","new_version":"1.43.0","repository_url":"https://github.com/open-telemetry/opentelemetry-js"},{"name":"@parcel/watcher-android-arm64","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-darwin-arm64","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-darwin-x64","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-freebsd-x64","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-linux-arm-glibc","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-linux-arm-musl","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-linux-arm64-glibc","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-linux-arm64-musl","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-linux-x64-glibc","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-linux-x64-musl","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-win32-arm64","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-win32-x64","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@peculiar/asn1-android","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@peculiar/asn1-cms","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@peculiar/asn1-csr","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@peculiar/asn1-ecc","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@peculiar/asn1-pfx","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@peculiar/asn1-pkcs8","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@peculiar/asn1-pkcs9","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@peculiar/asn1-rsa","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@peculiar/asn1-schema","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@peculiar/asn1-x509-attr","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@peculiar/asn1-x509","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@sentry/browser","old_version":"10.57.0","new_version":"10.73.0","repository_url":"https://github.com/getsentry/sentry-javascript"},{"name":"@sentry/core","old_version":"10.57.0","new_version":"10.73.0","repository_url":"https://github.com/getsentry/sentry-javascript"},{"name":"@sentry/node-core","old_version":"10.57.0","new_version":"10.73.0","repository_url":"https://github.com/getsentry/sentry-javascript"},{"name":"@sentry/opentelemetry","old_version":"10.57.0","new_version":"10.73.0","repository_url":"https://github.com/getsentry/sentry-javascript"},{"name":"@types/express-serve-static-core","old_version":"5.1.1","new_version":"5.1.3","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"body-parser","old_version":"1.20.5","new_version":"1.20.8","repository_url":"https://github.com/expressjs/body-parser"},{"name":"cjs-module-lexer","old_version":"2.2.0","new_version":"2.2.1","repository_url":"https://github.com/nodejs/cjs-module-lexer"},{"name":"es-to-primitive","old_version":"1.3.0","new_version":"1.3.4","repository_url":"https://github.com/ljharb/es-to-primitive"},{"name":"fast-uri","old_version":"3.1.2","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"immutable","old_version":"5.1.6","new_version":"5.1.9","repository_url":"https://github.com/immutable-js/immutable-js"},{"name":"import-in-the-middle","old_version":"3.0.2","new_version":"3.5.0","repository_url":"https://github.com/nodejs/import-in-the-middle"},{"name":"ip-address","old_version":"10.2.0","new_version":"10.7.0","repository_url":"https://github.com/beaugunderson/ip-address"},{"name":"music-metadata","old_version":"11.13.0","new_version":"11.15.0","repository_url":"https://github.com/Borewit/music-metadata"},{"name":"own-keys","old_version":"1.0.1","new_version":"1.0.2","repository_url":"https://github.com/ljharb/own-keys"},{"name":"pg-protocol","old_version":"1.14.0","new_version":"1.16.0","repository_url":"https://github.com/brianc/node-postgres"},{"name":"pvutils","old_version":"1.1.5","new_version":"1.2.0","repository_url":"https://github.com/PeculiarVentures/pvutils"},{"name":"qs","old_version":"6.15.2","new_version":"6.15.3","repository_url":"https://github.com/ljharb/qs"},{"name":"sax","old_version":"1.6.0","new_version":"1.6.1","repository_url":"https://github.com/isaacs/sax-js"},{"name":"socks","old_version":"2.8.9","new_version":"2.8.10","repository_url":"https://github.com/JoshGlazebrook/socks"},{"name":"string.prototype.matchall","old_version":"4.0.12","new_version":"4.1.0","repository_url":"https://github.com/es-shims/String.prototype.matchAll"},{"name":"universalify","old_version":"2.0.1","new_version":"0.2.0","repository_url":"https://github.com/RyanZim/universalify"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm-minor-patch group with 72 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@applemusic-like-lyrics/vue](https://github.com/amll-dev/applemusic-like-lyrics/tree/HEAD/packages/vue) | `0.5.1` | `0.5.2` |\n| [@neteasecloudmusicapienhanced/api](https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced) | `4.35.1` | `4.40.1` |\n| [@sansenjian/qq-music-api](https://github.com/sansenjian/qq-music-api) | `2.4.0` | `2.6.0` |\n| [@sentry/node](https://github.com/getsentry/sentry-javascript) | `10.57.0` | `10.73.0` |\n| [@sentry/vue](https://github.com/getsentry/sentry-javascript) | `10.57.0` | `10.73.0` |\n| [@simplewebauthn/server](https://github.com/MasterKale/SimpleWebAuthn/tree/HEAD/packages/server) | `13.3.1` | `13.3.3` |\n| [@types/pg](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/pg) | `8.20.0` | `8.23.1` |\n| [axios](https://github.com/axios/axios) | `1.17.0` | `1.20.0` |\n| [dayjs](https://github.com/iamkun/dayjs) | `1.11.21` | `1.11.23` |\n| [jszip](https://github.com/Stuk/jszip) | `3.10.1` | `3.10.2` |\n| [multer](https://github.com/expressjs/multer) | `2.1.1` | `2.3.0` |\n| [@types/multer](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/multer) | `2.1.0` | `2.2.0` |\n| [sass](https://github.com/sass/dart-sass) | `1.101.0` | `1.104.0` |\n| [tsx](https://github.com/privatenumber/tsx) | `4.22.4` | `4.23.13` |\n| [zod](https://github.com/colinhacks/zod) | `4.4.3` | `4.5.4` |\n| [prettier](https://github.com/prettier/prettier) | `3.8.4` | `3.9.6` |\n| [@applemusic-like-lyrics/core](https://github.com/amll-dev/applemusic-like-lyrics/tree/HEAD/packages/core) | `0.5.1` | `0.5.2` |\n| [@babel/plugin-transform-modules-systemjs](https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs) | `7.29.7` | `7.29.8` |\n| [@babel/plugin-transform-regenerator](https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-regenerator) | `7.29.7` | `7.29.8` |\n| [@babel/plugin-transform-spread](https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-spread) | `7.29.7` | `7.29.8` |\n| [@neteasecloudmusicapienhanced/unblockmusic-utils](https://github.com/NeteaseCloudMusicApiEnhanced/UnblockNeteaseMusic-utils) | `0.3.3` | `0.4.4` |\n| [@opentelemetry/api-logs](https://github.com/open-telemetry/opentelemetry-js) | `0.214.0` | `0.220.0` |\n| [@opentelemetry/core](https://github.com/open-telemetry/opentelemetry-js) | `2.8.0` | `2.11.0` |\n| [@opentelemetry/instrumentation](https://github.com/open-telemetry/opentelemetry-js) | `0.214.0` | `0.220.0` |\n| [@opentelemetry/resources](https://github.com/open-telemetry/opentelemetry-js) | `2.8.0` | `2.11.0` |\n| [@opentelemetry/sdk-trace-base](https://github.com/open-telemetry/opentelemetry-js) | `2.8.0` | `2.11.0` |\n| [@opentelemetry/semantic-conventions](https://github.com/open-telemetry/opentelemetry-js) | `1.41.1` | `1.43.0` |\n| [@parcel/watcher-android-arm64](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-darwin-arm64](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-darwin-x64](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-freebsd-x64](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-linux-arm-glibc](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-linux-arm-musl](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-linux-arm64-glibc](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-linux-arm64-musl](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-linux-x64-glibc](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-linux-x64-musl](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-win32-arm64](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-win32-x64](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@peculiar/asn1-android](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/android) | `2.8.0` | `2.9.4` |\n| [@peculiar/asn1-cms](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/cms) | `2.8.0` | `2.9.4` |\n| [@peculiar/asn1-csr](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/csr) | `2.8.0` | `2.9.4` |\n| [@peculiar/asn1-ecc](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/ecc) | `2.8.0` | `2.9.4` |\n| [@peculiar/asn1-pfx](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/pfx) | `2.8.0` | `2.9.4` |\n| [@peculiar/asn1-pkcs8](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/pkcs8) | `2.8.0` | `2.9.4` |\n| [@peculiar/asn1-pkcs9](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/pkcs9) | `2.8.0` | `2.9.4` |\n| [@peculiar/asn1-rsa](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/rsa) | `2.8.0` | `2.9.4` |\n| [@peculiar/asn1-schema](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/schema) | `2.8.0` | `2.9.4` |\n| [@peculiar/asn1-x509-attr](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/x509-attr) | `2.8.0` | `2.9.4` |\n| [@peculiar/asn1-x509](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/x509) | `2.8.0` | `2.9.4` |\n| [@sentry/browser](https://github.com/getsentry/sentry-javascript) | `10.57.0` | `10.73.0` |\n| [@sentry/core](https://github.com/getsentry/sentry-javascript) | `10.57.0` | `10.73.0` |\n| [@sentry/node-core](https://github.com/getsentry/sentry-javascript) | `10.57.0` | `10.73.0` |\n| [@sentry/opentelemetry](https://github.com/getsentry/sentry-javascript) | `10.57.0` | `10.73.0` |\n| [@types/express-serve-static-core](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/express-serve-static-core) | `5.1.1` | `5.1.3` |\n| [body-parser](https://github.com/expressjs/body-parser) | `1.20.5` | `1.20.8` |\n| [cjs-module-lexer](https://github.com/nodejs/cjs-module-lexer) | `2.2.0` | `2.2.1` |\n| [es-to-primitive](https://github.com/ljharb/es-to-primitive) | `1.3.0` | `1.3.4` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.2` | `3.1.7` |\n| [immutable](https://github.com/immutable-js/immutable-js) | `5.1.6` | `5.1.9` |\n| [import-in-the-middle](https://github.com/nodejs/import-in-the-middle) | `3.0.2` | `3.5.0` |\n| [ip-address](https://github.com/beaugunderson/ip-address) | `10.2.0` | `10.7.0` |\n| [music-metadata](https://github.com/Borewit/music-metadata) | `11.13.0` | `11.15.0` |\n| [own-keys](https://github.com/ljharb/own-keys) | `1.0.1` | `1.0.2` |\n| [pg-protocol](https://github.com/brianc/node-postgres/tree/HEAD/packages/pg-protocol) | `1.14.0` | `1.16.0` |\n| [pvutils](https://github.com/PeculiarVentures/pvutils) | `1.1.5` | `1.2.0` |\n| [qs](https://github.com/ljharb/qs) | `6.15.2` | `6.15.3` |\n| [sax](https://github.com/isaacs/sax-js) | `1.6.0` | `1.6.1` |\n| [socks](https://github.com/JoshGlazebrook/socks) | `2.8.9` | `2.8.10` |\n| [string.prototype.matchall](https://github.com/es-shims/String.prototype.matchAll) | `4.0.12` | `4.1.0` |\n| [universalify](https://github.com/RyanZim/universalify) | `2.0.1` | `0.2.0` |\n\nUpdates `@applemusic-like-lyrics/vue` from 0.5.1 to 0.5.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/amll-dev/applemusic-like-lyrics/releases\"\u003e@​applemusic-like-lyrics/vue's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e最新 main 分支开发调试构建\u003c/h2\u003e\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e修正工作流 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/4e586361026cd31b79d7d60ce41a6d3c5106d666\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e修正工作流 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/f9fa644e4726d5dec5f661036aa0a22cac58fa22\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e修正工作流 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/f090519d8393abb8fff76ed048e68b432917f214\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e修正顶栏 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/44ada57bc07f57f532bb7289c1dd0d42b7acb542\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e增加文档页面列表 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/6c2115fee0a4a0653c238ec125d13ea5d86e3b00\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e增加代码高亮，修改排版和样式 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/6b1c1f9deabfce77b4b218cf1bae84e24d44c871\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e增加表格和其他样式支持 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/a47b5db16ccf67d31185457188292d9247d45a10\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e优化样式 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/6c91b4b70a75e69635e7ee62b11d45de8caafa3e\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e增加歌词编辑器文档（感谢 \u003ca href=\"https://github.com/Xionghaizi001\"\u003e\u003ccode\u003e@​Xionghaizi001\u003c/code\u003e\u003c/a\u003e ） (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/4cddb8666f83da2d256127ba1fab694e03311216\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eCommits\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e解耦部分模块 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/804a0de7b6626b4982c55a2f0a875e2274423406\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e支持调节背景帧数和渲染精度 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/f4dd4e1eada165482c76fa3d73290118fd3b1c55\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e更新构建工作流 NodeJS 版本 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/289faae66c38aa8958473b3ce55ab65f6f7f033c\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e增加 ESLyric 歌词格式支持 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/13c05e66271281fb3b10f0877611760cc7cab7dd\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e补充说明 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/41479a6050164bbdac1909ea8203db5028bd290e\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e让歌词行保持在 GPU 层以缓解 CPU 压力 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/2c815abc09a0546bcf4bf72dc4c2b8ea2b94bbe0\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ea41d7f8: 更改辉光判定和渲染 (Eplor)\u003c/li\u003e\n\u003cli\u003e将是否应用强调效果的条件还原回去 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/8d30cf51f32d3b7aa7591eca35a43f92c3e0ba56\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e重新调节了辉光效果和相关样式的匹配 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/e0c9048083e213d7fffda290ab68b2d41e9342f2\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e57b243b: 优化请求接口 (SteveXMH)\u003c/li\u003e\n\u003cli\u003e增加镜像源以加速 AMLL TTML DB 歌词获取 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/3631c69fe56fcdb58e237e9b6719469f9eb046cc\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e完成对接低频数据到背景渲染器实现特殊效果 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/868cbc2edfb2a80f48b62c45020ffa34a2380eb1\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e5e45dbd: Merge branch 'dev' of github.com:Steve-xmh/applemusic-like-lyrics into dev (SteveXMH)\u003c/li\u003e\n\u003cli\u003e更新构建 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/5c47f87fd08b4d8573ff88c3fb8545767875875a\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e统一了音频可视化数据源 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/dfe5278eef72e5cb618aed9dbd3f42bc5017f40d\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e可以让背景接收音频可视化数据了 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/33ac4620f06d74279a80ad11258fcd7e2641e8e3\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e传入fttLowCut Shader实现 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/7d5208f73ed265bdc49128b0cf3e2859f401a638\"\u003eEplor\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e90ab6b5: Merge branch 'dev' of github.com:Steve-xmh/applemusic-like-lyrics into dev (SteveXMH)\u003c/li\u003e\n\u003cli\u003e支持传参FFT到背景 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/9ab091134ea35004998f0df76dca3e8c463ea0b8\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e微调了音频可视化效果 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/e1195a8260a580d8d827f4680cdf5f2f6f0070d3\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e增加作为组件嵌入其他项目的环境类别 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/1ad21dc4b47cf8c51310d3ee0be2c2476d812bd3\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e调优了窗口较小时的布局 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/171e35fefe7db68e7a8b6cce57ac3852b4d9edea\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e优化竖向布局 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/b43e28d53ca943dea16b5914f908621687fdadd5\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e流体FFT动画算法超级更新 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/187c1166f274576d53a08c69cc9e06b1d806e912\"\u003eEplor\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e修复FFT流体动态效果幅度 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/a72a4744ebac168a91a3fa4cb0ebd1a1dbb52925\"\u003eEplor\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e优化背景跳动算法 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/eba9040ccff32fe498ecef78d5be7fc59b3b0d6e\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e增加显示背景调试数据功能 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/188a761885727eaa889eb2f3c569998adcfaf428\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e稍微调整了一下fft动画算法 core: 给shader加了一个参数 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/97ca78af3130407be9587f7015fb529e2f0c15ff\"\u003eEplor\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e构建 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/4f55e86cbec878ff8a84eb7b190a9dac06ebddd3\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e支持 Eplor 背景修改流动速度 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/d38babacfb7c141684614ff2fa3c956359631230\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e修正产物类型定义文件指向 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/55b45b3f82f8b3b175ad2b14772eed8164b0ded6\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e修正样式 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/3291134e3392a48c38d14c92891c9f21a4955f22\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e为 Eplor 流体背景增加切换图像过渡效果 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/d8d4b3bda1129034e642bb72bbe1b2fc7b7bfeb5\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e增加根据是否有歌词调节背景效果 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/e443e6842bad69e08e07347b10f763aa75133dac\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e可配置禁用混色效果 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/efa6f0914ec7986140d329cb95d08da601cbf8a9\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e调整背景动画 更好的背景渲染效果 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/5906b725e6a0ecad1732c96d58f16f3eb8c1dc14\"\u003eEplor\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e调整了流体渲染效果 基本完美 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/a2e1833b9b0b9204a5001e894a769263b180bcd4\"\u003eEplor\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/amll-dev/applemusic-like-lyrics/blob/main/packages/vue/CHANGELOG.md\"\u003e@​applemusic-like-lyrics/vue's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.5.2 (2026-07-09)\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003erefactor(core):\u003c/strong\u003e 将点击相关事件和样式由歌词行上移至歌词组 (\u003ca href=\"https://redirect.github.com/amll-dev/applemusic-like-lyrics/pull/538\"\u003e#538\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003echore(core):\u003c/strong\u003e 一些简单的代码优化避免样式重新计算 (\u003ca href=\"https://redirect.github.com/amll-dev/applemusic-like-lyrics/pull/540\"\u003e#540\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003echore(core):\u003c/strong\u003e 简单优化一点Mesh着色器的代码 (\u003ca href=\"https://redirect.github.com/amll-dev/applemusic-like-lyrics/pull/558\"\u003e#558\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003echore:\u003c/strong\u003e 修复 linter 警告 (\u003ca href=\"https://redirect.github.com/amll-dev/applemusic-like-lyrics/pull/539\"\u003e#539\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eContributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eapoint123 \u003ca href=\"https://github.com/apoint123\"\u003e\u003ccode\u003e@​apoint123\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eLinho\u003c/li\u003e\n\u003cli\u003eSteveXMH \u003ca href=\"https://github.com/Steve-xmh\"\u003e\u003ccode\u003e@​Steve-xmh\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/amll-dev/applemusic-like-lyrics/commit/fd7ec2d597daa2a66a37ca5f3214d6757ec17cfa\"\u003e\u003ccode\u003efd7ec2d\u003c/code\u003e\u003c/a\u003e chore(release): publish\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/amll-dev/applemusic-like-lyrics/commits/core-bundle@0.5.2/packages/vue\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@neteasecloudmusicapienhanced/api` from 4.35.1 to 4.40.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/releases\"\u003e@​neteasecloudmusicapienhanced/api's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eRelease v4.40.1\u003c/h1\u003e\n\u003ch2\u003e更新内容 / Changelog\u003c/h2\u003e\n\u003cp\u003e从 \u003ccode\u003ev4.40.0\u003c/code\u003e 到 \u003ccode\u003ev4.40.1\u003c/code\u003e 的提交记录：\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eci: fix pnpm has no pnpm-workspace.yaml (4a91f77)\u003c/li\u003e\n\u003cli\u003efeat: 更新歌曲相关接口 (a7437f7)\u003c/li\u003e\n\u003cli\u003edocs: 补全私人漫游模式文档内容 (7b17a08)\u003c/li\u003e\n\u003cli\u003efix: /song/url/v1/302 \u0026amp; /song/download/url/v1 支持臻音全景声 (0b5c392)\u003c/li\u003e\n\u003cli\u003efix: /song/url/v1 支持臻音全景声 (881267c)\u003c/li\u003e\n\u003cli\u003efix: 错误的docker配置 (d7c0db9)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e自动发布 via GitHub Actions\u003c/p\u003e\n\u003ch1\u003eRelease v4.40.0\u003c/h1\u003e\n\u003ch2\u003e更新内容 / Changelog\u003c/h2\u003e\n\u003cp\u003e从 \u003ccode\u003ev4.39.0\u003c/code\u003e 到 \u003ccode\u003ev4.40.0\u003c/code\u003e 的提交记录：\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efixes (a2a2a40)\u003c/li\u003e\n\u003cli\u003efix: pkg打包node18兼容 (543660f)\u003c/li\u003e\n\u003cli\u003efix: node18兼容 (98a9500)\u003c/li\u003e\n\u003cli\u003erefactor: 重写checkToken V2模块 (c4a3d83)\u003c/li\u003e\n\u003cli\u003eMerge branch 'pr/235' (c1fe1eb)\u003c/li\u003e\n\u003cli\u003eupd (3357317)\u003c/li\u003e\n\u003cli\u003eci: test ci with the workflow file (5b780ad)\u003c/li\u003e\n\u003cli\u003eci: test ci with workflow file (fc9f418)\u003c/li\u003e\n\u003cli\u003eformat docs (5859944)\u003c/li\u003e\n\u003cli\u003eremove disclaimer (aaa6459)\u003c/li\u003e\n\u003cli\u003efeat: 新增云贝任务相关接口 (a898e1d)\u003c/li\u003e\n\u003cli\u003erevert: revert some changes (686e8bf)\u003c/li\u003e\n\u003cli\u003efix: V-001 security vulnerability (9214cb9)\u003c/li\u003e\n\u003cli\u003efix: 修正workflow文件 (a79a2d9)\u003c/li\u003e\n\u003cli\u003efix(voice): load created podcasts in upload example (9608da9)\u003c/li\u003e\n\u003cli\u003efeat(voice): support cover image uploads (93b3e62)\u003c/li\u003e\n\u003cli\u003eci(test): test ci with the workflow file (15f515c)\u003c/li\u003e\n\u003cli\u003efix: V-001 security vulnerability (e255e8f)\u003c/li\u003e\n\u003cli\u003eci(test): test ci workflow file (16aa61f)\u003c/li\u003e\n\u003cli\u003eci(test): test ci workflow file (a939003)\u003c/li\u003e\n\u003cli\u003eperf: 更新接口定义 (8f4873f)\u003c/li\u003e\n\u003cli\u003eci: 更新问题管理工作流 (1a70281)\u003c/li\u003e\n\u003cli\u003efeat: add complete current-user event listing (f5f4ff6)\u003c/li\u003e\n\u003cli\u003efeat: add event privacy endpoint (eb1b5ba)\u003c/li\u003e\n\u003cli\u003eci(test): test ci workflow file (6732fc7)\u003c/li\u003e\n\u003cli\u003efix: 修复分享笔记接口 (6ce6b84)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/commit/4a91f77e622fe22e95dea7c9b73f0eeb27f2f0aa\"\u003e\u003ccode\u003e4a91f77\u003c/code\u003e\u003c/a\u003e ci: fix pnpm has no pnpm-workspace.yaml\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/commit/a7437f7ca4160e6816893a7cf8736afcb505c8d3\"\u003e\u003ccode\u003ea7437f7\u003c/code\u003e\u003c/a\u003e feat: 更新歌曲相关接口\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/commit/498945c401bbca8f739388449632877aa0613539\"\u003e\u003ccode\u003e498945c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/issues/241\"\u003e#241\u003c/a\u003e from 1254qwer/fix/song-url-v1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/commit/7b17a08628dd08202c62fe831be4f9158ac163cf\"\u003e\u003ccode\u003e7b17a08\u003c/code\u003e\u003c/a\u003e docs: 补全私人漫游模式文档内容\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/commit/0b5c3927c91bad932b93f9219bd8e738d1b619db\"\u003e\u003ccode\u003e0b5c392\u003c/code\u003e\u003c/a\u003e fix: /song/url/v1/302 \u0026amp; /song/download/url/v1 支持臻音全景声\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/commit/881267c56dbeb562993b3d3a20085602f9c74bc8\"\u003e\u003ccode\u003e881267c\u003c/code\u003e\u003c/a\u003e fix: /song/url/v1 支持臻音全景声\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/commit/d7c0db9455ef991be72a182789549969fb3ba99c\"\u003e\u003ccode\u003ed7c0db9\u003c/code\u003e\u003c/a\u003e fix: 错误的docker配置\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/commit/c1d14a86d9f612d40cbd9352521a670d911ff972\"\u003e\u003ccode\u003ec1d14a8\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/issues/237\"\u003e#237\u003c/a\u003e from NeteaseCloudMusicApiEnhanced/fix/yidun\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/commit/a2a2a40d7173cd0cc2d5d55b1e510a38fc844026\"\u003e\u003ccode\u003ea2a2a40\u003c/code\u003e\u003c/a\u003e fixes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/commit/543660fcdf1a13341790f4b5630ab05159b4e5a4\"\u003e\u003ccode\u003e543660f\u003c/code\u003e\u003c/a\u003e fix: pkg打包node18兼容\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/compare/v4.35.1...v4.40.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@sansenjian/qq-music-api` from 2.4.0 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/sansenjian/qq-music-api/blob/main/CHANGELOG.md\"\u003e@​sansenjian/qq-music-api's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.6.0 (2026-08-27)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e增加微信登录二维码相关接口与功能 (\u003ca href=\"https://redirect.github.com/sansenjian/qq-music-api/issues/45\"\u003e#45\u003c/a\u003e) (\u003ca href=\"https://github.com/sansenjian/qq-music-api/commit/15a38f8b8e0663aa7afea1440f92c6dd3b36100f\"\u003e15a38f8\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.5.0 (2026-08-10)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eaddress PR 41 review comments (\u003ca href=\"https://redirect.github.com/sansenjian/qq-music-api/issues/42\"\u003e#42\u003c/a\u003e) (\u003ca href=\"https://github.com/sansenjian/qq-music-api/commit/ba107d1b427436d03ea138f68ad86efe5f08c76b\"\u003eba107d1\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/sansenjian/qq-music-api/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@sentry/node` from 10.57.0 to 10.73.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/getsentry/sentry-javascript/releases\"\u003e@​sentry/node's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e10.73.0\u003c/h2\u003e\n\u003ch3\u003eImportant Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003efeat(v10/nextjs): Add \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e entry point (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23766\"\u003e#23766\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003ewithSentryConfig\u003c/code\u003e is now available from \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e, the path it moves to in v11. Importing it from \u003ccode\u003e@sentry/nextjs\u003c/code\u003e still works on v10 but logs a warning once, so you can change your \u003ccode\u003enext.config\u003c/code\u003e file today and upgrade to v11 without touching it again.\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// next.config.mjs\n- import { withSentryConfig } from '@sentry/nextjs';\n+ import { withSentryConfig } from '@sentry/nextjs/config';\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(v10/node): Deprecate \u003ccode\u003eshouldHandleError\u003c/code\u003e on \u003ccode\u003esetupExpressErrorHandler\u003c/code\u003e and \u003ccode\u003esetupFasitfyErrorHandler\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23734\"\u003e#23734\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/cloudflare): Instrument Durable Object handlers installed as read-only properties (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23769\"\u003e#23769\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003etest(v10/nextjs): Drop nextjs-16-cf-workers canary variant (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23775\"\u003e#23775\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eBundle size 📦\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003ePath\u003c/th\u003e\n\u003cth\u003eSize\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e27.1 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e - with treeshaking flags\u003c/td\u003e\n\u003ctd\u003e25.58 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing)\u003c/td\u003e\n\u003ctd\u003e45.54 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing + Span Streaming)\u003c/td\u003e\n\u003ctd\u003e47.28 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Profiling)\u003c/td\u003e\n\u003ctd\u003e50.17 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay)\u003c/td\u003e\n\u003ctd\u003e83.87 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay) - with treeshaking flags\u003c/td\u003e\n\u003ctd\u003e73.74 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay with Canvas)\u003c/td\u003e\n\u003ctd\u003e88.49 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay, Feedback)\u003c/td\u003e\n\u003ctd\u003e100.83 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Feedback)\u003c/td\u003e\n\u003ctd\u003e43.87 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. sendFeedback)\u003c/td\u003e\n\u003ctd\u003e31.78 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. FeedbackAsync)\u003c/td\u003e\n\u003ctd\u003e36.79 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Metrics)\u003c/td\u003e\n\u003ctd\u003e28.16 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Logs)\u003c/td\u003e\n\u003ctd\u003e28.38 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Metrics \u0026amp; Logs)\u003c/td\u003e\n\u003ctd\u003e29.06 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/react\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e28.86 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/react\u003c/code\u003e (incl. Tracing)\u003c/td\u003e\n\u003ctd\u003e47.74 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/vue\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e32.4 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/vue\u003c/code\u003e (incl. Tracing)\u003c/td\u003e\n\u003ctd\u003e47.46 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/svelte\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e27.12 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eCDN Bundle\u003c/td\u003e\n\u003ctd\u003e29.43 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/getsentry/sentry-javascript/blob/10.73.0/CHANGELOG.md\"\u003e@​sentry/node's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e10.73.0\u003c/h2\u003e\n\u003ch3\u003eImportant Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003efeat(v10/nextjs): Add \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e entry point (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23766\"\u003e#23766\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003ewithSentryConfig\u003c/code\u003e is now available from \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e, the path it moves to in v11. Importing it from \u003ccode\u003e@sentry/nextjs\u003c/code\u003e still works on v10 but logs a warning once, so you can change your \u003ccode\u003enext.config\u003c/code\u003e file today and upgrade to v11 without touching it again.\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// next.config.mjs\n- import { withSentryConfig } from '@sentry/nextjs';\n+ import { withSentryConfig } from '@sentry/nextjs/config';\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(v10/node): Deprecate \u003ccode\u003eshouldHandleError\u003c/code\u003e on \u003ccode\u003esetupExpressErrorHandler\u003c/code\u003e and \u003ccode\u003esetupFasitfyErrorHandler\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23734\"\u003e#23734\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/cloudflare): Instrument Durable Object handlers installed as read-only properties (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23769\"\u003e#23769\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003etest(v10/nextjs): Drop nextjs-16-cf-workers canary variant (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23775\"\u003e#23775\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e10.72.0\u003c/h2\u003e\n\u003ch3\u003eImportant Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eAI integrations no longer report errors that propagate to the caller (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23638\"\u003e#23638\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23639\"\u003e#23639\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23640\"\u003e#23640\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eAcross all AI integrations (OpenAI, Anthropic, Google GenAI, LangChain, and LangGraph), the SDK no longer sends an event to Sentry for errors that the AI framework propagates to your code. Previously the instrumentation reported these as unhandled (\u003ccode\u003ehandled: false\u003c/code\u003e) before your own error handling ran, so an error your code caught still showed up in Sentry as an unhandled crash. The span is still marked as errored and the error still propagates, so reporting is left to your application: if your code does not handle the error, it reaches Sentry's global error handlers and is captured as unhandled, just like any other uncaught error. Errors that a provider surfaces as data on an otherwise successful response (such as Anthropic error-shaped responses or Google GenAI blocked content) are still captured, since your code never sees them propagate.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003efeat(v10/cloudflare): Add \u003ccode\u003erpcTracePropagationBindings\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23737\"\u003e#23737\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23738\"\u003e#23738\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe new \u003ccode\u003erpcTracePropagationBindings\u003c/code\u003e option names the \u003ccode\u003eenv\u003c/code\u003e bindings that outgoing RPC calls propagate trace context to. Strings match a binding name exactly, regular expressions match by pattern, and the default empty array propagates to nothing. RPC has no headers to carry trace context, so the SDK appends it as a trailing argument that only a Sentry-instrumented receiver removes again. List only the bindings whose receiver you know runs Sentry. Setting the option takes precedence over \u003ccode\u003eenableRpcTracePropagation\u003c/code\u003e, which is now deprecated. When you build with the Sentry Cloudflare Vite plugin, the bindings that resolve to this worker (its own Durable Objects and self service bindings) are derived from your wrangler config and added for you.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(v10/astro): support astro v7 route patterns properly (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23657\"\u003e#23657\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/bundler-plugins): Preserve full file path in component annotation source maps (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23595\"\u003e#23595\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/core): Store child span timeout handle in \u003ccode\u003e_childSpanTimeoutID\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23673\"\u003e#23673\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/node): Only end the process session when it is still ok (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23731\"\u003e#23731\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/react-router): Use react-router's own instrumentation types instead of a mirrored copy (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23589\"\u003e#23589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/replay): Suppress Worker destroyed error on session expiry (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23654\"\u003e#23654\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/server-utils): Keep orchestrion registration out of tree-shaking (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23591\"\u003e#23591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/server-utils): Stop shipping orchestrion bundler plugins as production dependencies (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23667\"\u003e#23667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/server-utils): Support openai v7 in auto-instrumentation (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23713\"\u003e#23713\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/sveltekit): Detect native tracing in flattened SvelteKit 3 config (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23656\"\u003e#23656\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/f109d922f5971e2ade549b6c755524168b101818\"\u003e\u003ccode\u003ef109d92\u003c/code\u003e\u003c/a\u003e release: 10.73.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/1a3e04edc4d1c97a702861a9bddd3ed577a71de4\"\u003e\u003ccode\u003e1a3e04e\u003c/code\u003e\u003c/a\u003e meta(changelog): Update changelog for 10.73.0 (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23778\"\u003e#23778\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/da8d7696b08432cd94e78552d9f4c9322c1dc746\"\u003e\u003ccode\u003eda8d769\u003c/code\u003e\u003c/a\u003e test(v10/nextjs): Drop nextjs-16-cf-workers canary variant (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23775\"\u003e#23775\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/bea4d38bf5422ae917275d0b68ad575a2b2b475b\"\u003e\u003ccode\u003ebea4d38\u003c/code\u003e\u003c/a\u003e feat(v10/node): Deprecate \u003ccode\u003eshouldHandleError\u003c/code\u003e on \u003ccode\u003esetupExpressErrorHandler\u003c/code\u003e a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/605caaf2aa85f78ed9a180b273a335fe798bf30c\"\u003e\u003ccode\u003e605caaf\u003c/code\u003e\u003c/a\u003e feat(v10/nextjs): Add \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e entry point (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23766\"\u003e#23766\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/da17307e9e1898a48a3d4037aff96d5849f123fb\"\u003e\u003ccode\u003eda17307\u003c/code\u003e\u003c/a\u003e fix(v10/cloudflare): Instrument Durable Object handlers installed as read-onl...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/2c4ca38e52cb0e4c4ee69cbdc218c9cabd52eccf\"\u003e\u003ccode\u003e2c4ca38\u003c/code\u003e\u003c/a\u003e Merge branch 'release/10.72.0' into v10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/0d236289ba889ac8f007882726aaa62d9a83cc15\"\u003e\u003ccode\u003e0d23628\u003c/code\u003e\u003c/a\u003e release: 10.72.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/ac2094d469ace03e883abb5fc98b5dc678ccfe49\"\u003e\u003ccode\u003eac2094d\u003c/code\u003e\u003c/a\u003e meta(changelog): Update changelog for 10.72.0 (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23743\"\u003e#23743\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/f3254344c4b63382c12cec95b64e7c54f9e45ff9\"\u003e\u003ccode\u003ef325434\u003c/code\u003e\u003c/a\u003e feat(v10/cloudflare): Derive rpcTracePropagationBindings from the wrangler co...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/getsentry/sentry-javascript/compare/10.57.0...10.73.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@sentry/vue` from 10.57.0 to 10.73.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/getsentry/sentry-javascript/releases\"\u003e@​sentry/vue's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e10.73.0\u003c/h2\u003e\n\u003ch3\u003eImportant Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003efeat(v10/nextjs): Add \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e entry point (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23766\"\u003e#23766\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003ewithSentryConfig\u003c/code\u003e is now available from \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e, the path it moves to in v11. Importing it from \u003ccode\u003e@sentry/nextjs\u003c/code\u003e still works on v10 but logs a warning once, so you can change your \u003ccode\u003enext.config\u003c/code\u003e file today and upgrade to v11 without touching it again.\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// next.config.mjs\n- import { withSentryConfig } from '@sentry/nextjs';\n+ import { withSentryConfig } from '@sentry/nextjs/config';\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(v10/node): Deprecate \u003ccode\u003eshouldHandleError\u003c/code\u003e on \u003ccode\u003esetupExpressErrorHandler\u003c/code\u003e and \u003ccode\u003esetupFasitfyErrorHandler\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23734\"\u003e#23734\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/cloudflare): Instrument Durable Object handlers installed as read-only properties (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23769\"\u003e#23769\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003etest(v10/nextjs): Drop nextjs-16-cf-workers canary variant (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23775\"\u003e#23775\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eBundle size 📦\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003ePath\u003c/th\u003e\n\u003cth\u003eSize\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e27.1 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e - with treeshaking flags\u003c/td\u003e\n\u003ctd\u003e25.58 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing)\u003c/td\u003e\n\u003ctd\u003e45.54 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing + Span Streaming)\u003c/td\u003e\n\u003ctd\u003e47.28 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Profiling)\u003c/td\u003e\n\u003ctd\u003e50.17 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay)\u003c/td\u003e\n\u003ctd\u003e83.87 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay) - with treeshaking flags\u003c/td\u003e\n\u003ctd\u003e73.74 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay with Canvas)\u003c/td\u003e\n\u003ctd\u003e88.49 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay, Feedback)\u003c/td\u003e\n\u003ctd\u003e100.83 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Feedback)\u003c/td\u003e\n\u003ctd\u003e43.87 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. sendFeedback)\u003c/td\u003e\n\u003ctd\u003e31.78 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. FeedbackAsync)\u003c/td\u003e\n\u003ctd\u003e36.79 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Metrics)\u003c/td\u003e\n\u003ctd\u003e28.16 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Logs)\u003c/td\u003e\n\u003ctd\u003e28.38 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Metrics \u0026amp; Logs)\u003c/td\u003e\n\u003ctd\u003e29.06 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/react\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e28.86 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/react\u003c/code\u003e (incl. Tracing)\u003c/td\u003e\n\u003ctd\u003e47.74 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/vue\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e32.4 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/vue\u003c/code\u003e (incl. Tracing)\u003c/td\u003e\n\u003ctd\u003e47.46 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/svelte\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e27.12 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eCDN Bundle\u003c/td\u003e\n\u003ctd\u003e29.43 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/getsentry/sentry-javascript/blob/10.73.0/CHANGELOG.md\"\u003e@​sentry/vue's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e10.73.0\u003c/h2\u003e\n\u003ch3\u003eImportant Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003efeat(v10/nextjs): Add \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e entry point (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23766\"\u003e#23766\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003ewithSentryConfig\u003c/code\u003e is now available from \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e, the path it moves to in v11. Importing it from \u003ccode\u003e@sentry/nextjs\u003c/code\u003e still works on v10 but logs a warning once, so you can change your \u003ccode\u003enext.config\u003c/code\u003e file today and upgrade to v11 without touching it again.\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// next.config.mjs\n- import { withSentryConfig } from '@sentry/nextjs';\n+ import { withSentryConfig } from '@sentry/nextjs/config';\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(v10/node): Deprecate \u003ccode\u003eshouldHandleError\u003c/code\u003e on \u003ccode\u003esetupExpressErrorHandler\u003c/code\u003e and \u003ccode\u003esetupFasitfyErrorHandler\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23734\"\u003e#23734\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/cloudflare): Instrument Durable Object handlers installed as read-only properties (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23769\"\u003e#23769\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003etest(v10/nextjs): Drop nextjs-16-cf-workers canary variant (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23775\"\u003e#23775\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e10.72.0\u003c/h2\u003e\n\u003ch3\u003eImportant Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eAI integrations no longer report errors that propagate to the caller (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23638\"\u003e#23638\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23639\"\u003e#23639\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23640\"\u003e#23640\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eAcross all AI integrations (OpenAI, Anthropic, Google GenAI, LangChain, and LangGraph), the SDK no longer sends an event to Sentry for errors that the AI framework propagates to your code. Previously the instrumentation reported these as unhandled (\u003ccode\u003ehandled: false\u003c/code\u003e) before your own error handling ran, so an error your code caught still showed up in Sentry as an unhandled crash. The span is still marked as errored and the error still propagates, so reporting is left to your application: if your code does not handle the error, it reaches Sentry's global error handlers and is captured as unhandled, just like any other uncaught error. Errors that a provider surfaces as data on an otherwise successful response (such as Anthropic error-shaped responses or Google GenAI blocked content) are still captured, since your code never sees them propagate.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003efeat(v10/cloudflare): Add \u003ccode\u003erpcTracePropagationBindings\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23737\"\u003e#23737\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23738\"\u003e#23738\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe new \u003ccode\u003erpcTracePropagationBindings\u003c/code\u003e option names the \u003ccode\u003eenv\u003c/code\u003e bindings that outgoing RPC calls propagate trace context to. Strings match a binding name exactly, regular expressions match by pattern, and the default empty array propagates to nothing. RPC has no headers to carry trace context, so the SDK appends it as a trailing argument that only a Sentry-instrumented receiver removes again. List only the bindings whose receiver you know runs Sentry. Setting the option takes precedence over \u003ccode\u003eenableRpcTracePropagation\u003c/code\u003e, which is now deprecated. When you build with the Sentry Cloudflare Vite plugin, the bindings that resolve to this worker (its own Durable Objects and self service bindings) are derived from your wrangler config and added for you.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(v10/astro): support astro v7 route patterns properly (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23657\"\u003e#23657\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/bundler-plugins): Preserve full file path in component annotation source maps (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23595\"\u003e#23595\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/core): Store child span timeout handle in \u003ccode\u003e_childSpanTimeoutID\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23673\"\u003e#23673\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/node): Only end the process session when it is still ok (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23731\"\u003e#23731\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/react-router): Use react-router's own instrumentation types instead of a mirrored copy (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23589\"\u003e#23589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/replay): Suppress Worker destroyed error on session expiry (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23654\"\u003e#23654\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/server-utils): Keep orchestrion registration out of tree-shaking (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23591\"\u003e#23591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/server-utils): Stop shipping orchestrion bundler plugins as production dependencies (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23667\"\u003e#23667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/server-utils): Support openai v7 in auto-instrumentation (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23713\"\u003e#23713\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/sveltekit): Detect native tracing in flattened SvelteKit 3 config (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23656\"\u003e#23656\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/f109d922f5971e2ade549b6c755524168b101818\"\u003e\u003ccode\u003ef109d92\u003c/code\u003e\u003c/a\u003e release: 10.73.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/1a3e04edc4d1c97a702861a9bddd3ed577a71de4\"\u003e\u003ccode\u003e1a3e04e\u003c/code\u003e\u003c/a\u003e meta(changelog): Update changelog for 10.73.0 (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23778\"\u003e#23778\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/da8d7696b08432cd94e78552d9f4c9322c1dc746\"\u003e\u003ccode\u003eda8d769\u003c/code\u003e\u003c/a\u003e test(v10/nextjs): Drop nextjs-16-cf-workers canary variant (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23775\"\u003e#23775\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/bea4d38bf5422ae917275d0b68ad575a2b2b475b\"\u003e\u003ccode\u003ebea4d38\u003c/code\u003e\u003c/a\u003e feat(v10/node): Deprecate \u003ccode\u003eshouldHandleError\u003c/code\u003e on \u003ccode\u003esetupExpressErrorHandler\u003c/code\u003e a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/605caaf2aa85f78ed9a180b273a335fe798bf30c\"\u003e\u003ccode\u003e605caaf\u003c/code\u003e\u003c/a\u003e feat(v10/nextjs): Add \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e entry point (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23766\"\u003e#23766\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/da17307e9e1898a48a3d4037aff96d5849f123fb\"\u003e\u003ccode\u003eda17307\u003c/code\u003e\u003c/a\u003e fix(v10/cloudflare): Instrument Durable Object handlers installed as read-onl...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/2c4ca38e52cb0e4c4ee69cbdc218c9cabd52eccf\"\u003e\u003ccode\u003e2c4ca38\u003c/code\u003e\u003c/a\u003e Merge branch 'release/10.72.0' into v10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/0d236289ba889ac8f007882726aaa62d9a83cc15\"\u003e\u003ccode\u003e0d23628\u003c/code\u003e\u003c/a\u003e release: 10.72.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/ac2094d469ace03e883abb5fc98b5dc678ccfe49\"\u003e\u003ccode\u003eac2094d\u003c/code\u003e\u003c/a\u003e meta(changelog): Update changelog for 10.72.0 (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23743\"\u003e#23743\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/f3254344c4b63382c12cec95b64e7c54f9e45ff9\"\u003e\u003ccode\u003ef325434\u003c/code\u003e\u003c/a\u003e feat(v10/cloudflare): Derive rpcTracePropagationBindings from the wrangler co...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/getsentry/sentry-javascript/compare/10.57.0...10.73.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@simplewebauthn/server` from 13.3.1 to 13.3.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/releases\"\u003e@​simplewebauthn/server's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev13.3.3\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eChanges:\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e[server]\u003c/strong\u003e Updated MDS blob signature verification to support more algorithms (\u003ca href=\"https://redirect.github.com/MasterKale/SimpleWebAuthn/pull/788\"\u003e#788\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e[server]\u003c/strong\u003e Updated \u003ccode\u003eMetadataService\u003c/code\u003e to know about the new FIDO MDS blob trust anchor certificate (\u003ca href=\"https://redirect.github.com/MasterKale/SimpleWebAuthn/pull/789\"\u003e#789\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev13.3.2\u003c/h2\u003e\n\u003cp\u003eThis update fixes a CVSS v4 Low (2.0) security vulnerability identified in \u003cstrong\u003e\u003ccode\u003e@​simplewebauthn/server\u003c/code\u003e\u003c/strong\u003e. See the security advisory linked below for more information.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eChanges:\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e[server]\u003c/strong\u003e Fixed an issue with \u003ccode\u003everifyRegistrationResponse()\u003c/code\u003e allowing a maliciously-crafted attestation statement's \u003ccode\u003ex5c\u003c/code\u003e to contain a self-signed \u0026quot;root certificate\u0026quot; instead of chaining back to an RP-specified trust anchor (\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/security/advisories/GHSA-6hxq-p678-4hr2\"\u003eGHSA-6hxq-p678-4hr2\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/blob/master/CHANGELOG.md\"\u003e@​simplewebauthn/server's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev13.3.3\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eChanges:\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e[server]\u003c/strong\u003e Updated MDS blob signature verification to support more algorithms\n(\u003ca href=\"https://redirect.github.com/MasterKale/SimpleWebAuthn/pull/788\"\u003e#788\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e[server]\u003c/strong\u003e Updated \u003ccode\u003eMetadataService\u003c/code\u003e to know about the new FIDO MDS blob trust anchor\ncertificate (\u003ca href=\"https://redirect.github.com/MasterKale/SimpleWebAuthn/pull/789\"\u003e#789\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev13.3.2\u003c/h2\u003e\n\u003cp\u003eThis update fixes a CVSS v4 Low (2.0) security vulnerability identified in\n\u003cstrong\u003e\u003ccode\u003e@​simplewebauthn/server\u003c/code\u003e\u003c/strong\u003e. See the security advisory linked below for more information.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eChanges:\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e[server]\u003c/strong\u003e Fixed an issue with \u003ccode\u003everifyRegistrationResponse()\u003c/code\u003e allowing a maliciously-crafted\nattestation statement's \u003ccode\u003ex5c\u003c/code\u003e to contain a self-signed \u0026quot;root certificate\u0026quot; instead of chaining back\nto an RP-specified trust anchor\n(\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/security/advisories/GHSA-6hxq-p678-4hr2\"\u003eGHSA-6hxq-p678-4hr2\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commit/4b189bdfd6ffd5e3d30023b2d3e9970d81c89ce9\"\u003e\u003ccode\u003e4b189bd\u003c/code\u003e\u003c/a\u003e Update server version to 13.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commit/05db595392530c13074064f081b71c47e25cc7cc\"\u003e\u003ccode\u003e05db595\u003c/code\u003e\u003c/a\u003e Add GlobalSign Root R46 to FIDO MDS default root certs (\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/tree/HEAD/packages/server/issues/789\"\u003e#789\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commit/9bf80bfa0acb6c2d9e479588841915c48e406e3e\"\u003e\u003ccode\u003e9bf80bf\u003c/code\u003e\u003c/a\u003e Use JWT header alg when verifying MDS blob (\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/tree/HEAD/packages/server/issues/788\"\u003e#788\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commit/84656fff764256609193b9e0a0661c82dd379ebb\"\u003e\u003ccode\u003e84656ff\u003c/code\u003e\u003c/a\u003e Update version to 13.3.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commit/dd0d73c716a528e6645efafbd43a972b64df71f9\"\u003e\u003ccode\u003edd0d73c\u003c/code\u003e\u003c/a\u003e Fail cert path validation closed instead\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commit/213e9ba052632c9915704edbab48d4667141c3f2\"\u003e\u003ccode\u003e213e9ba\u003c/code\u003e\u003c/a\u003e Add test for failure to chain to trust anchor\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commit/989507a62d23960933b44018c1b090da0e73c803\"\u003e\u003ccode\u003e989507a\u003c/code\u003e\u003c/a\u003e Add tests for notAfter enforcement\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commit/b55f4b957881ca6a0c93d05aebca6cdf6424fffb\"\u003e\u003ccode\u003eb55f4b9\u003c/code\u003e\u003c/a\u003e Move explanation into test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commit/7bed04ce33a8fc2e4b0c2f8c84d7c171f001905f\"\u003e\u003ccode\u003e7bed04c\u003c/code\u003e\u003c/a\u003e Update comments around cert chain validity\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commit/6ee964484ad9bb9365c45c95b32e0065db45ed96\"\u003e\u003ccode\u003e6ee9644\u003c/code\u003e\u003c/a\u003e Add new tests\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commits/v13.3.3/packages/server\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@types/pg` from 8.20.0 to 8.23.1\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/pg\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `axios` from 1.17.0 to 1.20.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/axios/axios/releases\"\u003eaxios's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.20.0 — August 19, 2026\u003c/h2\u003e\n\u003cp\u003eThis release hardens runtime option handling, adds RFC 9110 status-code aliases, fixes Node.js and XHR reliability issues, and refreshes project tooling and documentation.\u003c/p\u003e\n\u003ch2\u003e⚠️ Breaking Changes \u0026amp; Deprecations\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHTTP Status Naming: Added ContentTooLarge (413) and UnprocessableContent (422), while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11082\"\u003e#11082\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRuntime Option Handling: Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects. This also clarifies Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection; see the PR for documented compatibility effects. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11141\"\u003e#11141\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eInterceptor Lifecycle: Prevented unbounded handler-array growth by trimming trailing ejected interceptors without changing iteration semantics, and kept interceptor operations safe when the public handlers field is nullish. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11087\"\u003e#11087\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11118\"\u003e#11118\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequest Error Preservation: Prevented custom Error.prepareStackTrace implementations that return non-string values from replacing the original request failure with an unrelated TypeError. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11109\"\u003e#11109\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eXHR Reliability: Navigation-canceled requests now reject with ECONNABORTED instead of resolving with status 0, while successful downloads flush their final progress callback during the live loadend dispatch. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11094\"\u003e#11094\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11121\"\u003e#11121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNode.js Socket Memory: Removed request-context retention from per-socket error listeners, preventing completed response data from being pinned for the lifetime of pooled keep-alive sockets. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11091\"\u003e#11091\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCore Methods and HTTP Errors: Prevented structural method-header buckets from leaking into outgoing headers, standardized invalid DNS lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE, and corrected the timeoutErrorMessage merge strategy. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11096\"\u003e#11096\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔧 Maintenance \u0026amp; Chores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDependencies: Updated fast-uri, postcss, js-yaml, mocha, development-tooling groups, and GitHub Actions dependencies. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11092\"\u003e#11092\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11098\"\u003e#11098\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11099\"\u003e#11099\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11106\"\u003e#11106\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11107\"\u003e#11107\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11122\"\u003e#11122\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11123\"\u003e#11123\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11126\"\u003e#11126\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11127\"\u003e#11127\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11133\"\u003e#11133\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11140\"\u003e#11140\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11143\"\u003e#11143\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11144\"\u003e#11144\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDocumentation: Applied the v1.19.0 documentation updates, added the missing fs import to the README stream example, introduced localized global search, and repaired the interceptor test link. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11101\"\u003e#11101\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11113\"\u003e#11113\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11097\"\u003e#11097\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11119\"\u003e#11119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSponsorship: Updated sponsorship links and data and added ScrapingBee as a sponsor. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11124\"\u003e#11124\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11136\"\u003e#11136\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11137\"\u003e#11137\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCI and Release: Switched ESM smoke tests to locked dependencies and synchronized package and runtime version metadata for v1.20.0. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11128\"\u003e#11128\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11152\"\u003e#11152\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🌟 New Contributors\u003c/h2\u003e\n\u003cp\u003eWe are thrilled to welcome our new contributors. Thank you for helping improve axios:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yens1\"\u003e\u003ccode\u003e@​yens1\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11109\"\u003e#11109\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Sasireddy001\"\u003e\u003ccode\u003e@​Sasireddy001\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11113\"\u003e#11113\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ari-token-security\"\u003e\u003ccode\u003e@​ari-token-security\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11094\"\u003e#11094\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timothyokooboh\"\u003e\u003ccode\u003e@​timothyokooboh\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11097\"\u003e#11097\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gi9439041-png\"\u003e\u003ccode\u003e@​gi9439041-png\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11119\"\u003e#11119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Hashim1999164\"\u003e\u003ccode\u003e@​Hashim1999164\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11082\"\u003e#11082\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/v-dev-cl\"\u003e\u003ccode\u003e@​v-dev-cl\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11091\"\u003e#11091\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0h1tb\"\u003e\u003ccode\u003e@​r0h1tb\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11118\"\u003e#11118\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ostapondo\"\u003e\u003ccode\u003e@​ostapondo\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11121\"\u003e#11121\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFull Changelog (\u003ca href=\"https://github.com/axios/axios/compare/v1.19.0...v1.20.0\"\u003ehttps://github.com/axios/axios/compare/v1.19.0...v1.20.0\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003ev1.19.0 - July 22, 2026\u003c/h2\u003e\n\u003cp\u003eThis release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMultipart Form Data: Raised the form-data dependency floor to ^4.0.6, preventing fresh installations from resolving versions affected by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (\u003ca href=\"https://github.com/advisories/GHSA-hmw2-7cc7-3qxx\"\u003ehttps://github.com/advisories/GHSA-hmw2-7cc7-3qxx\u003c/a\u003e). (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11028\"\u003e#11028\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/axios/axios/blob/v1.x/CHANGELOG.md\"\u003eaxios's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog\u003c/h1\u003e\n\u003ch2\u003ev1.19.0 — July 22, 2026\u003c/h2\u003e\n\u003cp\u003eThis release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMultipart Form Data: Raised the form-data dependency floor to ^4.0.6, preventing fresh installations from resolving versions affected by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (\u003ca href=\"https://github.com/advisories/GHSA-hmw2-7cc7-3qxx\"\u003ehttps://github.com/advisories/GHSA-hmw2-7cc7-3qxx\u003c/a\u003e). (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11028\"\u003e#11028\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚀 New Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eConfiguration Extensibility: Preserved own-enumerable symbol-keyed fields through mergeConfig and added a generic params type across public TypeScript declarations, responses, errors,\nadapters, and serializers. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11043\"\u003e#11043\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11081\"\u003e#11081\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHeader Parameter Parsing: Added the opt-in AxiosHeaders.parseParameters() parser for quote-aware, RFC-style HTTP parameter parsing while preserving legacy parsing behavior. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11051\"\u003e#11051\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHTTP Status Codes: Added the missing Cloudflare 520 WebServerReturnsAnUnknownError status and matching ESM/CJS declarations. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11067\"\u003e#11067\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eForm Data Conversion: Limited formDataToJSON path splitting to dot and bracket notation, preserving literal punctuation in keys, and removed browser-facing Buffer.from usage from toFormData to avoid unnecessary polyfills. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11006\"\u003e#11006\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11018\"\u003e#11018\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eProxy Bypass: Canonicalized IPv4 shorthand, octal, and hexadecimal forms during NO_PROXY matching and honored * entries within comma- or space-separated bypass lists. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11029\"\u003e#11029\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11053\"\u003e#11053\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eCancellation: Propagated already-aborted input signals immediately when composing abort signals. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11035\"\u003e#11035\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eHeader Handling: Preserved empty first values for duplicate singleton headers and made AxiosHeaders#getSetCookie() consistently return arrays for present values. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11036\"\u003e#11036\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11037\"\u003e#11037\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eURL Handling: Included normalized, safely redacted offending URLs in malformed-protocol errors and removed repeated trailing slashes when combining base URLs. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11008\"\u003e#11008\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11038\"\u003e#11038\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eProgress Events: Clamped malformed negative progress values to zero and ensured final Node.js download progress events are delivered before streamed responses close. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11039\"\u003e#11039\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11040\"\u003e#11040\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eError and JSON Serialization: Serialized Set values as arrays in JSON-compatible snapshots and synthesized useful AxiosError messages from otherwise-empty AggregateError instances. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11044\"\u003e#11044\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11059\"\u003e#11059\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eContent-Length Enforcement: Corrected base64 data: URL size estimation so maxContentLength is enforced consistently by the HTTP and Fetch adapters. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11061\"\u003e#11061\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSynchronous Interceptors: Prevented requests from being dispatched after synchronous request interceptors fail unless their paired rejection handler resolves successfully. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11071\"\u003e#11071\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔧 Maintenance \u0026amp; Chores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDependencies: Updated development and test tooling, the docs fixture's Axios version, and GitHub Actions integrations including Checkout, Setup Node, Setup Deno, and Zizmor. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11031\"\u003e#11031\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11055\"\u003e#11055\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11056\"\u003e#11056\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11058\"\u003e#11058\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11079\"\u003e#11079\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11080\"\u003e#11080\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11088\"\u003e#11088\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11089\"\u003e#11089\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11090\"\u003e#11090\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBuild Outputs: Limited sourcemap generation to published minified bundles, removing broken map references from non-minified builds. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11054\"\u003e#11054\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eForm Data Internals: Centralized FormData header handling and made the Node.js adapter tolerate getHeaders() returning undefined under the content-only policy. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11062\"\u003e#11062\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeveloper Experience: Ignored common local AI-tooling directories and fixed a constant-reassignment crash when the development sandbox serves its root path. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11032\"\u003e#11032\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11073\"\u003e#11073\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDocumentation: Updated sponsor information, clarified that baseURL is not a path-security boundary, scoped provenance claims to attested releases, and corrected the configuration-defaults documentation. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11041\"\u003e#11041\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11068\"\u003e#11068\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11076\"\u003e#11076\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11078\"\u003e#11078\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePublishing: Simplified v1 publishing to use the npm version bundled with Node.js 26 and updated package metadata for the 1.19.0 release. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11083\"\u003e#11083\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11095\"\u003e#11095\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🌟 New Contributors\u003c/h2\u003e\n\u003cp\u003eWe are thrilled to welcome our new contributors. Thank you for helping improve Axios:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/afonsojramos\"\u003e\u003ccode\u003e@​afonsojramos\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11028\"\u003e#11028\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11006\"\u003e#11006\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yassertawfik4\"\u003e\u003ccode\u003e@​yassertawfik4\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/1...\n\n_Description has been truncated_","html_url":"https://github.com/nonameinnameaaaa/VoiceHub/pull/13","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/nonameinnameaaaa%2FVoiceHub/issues/13","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/13/packages"},{"uuid":"5429737493","node_id":"PR_kwDOPhFD_88AAAABDNb95w","number":22,"state":"open","title":"chore(deps): bump the npm_and_yarn group across 1 directory with 14 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T23:12:14.000Z","updated_at":"2026-09-11T23:12:23.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":14,"packages":[{"name":"axios","old_version":"1.16.0","new_version":"1.18.0","repository_url":"https://github.com/axios/axios"},{"name":"postcss","old_version":"8.5.15","new_version":"8.5.28","repository_url":"https://github.com/postcss/postcss"},{"name":"vite","old_version":"7.3.2","new_version":"7.3.6","repository_url":"https://github.com/vitejs/vite"},{"name":"@babel/core","old_version":"7.28.3","new_version":"7.29.0","repository_url":"https://github.com/babel/babel"},{"name":"@humanfs/node","old_version":"0.16.6","new_version":"0.16.7","repository_url":"https://github.com/humanwhocodes/humanfs"},{"name":"brace-expansion","old_version":"2.0.2","new_version":"2.1.4","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"brace-expansion","old_version":"1.1.12","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"brace-expansion","old_version":"1.1.13","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"browserslist","old_version":"4.25.3","new_version":"4.28.1","repository_url":"https://github.com/browserslist/browserslist"},{"name":"esbuild","old_version":"0.27.7","new_version":"0.28.2","repository_url":"https://github.com/evanw/esbuild"},{"name":"fast-uri","old_version":"3.1.2","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"form-data","old_version":"4.0.5","new_version":"4.0.6","repository_url":"https://github.com/form-data/form-data"},{"name":"js-yaml","old_version":"4.1.1","new_version":"4.3.2","repository_url":"https://github.com/nodeca/js-yaml"},{"name":"postcss-selector-parser","old_version":"6.1.2","new_version":"6.1.4","repository_url":"https://github.com/postcss/postcss-selector-parser"},{"name":"shell-quote","old_version":"1.8.4","new_version":"1.10.0","repository_url":"https://github.com/ljharb/shell-quote"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 13 updates in the /src/ForexRateAlerter.Web directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [axios](https://github.com/axios/axios) | `1.16.0` | `1.18.0` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.15` | `8.5.28` |\n| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `7.3.2` | `7.3.6` |\n| [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) | `7.28.3` | `7.29.0` |\n| [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node) | `0.16.6` | `0.16.7` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `2.0.2` | `2.1.4` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.12` | `1.1.18` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.13` | `1.1.18` |\n| [browserslist](https://github.com/browserslist/browserslist) | `4.25.3` | `4.28.1` |\n| [esbuild](https://github.com/evanw/esbuild) | `0.27.7` | `0.28.2` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.2` | `3.1.7` |\n| [form-data](https://github.com/form-data/form-data) | `4.0.5` | `4.0.6` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.1` | `4.3.2` |\n| [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) | `6.1.2` | `6.1.4` |\n| [shell-quote](https://github.com/ljharb/shell-quote) | `1.8.4` | `1.10.0` |\n\n\nUpdates `axios` from 1.16.0 to 1.18.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/axios/axios/releases\"\u003eaxios's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.18.0 — June 13, 2026\u003c/h2\u003e\n\u003cp\u003eThis release hardens redirect and URL handling, improves the validateStatus configuration semantics, and includes updates to documentation, dependencies, and release metadata.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRedirect Header Safety:\u003c/strong\u003e Added Node HTTP adapter support for stripping caller-specified sensitive headers on cross-origin redirects, helping prevent custom auth headers such as API keys from leaking to another origin. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10892\"\u003e#10892\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eURL And Request Hardening:\u003c/strong\u003e Rejects malformed \u003ccode\u003ehttp:\u003c/code\u003e and \u003ccode\u003ehttps:\u003c/code\u003e URLs that omit \u003ccode\u003e//\u003c/code\u003e with \u003ccode\u003eERR_INVALID_URL\u003c/code\u003e, while tightening prototype-pollution-safe config reads, stream size limits, FormData depth handling, data URL sizing, and local \u003ccode\u003eNO_PROXY\u003c/code\u003e matching. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11000\"\u003e#11000\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eStatus Validation:\u003c/strong\u003e Added \u003ccode\u003etransitional.validateStatusUndefinedResolves\u003c/code\u003e so applications can opt in to treating \u003ccode\u003evalidateStatus: undefined\u003c/code\u003e like the option was omitted, while \u003ccode\u003evalidateStatus: null\u003c/code\u003e remains the explicit way to accept every status. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔧 Maintenance \u0026amp; Chores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDocumentation:\u003c/strong\u003e Published the v1.17.0 release notes, fixed a changelog typo, clarified the package update PR policy, and marked the \u003ccode\u003eproxy\u003c/code\u003e request config as Node.js-only in the advanced docs. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10988\"\u003e#10988\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10992\"\u003e#10992\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDependencies:\u003c/strong\u003e Bumped \u003ccode\u003e@babel/core\u003c/code\u003e, \u003ccode\u003e@babel/preset-env\u003c/code\u003e, \u003ccode\u003e@commitlint/cli\u003c/code\u003e, \u003ccode\u003e@commitlint/config-conventional\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-babel\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-commonjs\u003c/code\u003e, \u003ccode\u003e@vitest/browser\u003c/code\u003e, \u003ccode\u003e@vitest/browser-playwright\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003elint-staged\u003c/code\u003e, \u003ccode\u003erollup\u003c/code\u003e, \u003ccode\u003evitest\u003c/code\u003e, and \u003ccode\u003eactions/checkout\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10989\"\u003e#10989\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10996\"\u003e#10996\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10997\"\u003e#10997\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRelease Metadata:\u003c/strong\u003e Prepared the 1.18.0 release by updating package metadata and the runtime \u003ccode\u003eVERSION\u003c/code\u003e value. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11003\"\u003e#11003\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🌟 New Contributors\u003c/h2\u003e\n\u003cp\u003eWe are thrilled to welcome our new contributors. Thank you for helping improve axios:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/drori12\"\u003e\u003ccode\u003e@​drori12\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/eyupcanakman\"\u003e\u003ccode\u003e@​eyupcanakman\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/Adi-Beker\"\u003e\u003ccode\u003e@​Adi-Beker\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/axios/axios/compare/v1.17.0...v1.18.0\"\u003eFull Changelog\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.17.0 — June 1, 2026\u003c/h2\u003e\n\u003cp\u003eThis release adds Node HTTP zstd decompression, hardens config and release workflows, and fixes authentication, header, proxy, and type-handling regressions.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eConfig Hardening:\u003c/strong\u003e Guarded \u003ccode\u003esocketPath\u003c/code\u003e, \u003ccode\u003eparams\u003c/code\u003e, and \u003ccode\u003eparamsSerializer\u003c/code\u003e reads with own-property checks to prevent inherited prototype values from affecting request behavior, including SSRF-sensitive paths. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10901\"\u003e#10901\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10922\"\u003e#10922\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRelease Publishing:\u003c/strong\u003e Switched the publish workflow to npm staged publishing for safer, auditable package releases with provenance. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10926\"\u003e#10926\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚀 New Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eHTTP Compression:\u003c/strong\u003e Added Node HTTP adapter support for zstd response decompression, with \u003ccode\u003etransitional.advertiseZstdAcceptEncoding\u003c/code\u003e controlling whether \u003ccode\u003ezstd\u003c/code\u003e is advertised in \u003ccode\u003eAccept-Encoding\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/6792\"\u003e#6792\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10920\"\u003e#10920\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eAuthentication Handling:\u003c/strong\u003e Restored Basic auth on same-origin Node redirects while continuing to strip credentials cross-origin, and aligned the fetch adapter with HTTP adapter behavior for URL-embedded Basic auth. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10929\"\u003e#10929\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10896\"\u003e#10896\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eProxy TLS:\u003c/strong\u003e Preserved user \u003ccode\u003ehttpsAgent\u003c/code\u003e TLS options when tunneling HTTPS requests through HTTP CONNECT proxies. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10957\"\u003e#10957\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReact Native FormData:\u003c/strong\u003e Cleared default \u003ccode\u003eContent-Type\u003c/code\u003e for React Native \u003ccode\u003eFormData\u003c/code\u003e so multipart boundaries can be generated correctly. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10898\"\u003e#10898\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/axios/axios/blob/v1.x/CHANGELOG.md\"\u003eaxios's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.18.0 — June 13, 2026\u003c/h2\u003e\n\u003cp\u003eThis release hardens redirect and URL handling, improves the validateStatus configuration semantics, and includes updates to documentation, dependencies, and release metadata.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRedirect Header Safety:\u003c/strong\u003e Added Node HTTP adapter support for stripping caller-specified sensitive headers on cross-origin redirects, helping prevent custom auth headers such as API keys from leaking to another origin. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10892\"\u003e#10892\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eURL And Request Hardening:\u003c/strong\u003e Rejects malformed \u003ccode\u003ehttp:\u003c/code\u003e and \u003ccode\u003ehttps:\u003c/code\u003e URLs that omit \u003ccode\u003e//\u003c/code\u003e with \u003ccode\u003eERR_INVALID_URL\u003c/code\u003e, while tightening prototype-pollution-safe config reads, stream size limits, FormData depth handling, data URL sizing, and local \u003ccode\u003eNO_PROXY\u003c/code\u003e matching. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11000\"\u003e#11000\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eStatus Validation:\u003c/strong\u003e Added \u003ccode\u003etransitional.validateStatusUndefinedResolves\u003c/code\u003e so applications can opt in to treating \u003ccode\u003evalidateStatus: undefined\u003c/code\u003e like the option was omitted, while \u003ccode\u003evalidateStatus: null\u003c/code\u003e remains the explicit way to accept every status. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔧 Maintenance \u0026amp; Chores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDocumentation:\u003c/strong\u003e Published the v1.17.0 release notes, fixed a changelog typo, clarified the package update PR policy, and marked the \u003ccode\u003eproxy\u003c/code\u003e request config as Node.js-only in the advanced docs. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10988\"\u003e#10988\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10992\"\u003e#10992\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDependencies:\u003c/strong\u003e Bumped \u003ccode\u003e@babel/core\u003c/code\u003e, \u003ccode\u003e@babel/preset-env\u003c/code\u003e, \u003ccode\u003e@commitlint/cli\u003c/code\u003e, \u003ccode\u003e@commitlint/config-conventional\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-babel\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-commonjs\u003c/code\u003e, \u003ccode\u003e@vitest/browser\u003c/code\u003e, \u003ccode\u003e@vitest/browser-playwright\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003elint-staged\u003c/code\u003e, \u003ccode\u003erollup\u003c/code\u003e, \u003ccode\u003evitest\u003c/code\u003e, and \u003ccode\u003eactions/checkout\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10989\"\u003e#10989\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10996\"\u003e#10996\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10997\"\u003e#10997\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRelease Metadata:\u003c/strong\u003e Prepared the 1.18.0 release by updating package metadata and the runtime \u003ccode\u003eVERSION\u003c/code\u003e value. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11003\"\u003e#11003\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🌟 New Contributors\u003c/h2\u003e\n\u003cp\u003eWe are thrilled to welcome our new contributors. Thank you for helping improve axios:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/drori12\"\u003e\u003ccode\u003e@​drori12\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/eyupcanakman\"\u003e\u003ccode\u003e@​eyupcanakman\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/Adi-Beker\"\u003e\u003ccode\u003e@​Adi-Beker\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/axios/axios/compare/v1.17.0...v1.18.0\"\u003eFull Changelog\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.17.0 — June 1, 2026\u003c/h2\u003e\n\u003cp\u003eThis release adds Node HTTP zstd decompression, hardens config and release workflows, and fixes authentication, header, proxy, and type-handling regressions.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eConfig Hardening:\u003c/strong\u003e Guarded \u003ccode\u003esocketPath\u003c/code\u003e, \u003ccode\u003eparams\u003c/code\u003e, and \u003ccode\u003eparamsSerializer\u003c/code\u003e reads with own-property checks to prevent inherited prototype values from affecting request behavior, including SSRF-sensitive paths. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10901\"\u003e#10901\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10922\"\u003e#10922\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRelease Publishing:\u003c/strong\u003e Switched the publish workflow to npm staged publishing for safer, auditable package releases with provenance. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10926\"\u003e#10926\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚀 New Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eHTTP Compression:\u003c/strong\u003e Added Node HTTP adapter support for zstd response decompression, with \u003ccode\u003etransitional.advertiseZstdAcceptEncoding\u003c/code\u003e controlling whether \u003ccode\u003ezstd\u003c/code\u003e is advertised in \u003ccode\u003eAccept-Encoding\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/6792\"\u003e#6792\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10920\"\u003e#10920\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eAuthentication Handling:\u003c/strong\u003e Restored Basic auth on same-origin Node redirects while continuing to strip credentials cross-origin, and aligned the fetch adapter with HTTP adapter behavior for URL-embedded Basic auth. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10929\"\u003e#10929\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10896\"\u003e#10896\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eProxy TLS:\u003c/strong\u003e Preserved user \u003ccode\u003ehttpsAgent\u003c/code\u003e TLS options when tunneling HTTPS requests through HTTP CONNECT proxies. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10957\"\u003e#10957\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReact Native FormData:\u003c/strong\u003e Cleared default \u003ccode\u003eContent-Type\u003c/code\u003e for React Native \u003ccode\u003eFormData\u003c/code\u003e so multipart boundaries can be generated correctly. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10898\"\u003e#10898\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/2d06f96e8602c2db13b65a26340ee4a1bbc0b61f\"\u003e\u003ccode\u003e2d06f96\u003c/code\u003e\u003c/a\u003e chore(release): prepare release 1.18.0 (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11003\"\u003e#11003\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/32fc489632377d214db55bfa4e2c48486a7d7ce2\"\u003e\u003ccode\u003e32fc489\u003c/code\u003e\u003c/a\u003e fix: malformed http urls (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11000\"\u003e#11000\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/b40ce498abfa10d90b873b4fd08f520afa5d2545\"\u003e\u003ccode\u003eb40ce49\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump the development_dependencies group with 10 updates (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10\"\u003e#10\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/fe964f960ecb52c3e1155b0daf7be77541956b01\"\u003e\u003ccode\u003efe964f9\u003c/code\u003e\u003c/a\u003e docs: mark proxy config as Node.js only (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/5f229d2d1f018d1db3dab6bbe034dbf3f9041b99\"\u003e\u003ccode\u003e5f229d2\u003c/code\u003e\u003c/a\u003e chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/fae9d4e7db6a858c407c75e607a071c533c5c4f6\"\u003e\u003ccode\u003efae9d4e\u003c/code\u003e\u003c/a\u003e docs: clarify package update PR policy (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10992\"\u003e#10992\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/28ab2ced820e55192806c53472ab3eb0cbb68dc2\"\u003e\u003ccode\u003e28ab2ce\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump the development_dependencies group with 2 updates (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10989\"\u003e#10989\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/a8e4f13aeecc45a3b8fab3ecfd9ddb5d70fb772b\"\u003e\u003ccode\u003ea8e4f13\u003c/code\u003e\u003c/a\u003e fix(core): keep default validateStatus when request passes undefined (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/614f4552a17de757d4171ad7c3bd38c9c1025fd8\"\u003e\u003ccode\u003e614f455\u003c/code\u003e\u003c/a\u003e docs: publish v1.17.0 release notes (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10988\"\u003e#10988\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/6bb12c191f5380fad321322fb90216ae0dc36985\"\u003e\u003ccode\u003e6bb12c1\u003c/code\u003e\u003c/a\u003e fix: custom auth headers not stripped on cross-origin redirects (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10892\"\u003e#10892\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/axios/axios/compare/v1.16.0...v1.18.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.15 to 8.5.28\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.28\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes types regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed removing any comments starting with \u003ccode\u003e/*#\u003c/code\u003e (by \u003ca href=\"https://github.com/dylanpulver\"\u003e\u003ccode\u003e@​dylanpulver\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e*\u003c/code\u003e hack before a comment in Custom Properties (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed empty values in the middle of \u003ccode\u003elist.comma()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed whitespace-only values in \u003ccode\u003elist.space()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed rule’s end position on space before semicolon (by \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/romainmenke\"\u003e\u003ccode\u003e@​romainmenke\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed Chinese text in deprecation warning (by \u003ca href=\"https://github.com/Jesse205\"\u003e\u003ccode\u003e@​Jesse205\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.28\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes types regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed removing any comments starting with \u003ccode\u003e/*#\u003c/code\u003e (by \u003ca href=\"https://github.com/dylanpulver\"\u003e\u003ccode\u003e@​dylanpulver\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e*\u003c/code\u003e hack before a comment in Custom Properties (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed empty values in the middle of \u003ccode\u003elist.comma()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed whitespace-only values in \u003ccode\u003elist.space()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed rule’s end position on space before semicolon (by \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/romainmenke\"\u003e\u003ccode\u003e@​romainmenke\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed Chinese text in deprecation warning (by \u003ca href=\"https://github.com/Jesse205\"\u003e\u003ccode\u003e@​Jesse205\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/e544bffc4f4b3966d8ec69c41744b3ed65afc64a\"\u003e\u003ccode\u003ee544bff\u003c/code\u003e\u003c/a\u003e Release 8.5.28 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f8fc2525717a6a7216659f7be43c525f60c6a15a\"\u003e\u003ccode\u003ef8fc252\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/5039fd78962d285abea5d7b3aebef32f053781ce\"\u003e\u003ccode\u003e5039fd7\u003c/code\u003e\u003c/a\u003e Add missed release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/ae40ca499cf6a9afdbb264c0ec09e71fe934e2af\"\u003e\u003ccode\u003eae40ca4\u003c/code\u003e\u003c/a\u003e Release 8.5.27 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/62b1626bb7fbb28eda616d002cbd525d239b18ba\"\u003e\u003ccode\u003e62b1626\u003c/code\u003e\u003c/a\u003e Fix linter\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/1dba9384515a2dbc64517697c2f738b6d5c3f9a4\"\u003e\u003ccode\u003e1dba938\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3e82edc9f037faa41647342dceceba9b841f9881\"\u003e\u003ccode\u003e3e82edc\u003c/code\u003e\u003c/a\u003e Keep non-annotation comments when the processor has no plugins (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2150\"\u003e#2150\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/6d23bc362203118478bc8051b81f2910907ebe6e\"\u003e\u003ccode\u003e6d23bc3\u003c/code\u003e\u003c/a\u003e Fix link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/508e9976be81536292e7666741e1c35e876b9a6a\"\u003e\u003ccode\u003e508e997\u003c/code\u003e\u003c/a\u003e Add GitHub Sponsors link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/e993739dc49b6055f7dfc59b161d75702f0b2b8b\"\u003e\u003ccode\u003ee993739\u003c/code\u003e\u003c/a\u003e Add CodeRabbit sponsor (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2145\"\u003e#2145\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.15...8.5.28\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `vite` from 7.3.2 to 7.3.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/releases\"\u003evite's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.3.6\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.6/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.3.5\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.5/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.3.3\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.3/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.6/packages/vite/CHANGELOG.md\"\u003evite's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.5...v7.3.6\"\u003e7.3.6\u003c/a\u003e (2026-06-25)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eallow esbuild 0.28 (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22743\"\u003e#22743\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/a24931e7934e80eff5895b89d9e612ad3ad3e1f4\"\u003ea24931e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.3...v7.3.5\"\u003e7.3.5\u003c/a\u003e (2026-06-01)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ebackport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22572\"\u003e#22572\u003c/a\u003e, reject windows alternate paths (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22574\"\u003e#22574\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8c1855607b7c9884c4565d897ee98899a008a2d0\"\u003e8c18556\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e backport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22571\"\u003e#22571\u003c/a\u003e, reject UNC paths for launch-editor-middleware (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22573\"\u003e#22573\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/f20d64bef6e0ef1e4fa7a9783281c7bba0ce5292\"\u003ef20d64b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMiscellaneous Chores\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eskip v7.3.4 release (\u003ca href=\"https://github.com/vitejs/vite/commit/8a6a0c9fc734dbfe293ac33a4954506ee50430e1\"\u003e8a6a0c9\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.3...v7.3.4\"\u003e7.3.4\u003c/a\u003e (2026-06-01)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ebackport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22572\"\u003e#22572\u003c/a\u003e, reject windows alternate paths (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22574\"\u003e#22574\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8c1855607b7c9884c4565d897ee98899a008a2d0\"\u003e8c18556\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e backport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22571\"\u003e#22571\u003c/a\u003e, reject UNC paths for launch-editor-middleware (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22573\"\u003e#22573\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/f20d64bef6e0ef1e4fa7a9783281c7bba0ce5292\"\u003ef20d64b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.2...v7.3.3\"\u003e7.3.3\u003c/a\u003e (2026-05-07)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eavoid destructure lowering for newer safari (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22346\"\u003e#22346\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/5ab51c0f76f0896175e02ad797c1f5fe116d02f4\"\u003e5ab51c0\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/0a7b53ba230c6e68f502a89864534c607d393ab7\"\u003e\u003ccode\u003e0a7b53b\u003c/code\u003e\u003c/a\u003e release: v7.3.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/a24931e7934e80eff5895b89d9e612ad3ad3e1f4\"\u003e\u003ccode\u003ea24931e\u003c/code\u003e\u003c/a\u003e feat: allow esbuild 0.28 (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22743\"\u003e#22743\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/077945cb60df372a52cf999b6e532ba70fac7423\"\u003e\u003ccode\u003e077945c\u003c/code\u003e\u003c/a\u003e release: v7.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/8a6a0c9fc734dbfe293ac33a4954506ee50430e1\"\u003e\u003ccode\u003e8a6a0c9\u003c/code\u003e\u003c/a\u003e chore: skip v7.3.4 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/8c1855607b7c9884c4565d897ee98899a008a2d0\"\u003e\u003ccode\u003e8c18556\u003c/code\u003e\u003c/a\u003e fix: backport \u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22572\"\u003e#22572\u003c/a\u003e, reject windows alternate paths (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22574\"\u003e#22574\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/f20d64bef6e0ef1e4fa7a9783281c7bba0ce5292\"\u003e\u003ccode\u003ef20d64b\u003c/code\u003e\u003c/a\u003e fix(deps): backport \u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22571\"\u003e#22571\u003c/a\u003e, reject UNC paths for launch-editor-middleware (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/2\"\u003e#2\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/ca31424cccb075c88131132b929a63527d0e2b69\"\u003e\u003ccode\u003eca31424\u003c/code\u003e\u003c/a\u003e release: v7.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/5ab51c0f76f0896175e02ad797c1f5fe116d02f4\"\u003e\u003ccode\u003e5ab51c0\u003c/code\u003e\u003c/a\u003e fix: avoid destructure lowering for newer safari (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22346\"\u003e#22346\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/vitejs/vite/commits/v7.3.6/packages/vite\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@babel/core` from 7.28.3 to 7.29.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/babel/babel/releases\"\u003e@​babel/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0 (2026-01-31)\u003c/h2\u003e\n\u003cp\u003eThanks \u003ca href=\"https://github.com/simbahax\"\u003e\u003ccode\u003e@​simbahax\u003c/code\u003e\u003c/a\u003e for your first PR!\u003c/p\u003e\n\u003ch4\u003e:rocket: New Feature\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-types\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17750\"\u003e#17750\u003c/a\u003e [7.x backport] Add attributes import declaration builder (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-standalone\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17663\"\u003e#17663\u003c/a\u003e [7.x backport] feat(standalone): export async transform (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17725\"\u003e#17725\u003c/a\u003e [7.x backport] feat: read standalone targets from data-targets (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17765\"\u003e#17765\u003c/a\u003e fix(parser): correctly parse type assertions in \u003ccode\u003eextends\u003c/code\u003e clause (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17723\"\u003e#17723\u003c/a\u003e [7.x backport] fix(parser): improve super type argument parsing (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-traverse\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17708\"\u003e#17708\u003c/a\u003e fix(traverse): provide a hub when traversing a File or Program and no parentPath is given (\u003ca href=\"https://github.com/simbahax\"\u003e\u003ccode\u003e@​simbahax\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-transform-block-scoping\u003c/code\u003e, \u003ccode\u003ebabel-traverse\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17737\"\u003e#17737\u003c/a\u003e [7.x backport] fix: Rename switch discriminant references when body creates shadowing variable (\u003ca href=\"https://github.com/magic-akari\"\u003e\u003ccode\u003e@​magic-akari\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:running_woman: Performance\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e, \u003ccode\u003ebabel-runtime-corejs3\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17642\"\u003e#17642\u003c/a\u003e [Babel 7] Improve generator performance (\u003ca href=\"https://github.com/liuxingbaoyu\"\u003e\u003ccode\u003e@​liuxingbaoyu\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 6\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eDavid (\u003ca href=\"https://github.com/simbahax\"\u003e\u003ccode\u003e@​simbahax\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/liuxingbaoyu\"\u003e\u003ccode\u003e@​liuxingbaoyu\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/magic-akari\"\u003e\u003ccode\u003e@​magic-akari\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.28.6 (2026-01-12)\u003c/h2\u003e\n\u003cp\u003eThanks \u003ca href=\"https://github.com/kadhirash\"\u003e\u003ccode\u003e@​kadhirash\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/kolvian\"\u003e\u003ccode\u003e@​kolvian\u003c/code\u003e\u003c/a\u003e for your first PRs!\u003c/p\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-cli\u003c/code\u003e, \u003ccode\u003ebabel-code-frame\u003c/code\u003e, \u003ccode\u003ebabel-core\u003c/code\u003e, \u003ccode\u003ebabel-helper-check-duplicate-nodes\u003c/code\u003e, \u003ccode\u003ebabel-helper-fixtures\u003c/code\u003e, \u003ccode\u003ebabel-helper-plugin-utils\u003c/code\u003e, \u003ccode\u003ebabel-node\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-flow-comments\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-modules-commonjs\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-property-mutators\u003c/code\u003e, \u003ccode\u003ebabel-preset-env\u003c/code\u003e, \u003ccode\u003ebabel-traverse\u003c/code\u003e, \u003ccode\u003ebabel-types\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17589\"\u003e#17589\u003c/a\u003e Improve Unicode handling in code-frame tokenizer (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-transform-regenerator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17556\"\u003e#17556\u003c/a\u003e fix: \u003ccode\u003etransform-regenerator\u003c/code\u003e correctly handles scope (\u003ca href=\"https://github.com/liuxingbaoyu\"\u003e\u003ccode\u003e@​liuxingbaoyu\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-transform-react-jsx\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17538\"\u003e#17538\u003c/a\u003e fix: Keep jsx comments (\u003ca href=\"https://github.com/liuxingbaoyu\"\u003e\u003ccode\u003e@​liuxingbaoyu\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:nail_care: Polish\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e, \u003ccode\u003ebabel-standalone\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17606\"\u003e#17606\u003c/a\u003e Polish(standalone): improve message on invalid preset/plugin (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:house: Internal\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-bugfix-v8-static-class-fields-redefine-readonly\u003c/code\u003e, \u003ccode\u003ebabel-plugin-proposal-decorators\u003c/code\u003e, \u003ccode\u003ebabel-plugin-proposal-import-attributes-to-assertions\u003c/code\u003e, \u003ccode\u003ebabel-plugin-proposal-import-wasm-source\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-async-do-expressions\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-decorators\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-destructuring-private\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-do-expressions\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-explicit-resource-management\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-export-default-from\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-flow\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-function-bind\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-function-sent\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-import-assertions\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-import-attributes\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-import-defer\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-import-source\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-jsx\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-module-blocks\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-optional-chaining-assign\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-partial-application\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-pipeline-operator\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-throw-expressions\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-typescript\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-async-generator-functions\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-async-to-generator\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-class-properties\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-class-static-block\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-dotall-regex\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-duplicate-named-capturing-groups-regex\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-explicit-resource-management\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-exponentiation-operator\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-json-strings\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-logical-assignment-operators\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-nullish-coalescing-operator\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-numeric-separator\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-object-rest-spread\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-optional-catch-binding\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-optional-chaining\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-private-methods\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-private-property-in-object\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-regexp-modifiers\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-unicode-property-regex\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-unicode-sets-regex\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17580\"\u003e#17580\u003c/a\u003e Allow Babel 8 in compatible Babel 7 plugins (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/aa8394e454337d118ac3d40bfa3ee1a3cb3f3ed2\"\u003e\u003ccode\u003eaa8394e\u003c/code\u003e\u003c/a\u003e v7.29.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/ad0d03f0c92404a60ec6b1c12f15febd38e2397a\"\u003e\u003ccode\u003ead0d03f\u003c/code\u003e\u003c/a\u003e [7.x backport] feat: Allow specifying startLine in code frame (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17739\"\u003e#17739\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/d7f400889567ae18ef9ac41b024b5120f6060e17\"\u003e\u003ccode\u003ed7f4008\u003c/code\u003e\u003c/a\u003e v7.28.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/e130225028e93e106135586f344cfa44c4aac847\"\u003e\u003ccode\u003ee130225\u003c/code\u003e\u003c/a\u003e Polish(standalone): improve message on invalid preset/plugin (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17606\"\u003e#17606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/99dcba5e71de3bd81ce14077cfa5b6df58e9b177\"\u003e\u003ccode\u003e99dcba5\u003c/code\u003e\u003c/a\u003e chore: enable some ts-eslint rules (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17592\"\u003e#17592\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/c92c4919771105140015167f25f7bacac77c90d9\"\u003e\u003ccode\u003ec92c491\u003c/code\u003e\u003c/a\u003e Improve Unicode handling in code-frame tokenizer (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17589\"\u003e#17589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/d725e399fd6a4da463cff4918cf71aa03b8beb14\"\u003e\u003ccode\u003ed725e39\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003eBABEL_7_TO_8_DANGEROUSLY_DISABLE_VERSION_CHECK\u003c/code\u003e (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17569\"\u003e#17569\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/c1b55f6ad56523ccc96fa68721de0bed2f2cdb23\"\u003e\u003ccode\u003ec1b55f6\u003c/code\u003e\u003c/a\u003e Use \u003ccode\u003eeslint.config.mts\u003c/code\u003e (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17573\"\u003e#17573\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/61647ae2397c82c3c71f077b5ab109106a5cac0f\"\u003e\u003ccode\u003e61647ae\u003c/code\u003e\u003c/a\u003e v7.28.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/42cb285b59fc99a8102d69bef6223b75617e9f46\"\u003e\u003ccode\u003e42cb285\u003c/code\u003e\u003c/a\u003e Improve \u003ccode\u003e@babel/core\u003c/code\u003e types (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17404\"\u003e#17404\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/babel/babel/commits/v7.29.0/packages/babel-core\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​babel/core\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@humanfs/node` from 0.16.6 to 0.16.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/humanwhocodes/humanfs/releases\"\u003e@​humanfs/node's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003enode: v0.16.7\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/compare/node-v0.16.6...node-v0.16.7\"\u003e0.16.7\u003c/a\u003e (2024-11-27)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd directory to package.json (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/f691b60a0df2ce9a5894b6af51acc2461654cf6b\"\u003ef691b60\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/humanwhocodes/humanfs/blob/main/packages/node/CHANGELOG.md\"\u003e@​humanfs/node's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/compare/node-v0.16.6...node-v0.16.7\"\u003e0.16.7\u003c/a\u003e (2024-11-27)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd directory to package.json (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/f691b60a0df2ce9a5894b6af51acc2461654cf6b\"\u003ef691b60\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/257b7b53eb2800daca06453ea385f9f2a098fcb9\"\u003e\u003ccode\u003e257b7b5\u003c/code\u003e\u003c/a\u003e chore: release main (\u003ca href=\"https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node/issues/142\"\u003e#142\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/f691b60a0df2ce9a5894b6af51acc2461654cf6b\"\u003e\u003ccode\u003ef691b60\u003c/code\u003e\u003c/a\u003e fix: Add directory to package.json\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/7b81d9accf36bed41883e5e0c2eaaefce8c15fee\"\u003e\u003ccode\u003e7b81d9a\u003c/code\u003e\u003c/a\u003e chore(deps): Upgrading retry dependency in node package. (\u003ca href=\"https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node/issues/140\"\u003e#140\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/humanwhocodes/humanfs/commits/node-v0.16.7/packages/node\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 2.0.2 to 2.1.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.1.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v2 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/109\"\u003e#109\u003c/a\u003e)  c3a817c\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v2.1.0...v2.1.1\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v2.1.0...v2.1.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/b25213dff0446d622f97d736420b9830ee1abc32\"\u003e\u003ccode\u003eb25213d\u003c/code\u003e\u003c/a\u003e 2.1.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac\"\u003e\u003ccode\u003e1e30c93\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/878df3989e816dfb28cbe0d64de0b88738ff0ed6\"\u003e\u003ccode\u003e878df39\u003c/code\u003e\u003c/a\u003e 2.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/c8bd93cfff4e45cb295557d2be17e1d1d4e52a11\"\u003e\u003ccode\u003ec8bd93c\u003c/code\u003e\u003c/a\u003e npm ignore .claude\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d13ff455a58b0d56704f0111e3c2a0b16ceb06eb\"\u003e\u003ccode\u003ed13ff45\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/130\"\u003e#130\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/9e67a3b151e418679ac4800f31f874ec6d220b4a\"\u003e\u003ccode\u003e9e67a3b\u003c/code\u003e\u003c/a\u003e 2.1.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/835d6be91201122d9adffb0c0c8c094189ace265\"\u003e\u003ccode\u003e835d6be\u003c/code\u003e\u003c/a\u003e fix: v2 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/123\"\u003e#123\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/64b71d31d7c43b956ce64fccc1dda5a3729be728\"\u003e\u003ccode\u003e64b71d3\u003c/code\u003e\u003c/a\u003e 2.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/c3a817c8e5421d19a37c9babcf3f216b6bf2e6b4\"\u003e\u003ccode\u003ec3a817c\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v2 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/109\"\u003e#109\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/1ee4a9069c69a51bd502aab289c0c6629c8920ca\"\u003e\u003ccode\u003e1ee4a90\u003c/code\u003e\u003c/a\u003e 2.1.0\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v2.0.2...v2.1.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.12 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.1.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v2 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/109\"\u003e#109\u003c/a\u003e)  c3a817c\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v2.1.0...v2.1.1\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v2.1.0...v2.1.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/b25213dff0446d622f97d736420b9830ee1abc32\"\u003e\u003ccode\u003eb25213d\u003c/code\u003e\u003c/a\u003e 2.1.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac\"\u003e\u003ccode\u003e1e30c93\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/878df3989e816dfb28cbe0d64de0b88738ff0ed6\"\u003e\u003ccode\u003e878df39\u003c/code\u003e\u003c/a\u003e 2.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/c8bd93cfff4e45cb295557d2be17e1d1d4e52a11\"\u003e\u003ccode\u003ec8bd93c\u003c/code\u003e\u003c/a\u003e npm ignore .claude\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d13ff455a58b0d56704f0111e3c2a0b16ceb06eb\"\u003e\u003ccode\u003ed13ff45\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/130\"\u003e#130\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/9e67a3b151e418679ac4800f31f874ec6d220b4a\"\u003e\u003ccode\u003e9e67a3b\u003c/code\u003e\u003c/a\u003e 2.1.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/835d6be91201122d9adffb0c0c8c094189ace265\"\u003e\u003ccode\u003e835d6be\u003c/code\u003e\u003c/a\u003e fix: v2 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/123\"\u003e#123\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/64b71d31d7c43b956ce64fccc1dda5a3729be728\"\u003e\u003ccode\u003e64b71d3\u003c/code\u003e\u003c/a\u003e 2.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/c3a817c8e5421d19a37c9babcf3f216b6bf2e6b4\"\u003e\u003ccode\u003ec3a817c\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v2 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/109\"\u003e#109\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/1ee4a9069c69a51bd502aab289c0c6629c8920ca\"\u003e\u003ccode\u003e1ee4a90\u003c/code\u003e\u003c/a\u003e 2.1.0\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v2.0.2...v2.1.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.13 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.1.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v2 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/109\"\u003e#109\u003c/a\u003e)  c3a817c\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v2.1.0...v2.1.1\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v2.1.0...v2.1.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/b25213dff0446d622f97d736420b9830ee1abc32\"\u003e\u003ccode\u003eb25213d\u003c/code\u003e\u003c/a\u003e 2.1.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac\"\u003e\u003ccode\u003e1e30c93\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/878df3989e816dfb28cbe0d64de0b88738ff0ed6\"\u003e\u003ccode\u003e878df39\u003c/code\u003e\u003c/a\u003e 2.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/c8bd93cfff4e45cb295557d2be17e1d1d4e52a11\"\u003e\u003ccode\u003ec8bd93c\u003c/code\u003e\u003c/a\u003e npm ignore .claude\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d13ff455a58b0d56704f0111e3c2a0b16ceb06eb\"\u003e\u003ccode\u003ed13ff45\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/130\"\u003e#130\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/9e67a3b151e418679ac4800f31f874ec6d220b4a\"\u003e\u003ccode\u003e9e67a3b\u003c/code\u003e\u003c/a\u003e 2.1.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/835d6be91201122d9adffb0c0c8c094189ace265\"\u003e\u003ccode\u003e835d6be\u003c/code\u003e\u003c/a\u003e fix: v2 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/123\"\u003e#123\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/64b71d31d7c43b956ce64fccc1dda5a3729be728\"\u003e\u003ccode\u003e64b71d3\u003c/code\u003e\u003c/a\u003e 2.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/c3a817c8e5421d19a37c9babcf3f216b6bf2e6b4\"\u003e\u003ccode\u003ec3a817c\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v2 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/109\"\u003e#109\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/1ee4a9069c69a51bd502aab289c0c6629c8920ca\"\u003e\u003ccode\u003e1ee4a90\u003c/code\u003e\u003c/a\u003e 2.1.0\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v2.0.2...v2.1.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `browserslist` from 4.25.3 to 4.28.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/releases\"\u003ebrowserslist's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved Baseline warning since we have it own warning.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.27.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003eBROWSERSLIST_TRACE_WARNING\u003c/code\u003e environment variable.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003ethrowOnMissing\u003c/code\u003e with \u003ccode\u003eextends\u003c/code\u003e query (by \u003ca href=\"https://github.com/alexander-akait\"\u003e\u003ccode\u003e@​alexander-akait\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003ebaseline-browser-mapping\u003c/code\u003e version requirement.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated Firefox ESR.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded Baseline queries (by \u003ca href=\"https://github.com/tonypconway\"\u003e\u003ccode\u003e@​tonypconway\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.25.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Windows support for custom stats (by \u003ca href=\"https://github.com/torgeilo\"\u003e\u003ccode\u003e@​torgeilo\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md\"\u003ebrowserslist's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved Baseline warning since we have it own warning.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.48.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003efirefox \u0026gt;= esr\u003c/code\u003e query support (by \u003ca href=\"https://github.com/SethFalco\"\u003e\u003ccode\u003e@​SethFalco\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/SethFalco\"\u003e\u003ccode\u003e@​SethFalco\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.27.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003eBROWSERSLIST_TRACE_WARNING\u003c/code\u003e environment variable.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003ethrowOnMissing\u003c/code\u003e with \u003ccode\u003eextends\u003c/code\u003e query (by \u003ca href=\"https://github.com/alexander-akait\"\u003e\u003ccode\u003e@​alexander-akait\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003ebaseline-browser-mapping\u003c/code\u003e version requirement.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated Firefox ESR.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded Baseline queries (by \u003ca href=\"https://github.com/tonypconway\"\u003e\u003ccode\u003e@​tonypconway\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.25.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Windows support for custom stats (by \u003ca href=\"https://github.com/torgeilo\"\u003e\u003ccode\u003e@​torgeilo\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/5cad191bc1a1e5beb7768ca263503cc15d0dcc7d\"\u003e\u003ccode\u003e5cad191\u003c/code\u003e\u003c/a\u003e Release 4.28.1 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/592e11969e5ba65ec1d71ded09c2404e2cdc41a2\"\u003e\u003ccode\u003e592e119\u003c/code\u003e\u003c/a\u003e Update dependencies to use new baseline library with a way to supress warning\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/dc1ea132f4922164eb4d649db5a1c50d38f0de01\"\u003e\u003ccode\u003edc1ea13\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/bb4fcc6d0317352597354135fde12262402a38bf\"\u003e\u003ccode\u003ebb4fcc6\u003c/code\u003e\u003c/a\u003e Fix link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/67a7b669b385812c6f9a45aa79eacfcb5f1b1581\"\u003e\u003ccode\u003e67a7b66\u003c/code\u003e\u003c/a\u003e Add browserslist-plausible link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/a4006b0c324b081971acf3367780660f8e4ddb23\"\u003e\u003ccode\u003ea4006b0\u003c/code\u003e\u003c/a\u003e Release 4.28.0 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/5644b5e8272e4af1b5e8ef1cd6df805975b04ccb\"\u003e\u003ccode\u003e5644b5e\u003c/code\u003e\u003c/a\u003e Update dependencies and add Multiocular to track changes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/90721c859e78f4cc311db39e11afb7042e279470\"\u003e\u003ccode\u003e90721c8\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/browserslist/browserslist/issues/909\"\u003e#909\u003c/a\u003e from SethFalco/esr-range\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/98d83747223c88c98e424e086a83dec50152bfe5\"\u003e\u003ccode\u003e98d8374\u003c/code\u003e\u003c/a\u003e feat: allow esr alias in firefox version ranges\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/436f4600a7bcab8e80ff6dd43f9f3b08f6273eec\"\u003e\u003ccode\u003e436f460\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/browserslist/browserslist/issues/910\"\u003e#910\u003c/a\u003e from SethFalco/docs\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/browserslist/browserslist/compare/4.25.3...4.28.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `esbuild` from 0.27.7 to 0.28.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/evanw/esbuild/releases\"\u003eesbuild's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.28.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix tree shaking bug due to TypeScript import alias (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4507\"\u003e#4507\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific \u003ccode\u003eimport\u003c/code\u003e assignment and looks something like this:\u003c/p\u003e\n\u003cpre lang=\"ts\"\u003e\u003ccode\u003eimport Base from './dep.js';\r\nimport Alias = Base.SomeType;\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix CSS minification bug involving \u003ccode\u003e\u0026amp;\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4497\"\u003e#4497\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug where esbuild's CSS minifier incorrectly removed a \u003ccode\u003e\u0026amp;\u003c/code\u003e when it was unsafe to do so. Here is an example:\u003c/p\u003e\n\u003cpre lang=\"css\"\u003e\u003ccode\u003e/* Original code */\r\n.a .b {\r\n  \u0026amp; .b:not(\u0026amp; .c) {\r\n    color: red;\r\n  }\r\n}\r\n\u003cp\u003e/* Old output (with --minify) */\u003cbr /\u003e\n.a .b{.b:not(\u0026amp; .c){color:red}}\u003c/p\u003e\n\u003cp\u003e/* New output (with --minify) */\u003cbr /\u003e\n.a .b{\u0026amp; .b:not(\u0026amp; .c){color:red}}\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eThis should match \u003ccode\u003e\u0026lt;span class=\u0026quot;a\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;yes\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u003c/code\u003e but not \u003ccode\u003e\u0026lt;span class=\u0026quot;a\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;no\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u003c/code\u003e. The old output incorrectly matched both.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAvoid overwriting input files without \u003ccode\u003e--allow-overwrite\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4484\"\u003e#4484\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eFor example: \u003ccode\u003eesbuild input.js --outfile=input.js\u003c/code\u003e tells esbuild to overwrite \u003ccode\u003einput.js\u003c/code\u003e with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.\u003c/p\u003e\n\u003cp\u003eThis release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless \u003ccode\u003e--allow-overwrite\u003c/code\u003e is explicitly present. This is done by not writing out any files when a build error is encountered.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix incorrect code generated when using top-level await (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4498\"\u003e#4498\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003ePreviously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing \u003ccode\u003easync\u003c/code\u003e on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an \u003ccode\u003easync\u003c/code\u003e module wrapper.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix a minification bug with lowered logical assignment operators (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4508\"\u003e#4508\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Original code\r\nfunction foo() {\r\n  let x\r\n  bar(x ||= {})\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/evanw/esbuild/blob/main/CHANGELOG.md\"\u003eesbuild's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.28.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix tree shaking bug due to TypeScript import alias (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4507\"\u003e#4507\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific \u003ccode\u003eimport\u003c/code\u003e assignment and looks something like this:\u003c/p\u003e\n\u003cpre lang=\"ts\"\u003e\u003ccode\u003eimport Base from './dep.js';\nimport Alias = Base.SomeType;\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix CSS minification bug involving \u003ccode\u003e\u0026amp;\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4497\"\u003e#4497\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug where esbuild's CSS minifier incorrectly removed a \u003ccode\u003e\u0026amp;\u003c/code\u003e when it was unsafe to do so. Here is an example:\u003c/p\u003e\n\u003cpre lang=\"css\"\u003e\u003ccode\u003e/* Original code */\n.a .b {\n  \u0026amp; .b:not(\u0026amp; .c) {\n    color: red;\n  }\n}\n\u003cp\u003e/* Old output (with --minify) */\u003cbr /\u003e\n.a .b{.b:not(\u0026amp; .c){color:red}}\u003c/p\u003e\n\u003cp\u003e/* New output (with --minify) */\u003cbr /\u003e\n.a .b{\u0026amp; .b:not(\u0026amp; .c){color:red}}\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eThis should match \u003ccode\u003e\u0026lt;span class=\u0026quot;a\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;yes\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u003c/code\u003e but not \u003ccode\u003e\u0026lt;span class=\u0026quot;a\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;no\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u003c/code\u003e. The old output incorrectly matched both.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAvoid overwriting input files without \u003ccode\u003e--allow-overwrite\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4484\"\u003e#4484\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eFor example: \u003ccode\u003eesbuild input.js --outfile=input.js\u003c/code\u003e tells esbuild to overwrite \u003ccode\u003einput.js\u003c/code\u003e with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.\u003c/p\u003e\n\u003cp\u003eThis release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless \u003ccode\u003e--allow-overwrite\u003c/code\u003e is explicitly present. This is done by not writing out any files when a build error is encountered.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix incorrect code generated when using top-level await (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4498\"\u003e#4498\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003ePreviously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing \u003ccode\u003easync\u003c/code\u003e on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an \u003ccode\u003easync\u003c/code\u003e module wrapper.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix a minification bug with lowered logical assignment operators (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4508\"\u003e#4508\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Original code\nfunction foo() {\n  let x\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/609683d892977362a0f99026cb74b96263d728a9\"\u003e\u003ccode\u003e609683d\u003c/code\u003e\u003c/a\u003e publish 0.28.2 to npm\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/11b1fe48df6859393d9469f323b5ebd17baaf989\"\u003e\u003ccode\u003e11b1fe4\u003c/code\u003e\u003c/a\u003e add to release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/ab50d91559a27e54cd0a27a403389130ea10d97d\"\u003e\u003ccode\u003eab50d91\u003c/code\u003e\u003c/a\u003e css: fix green/blue channel swap in oklch gamut mapping (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4488\"\u003e#4488\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/04627b6cf99b4a7491bebb0268173a7c77a85030\"\u003e\u003ccode\u003e04627b6\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4498\"\u003e#4498\u003c/a\u003e: \u003ccode\u003easync\u003c/code\u003e TLA checks need a worklist\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/5c15177a308c7224604058a769c4abf0a66b0a36\"\u003e\u003ccode\u003e5c15177\u003c/code\u003e\u003c/a\u003e disable \u003ccode\u003egopls\u003c/code\u003e in the \u003ccode\u003ego\u003c/code\u003e folder\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/fc2ee9babc5a2e8ea7ec7c10dd5850b71f7cec7e\"\u003e\u003ccode\u003efc2ee9b\u003c/code\u003e\u003c/a\u003e css: adjust parser to allow \u003ccode\u003e--foo: {...}\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/209db54371e62ad1c50e12e56bb93c74c53b0408\"\u003e\u003ccode\u003e209db54\u003c/code\u003e\u003c/a\u003e release notes for css nesting bugfix\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/c625d31bf08a0647ec724bf76c7115f7aec55971\"\u003e\u003ccode\u003ec625d31\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4497\"\u003e#4497\u003c/a\u003e: preserve nested ampersands during minification (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4500\"\u003e#4500\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/...\n\n_Description has been truncated_","html_url":"https://github.com/hopekali04/ForexRateAlerter/pull/22","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/hopekali04%2FForexRateAlerter/issues/22","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/22/packages"}],"issue_packages":[{"old_version":"3.1.0","new_version":"3.1.7","update_type":"patch","path":null,"pr_created_at":"2026-09-13T15:46:34.000Z","version_change":"3.1.0 → 3.1.7","issue":{"uuid":"5441053985","node_id":"PR_kwDOR7hZzM8AAAABDWHsmw","number":1,"state":"closed","title":"build(deps): bump the npm_and_yarn group across 5 directories with 18 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-13T15:46:45.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-13T15:46:34.000Z","updated_at":"2026-09-13T15:46:47.000Z","time_to_close":11,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"npm_and_yarn","update_count":18,"packages":[{"name":"vitest","old_version":"4.0.18","new_version":"4.1.0","repository_url":"https://github.com/vitest-dev/vitest"},{"name":"yaml","old_version":"2.8.2","new_version":"2.9.1","repository_url":"https://github.com/eemeli/yaml"},{"name":"@hono/node-server","old_version":"1.19.9","new_version":"1.19.17","repository_url":"https://github.com/honojs/node-server"},{"name":"esbuild","old_version":"0.27.2","new_version":"0.28.2","repository_url":"https://github.com/evanw/esbuild"},{"name":"fast-uri","old_version":"3.1.0","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"hono","old_version":"4.12.3","new_version":"4.13.7","repository_url":"https://github.com/honojs/hono"},{"name":"ip-address","old_version":"10.0.1","new_version":"10.7.0","repository_url":"https://github.com/beaugunderson/ip-address"},{"name":"qs","old_version":"6.15.0","new_version":"6.16.0","repository_url":"https://github.com/ljharb/qs"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 8 updates in the /test/harness directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.0.18` | `4.1.0` |\n| [yaml](https://github.com/eemeli/yaml) | `2.8.2` | `2.9.1` |\n| [@hono/node-server](https://github.com/honojs/node-server) | `1.19.9` | `1.19.17` |\n| [esbuild](https://github.com/evanw/esbuild) | `0.27.2` | `0.28.2` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.0` | `3.1.7` |\n| [hono](https://github.com/honojs/hono) | `4.12.3` | `4.13.7` |\n| [ip-address](https://github.com/beaugunderson/ip-address) | `10.0.1` | `10.7.0` |\n| [qs](https://github.com/ljharb/qs) | `6.15.0` | `6.16.0` |\n\nBumps the npm_and_yarn group with 2 updates in the /scripts/docs-validation directory: [esbuild](https://github.com/evanw/esbuild) and [brace-expansion](https://github.com/juliangruber/brace-expansion).\nBumps the npm_and_yarn group with 6 updates in the /scripts/corrections directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `3.2.4` | `3.2.6` |\n| [esbuild](https://github.com/evanw/esbuild) | `0.27.4` | `0.28.2` |\n| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `7.3.1` | `7.3.6` |\n| [nanoid](https://github.com/ai/nanoid) | `3.3.11` | `3.3.19` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.8` | `8.5.28` |\n| [undici](https://github.com/nodejs/undici) | `6.24.1` | `6.28.1` |\n\nBumps the npm_and_yarn group with 5 updates in the /scripts/codegen directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [yaml](https://github.com/eemeli/yaml) | `2.8.2` | `2.9.1` |\n| [esbuild](https://github.com/evanw/esbuild) | `0.27.3` | `0.28.2` |\n| [picomatch](https://github.com/micromatch/picomatch) | `4.0.3` | `4.0.7` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.1` | `4.3.2` |\n| [lodash](https://github.com/lodash/lodash) | `4.17.23` | `4.18.1` |\n\nBumps the npm_and_yarn group with 7 updates in the /nodejs directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.0.18` | `4.1.0` |\n| [yaml](https://github.com/eemeli/yaml) | `2.8.2` | `2.9.1` |\n| [esbuild](https://github.com/evanw/esbuild) | `0.27.2` | `0.28.2` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.12` | `1.1.18` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.1` | `4.3.2` |\n| [lodash](https://github.com/lodash/lodash) | `4.17.21` | `4.18.1` |\n| [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node) | `0.16.7` | `0.16.8` |\n\n\nUpdates `vitest` from 4.0.18 to 4.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitest-dev/vitest/releases\"\u003evitest's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.1.0\u003c/h2\u003e\n\u003cp\u003eVitest 4.1 is out!\u003c/p\u003e\n\u003cp\u003eThis release page lists all changes made to the project during the 4.1 beta. To get a review of all the new features, read our \u003ca href=\"https://vitest.dev/blog/vitest-4-1\"\u003eblog post\u003c/a\u003e.\u003c/p\u003e\n\u003ch3\u003e   🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReturn a disposable from doMock()  -  by \u003ca href=\"https://github.com/kirkwaiblinger\"\u003e\u003ccode\u003e@​kirkwaiblinger\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9332\"\u003evitest-dev/vitest#9332\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/e3e659a96\"\u003e\u003c!-- raw HTML omitted --\u003e(e3e65)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded chai style assertions  -  by \u003ca href=\"https://github.com/ronnakamoto\"\u003e\u003ccode\u003e@​ronnakamoto\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/8842\"\u003evitest-dev/vitest#8842\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/841df9ac5\"\u003e\u003c!-- raw HTML omitted --\u003e(841df)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate to sinon/fake-timers v15 and add \u003ccode\u003esetTickMode\u003c/code\u003e to timer controls  -  by \u003ca href=\"https://github.com/atscott\"\u003e\u003ccode\u003e@​atscott\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/8726\"\u003evitest-dev/vitest#8726\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/4b480aaed\"\u003e\u003c!-- raw HTML omitted --\u003e(4b480)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExpose matcher types  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9448\"\u003evitest-dev/vitest#9448\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/3e4b913b1\"\u003e\u003c!-- raw HTML omitted --\u003e(3e4b9)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003etoTestSpecification\u003c/code\u003e to reported tasks  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9464\"\u003evitest-dev/vitest#9464\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/1a4705da9\"\u003e\u003c!-- raw HTML omitted --\u003e(1a470)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eShow a warning if \u003ccode\u003evi.mock\u003c/code\u003e or \u003ccode\u003evi.hoisted\u003c/code\u003e are declared outside of top level of the module  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9387\"\u003evitest-dev/vitest#9387\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/5db54a468\"\u003e\u003c!-- raw HTML omitted --\u003e(5db54)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTrack and display expectedly failed tests (.fails) in UI and CLI  -  by \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003esheremet-va\u003c/strong\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9476\"\u003evitest-dev/vitest#9476\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/77d75fd34\"\u003e\u003c!-- raw HTML omitted --\u003e(77d75)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport tags  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9478\"\u003evitest-dev/vitest#9478\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/de7c8a521\"\u003e\u003c!-- raw HTML omitted --\u003e(de7c8)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplement \u003ccode\u003earoundEach\u003c/code\u003e and \u003ccode\u003earoundAll\u003c/code\u003e hooks  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9450\"\u003evitest-dev/vitest#9450\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/2a8cb9dc2\"\u003e\u003c!-- raw HTML omitted --\u003e(2a8cb)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eStabilize experimental features  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9529\"\u003evitest-dev/vitest#9529\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/b5fd2a16a\"\u003e\u003c!-- raw HTML omitted --\u003e(b5fd2)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAccept \u003ccode\u003enew\u003c/code\u003e or \u003ccode\u003eall\u003c/code\u003e in \u003ccode\u003e--update\u003c/code\u003e flag  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9543\"\u003evitest-dev/vitest#9543\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/a5acf28a5\"\u003e\u003c!-- raw HTML omitted --\u003e(a5acf)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport \u003ccode\u003emeta\u003c/code\u003e in test options  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9535\"\u003evitest-dev/vitest#9535\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/7d622e3d1\"\u003e\u003c!-- raw HTML omitted --\u003e(7d622)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport type inference with a new \u003ccode\u003etest.extend\u003c/code\u003e syntax  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9550\"\u003evitest-dev/vitest#9550\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/e53854fcc\"\u003e\u003c!-- raw HTML omitted --\u003e(e5385)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport vite 8 beta, fix type issues in the config with different vite versions  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9587\"\u003evitest-dev/vitest#9587\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/990281dfd\"\u003e\u003c!-- raw HTML omitted --\u003e(99028)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd assertion helper to hide internal stack traces  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e and \u003cstrong\u003eClaude Opus 4.6\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9594\"\u003evitest-dev/vitest#9594\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/eeb0ae2f8\"\u003e\u003c!-- raw HTML omitted --\u003e(eeb0a)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eStore failure screenshots using artifacts API  -  by \u003ca href=\"https://github.com/macarie\"\u003e\u003ccode\u003e@​macarie\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9588\"\u003evitest-dev/vitest#9588\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/24603e3c4\"\u003e\u003c!-- raw HTML omitted --\u003e(24603)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAllow \u003ccode\u003evitest list\u003c/code\u003e to statically collect tests instead of running files to collect them  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9630\"\u003evitest-dev/vitest#9630\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/7a8e7fc20\"\u003e\u003c!-- raw HTML omitted --\u003e(7a8e7)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003e--detect-async-leaks\u003c/code\u003e  -  by \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9528\"\u003evitest-dev/vitest#9528\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/c594d4af3\"\u003e\u003c!-- raw HTML omitted --\u003e(c594d)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplement \u003ccode\u003emockThrow\u003c/code\u003e and \u003ccode\u003emockThrowOnce\u003c/code\u003e  -  by \u003ca href=\"https://github.com/thor-juhasz\"\u003e\u003ccode\u003e@​thor-juhasz\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9512\"\u003evitest-dev/vitest#9512\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/619179fb7\"\u003e\u003c!-- raw HTML omitted --\u003e(61917)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport \u003ccode\u003eupdate: \u0026quot;none\u0026quot;\u003c/code\u003e and add docs about snapshots behavior on CI  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9700\"\u003evitest-dev/vitest#9700\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/05f1854e2\"\u003e\u003c!-- raw HTML omitted --\u003e(05f18)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport playwright \u003ccode\u003elaunchOptions\u003c/code\u003e with \u003ccode\u003econnectOptions\u003c/code\u003e  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9702\"\u003evitest-dev/vitest#9702\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/f0ff1b2a0\"\u003e\u003c!-- raw HTML omitted --\u003e(f0ff1)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003epage/locator.mark\u003c/code\u003e API to enhance playwright trace  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9652\"\u003evitest-dev/vitest#9652\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/d0ee546fe\"\u003e\u003c!-- raw HTML omitted --\u003e(d0ee5)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eapi\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eSupport tests starting or ending with \u003ccode\u003etest\u003c/code\u003e in \u003ccode\u003eexperimental_parseSpecification\u003c/code\u003e  -  by \u003ca href=\"https://github.com/jgillick\"\u003e\u003ccode\u003e@​jgillick\u003c/code\u003e\u003c/a\u003e and \u003cstrong\u003eJeremy Gillick\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9235\"\u003evitest-dev/vitest#9235\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/2f367fad3\"\u003e\u003c!-- raw HTML omitted --\u003e(2f367)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd filters to \u003ccode\u003ecreateSpecification\u003c/code\u003e  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9336\"\u003evitest-dev/vitest#9336\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/c8e6c7fbf\"\u003e\u003c!-- raw HTML omitted --\u003e(c8e6c)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExpose \u003ccode\u003erunTestFiles\u003c/code\u003e as alternative to \u003ccode\u003erunTestSpecifications\u003c/code\u003e  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9443\"\u003evitest-dev/vitest#9443\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/43d761821\"\u003e\u003c!-- raw HTML omitted --\u003e(43d76)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eallowWrite\u003c/code\u003e and \u003ccode\u003eallowExec\u003c/code\u003e options to \u003ccode\u003eapi\u003c/code\u003e  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9350\"\u003evitest-dev/vitest#9350\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/20e00ef78\"\u003e\u003c!-- raw HTML omitted --\u003e(20e00)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAllow passing down test cases to \u003ccode\u003etoTestSpecification\u003c/code\u003e  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9627\"\u003evitest-dev/vitest#9627\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/6f17d5ddf\"\u003e\u003c!-- raw HTML omitted --\u003e(6f17d)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebrowser\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003euserEvent.wheel\u003c/code\u003e API  -  by \u003ca href=\"https://github.com/macarie\"\u003e\u003ccode\u003e@​macarie\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9188\"\u003evitest-dev/vitest#9188\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/660801979\"\u003e\u003c!-- raw HTML omitted --\u003e(66080)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003efilterNode\u003c/code\u003e option to prettyDOM for filtering browser assertion error output  -  by \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003esheremet-va\u003c/strong\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9475\"\u003evitest-dev/vitest#9475\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/d3220fcd8\"\u003e\u003c!-- raw HTML omitted --\u003e(d3220)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport playwright persistent context  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eClaude Opus 4.6\u003c/strong\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9229\"\u003evitest-dev/vitest#9229\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/f865d2ba4\"\u003e\u003c!-- raw HTML omitted --\u003e(f865d)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003edetailsPanelPosition\u003c/code\u003e option and button  -  by \u003ca href=\"https://github.com/shairez\"\u003e\u003ccode\u003e@​shairez\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9525\"\u003evitest-dev/vitest#9525\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/c8a31147c\"\u003e\u003c!-- raw HTML omitted --\u003e(c8a31)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse BlazeDiff instead of pixelmatch  -  by \u003ca href=\"https://github.com/macarie\"\u003e\u003ccode\u003e@​macarie\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9514\"\u003evitest-dev/vitest#9514\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/309362089\"\u003e\u003c!-- raw HTML omitted --\u003e(30936)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003efindElement\u003c/code\u003e and enable strict mode in webdriverio and preview  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9677\"\u003evitest-dev/vitest#9677\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/c3f37721c\"\u003e\u003c!-- raw HTML omitted --\u003e(c3f37)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecli\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eAdd \u003ca href=\"https://github.com/bomb\"\u003e\u003ccode\u003e@​bomb\u003c/code\u003e\u003c/a\u003e.sh/tab completions  -  by \u003ca href=\"https://github.com/AmirSa12\"\u003e\u003ccode\u003e@​AmirSa12\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/8639\"\u003evitest-dev/vitest#8639\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/200f31704\"\u003e\u003c!-- raw HTML omitted --\u003e(200f3)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecoverage\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003eignore start/stop\u003c/code\u003e ignore hints  -  by \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9204\"\u003evitest-dev/vitest#9204\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/e59c94ba6\"\u003e\u003c!-- raw HTML omitted --\u003e(e59c9)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003ecoverage.changed\u003c/code\u003e option to report only changed files  -  by \u003ca href=\"https://github.com/kykim00\"\u003e\u003ccode\u003e@​kykim00\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9521\"\u003evitest-dev/vitest#9521\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/1d9392c67\"\u003e\u003c!-- raw HTML omitted --\u003e(1d939)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexperimental\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003eonModuleRunner\u003c/code\u003e hook to \u003ccode\u003eworker.init\u003c/code\u003e  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9286\"\u003evitest-dev/vitest#9286\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/e977f3deb\"\u003e\u003c!-- raw HTML omitted --\u003e(e977f)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eOption to disable the module runner  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9210\"\u003evitest-dev/vitest#9210\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/9be6121ee\"\u003e\u003c!-- raw HTML omitted --\u003e(9be61)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/4150b913171bda3971a4a4c47c633c26d0c6ae45\"\u003e\u003ccode\u003e4150b91\u003c/code\u003e\u003c/a\u003e chore: release v4.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/1de0aa22dd6311a93546a75a3c58a6be519c1baf\"\u003e\u003ccode\u003e1de0aa2\u003c/code\u003e\u003c/a\u003e fix: correctly identify concurrent test during static analysis (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9846\"\u003e#9846\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/c3cac1c1b5a91d921942e9391fbd94841717363f\"\u003e\u003ccode\u003ec3cac1c\u003c/code\u003e\u003c/a\u003e fix: use isAgent check, not just TTY, for watch mode (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9841\"\u003e#9841\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/eab68ba2b8ea6f89717c0b885c573579659d7c3b\"\u003e\u003ccode\u003eeab68ba\u003c/code\u003e\u003c/a\u003e chore(deps): update all non-major dependencies (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9824\"\u003e#9824\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/031f02a89be34491c441b4da9c4e2bacb7db71df\"\u003e\u003ccode\u003e031f02a\u003c/code\u003e\u003c/a\u003e fix: allow catch/finally for async assertion (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9827\"\u003e#9827\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/3e9e096a231fa0ec6475da82e36cbd6fcc9bc8f9\"\u003e\u003ccode\u003e3e9e096\u003c/code\u003e\u003c/a\u003e feat(reporters): add \u003ccode\u003eagent\u003c/code\u003e reporter to reduce ai agent token usage (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9779\"\u003e#9779\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/0c2c01361a95dd26d0d7fd7bc38bcca8dbc6e5d2\"\u003e\u003ccode\u003e0c2c013\u003c/code\u003e\u003c/a\u003e chore: release v4.1.0-beta.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/8181e06e765f4d043818b244c76795022fa78ff6\"\u003e\u003ccode\u003e8181e06\u003c/code\u003e\u003c/a\u003e fix: \u003ccode\u003ehideSkippedTests\u003c/code\u003e should not hide \u003ccode\u003etest.todo\u003c/code\u003e (fix \u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9562\"\u003e#9562\u003c/a\u003e) (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9781\"\u003e#9781\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/a8216b0014b83612e40ef49f919d5293b68717b3\"\u003e\u003ccode\u003ea8216b0\u003c/code\u003e\u003c/a\u003e fix: manual and redirect mock shouldn't \u003ccode\u003eload\u003c/code\u003e or \u003ccode\u003etransform\u003c/code\u003e original module...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/689a22a1b8c79595f6f4ae82d2b43c895d7f1c50\"\u003e\u003ccode\u003e689a22a\u003c/code\u003e\u003c/a\u003e fix(browser): types of \u003ccode\u003egetCDPSession\u003c/code\u003e and \u003ccode\u003ecdp()\u003c/code\u003e (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/9716\"\u003e#9716\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vitest-dev/vitest/commits/v4.1.0/packages/vitest\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `yaml` from 2.8.2 to 2.9.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/eemeli/yaml/releases\"\u003eyaml's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.9.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eLimit recursive merge aliases (\u003ca href=\"https://redirect.github.com/eemeli/yaml/issues/685\"\u003e#685\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/eemeli/yaml/issues/713\"\u003e#713\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSimplify line unfolding during quoted string parsing (\u003ca href=\"https://redirect.github.com/eemeli/yaml/issues/714\"\u003e#714\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.9.0\u003c/h2\u003e\n\u003cp\u003eThe changes here are really only patches, but I'm releasing this as a minor version to note a small change to the documentation of \u003ccode\u003eparseDocument()\u003c/code\u003e and \u003ccode\u003eparseAllDocuments()\u003c/code\u003e: I've removed the claim that they'll \u0026quot;never throw\u0026quot;.\u003c/p\u003e\n\u003cp\u003eIt remains the case that practically all non-malicious inputs will be handled without emitting an error, but there is a decent chance that code paths remain where e.g. a RangeError due to call stack exhaustion can be triggered by malicious inputs. Up to now, I've considered these as security vulnerabilities, and in fact it's the only category of error for which \u003ccode\u003eyaml\u003c/code\u003e CVEs have been issued so far.\u003c/p\u003e\n\u003cp\u003eStarting from this release, I'll be considering such errors as bugs, but not vulnerabilities. I do welcome people and/or LLMs looking for them, but please report them as normal issues rather than suspected security vulnerabilities. This also applies to previously undiscovered bugs in earlier releases.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efix: Avoid calling \u003ccode\u003eArray.prototype.push.apply()\u003c/code\u003e with large source array\u003c/li\u003e\n\u003cli\u003efix(lexer): Avoid recursive calls that may exhaust the call stack\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.8.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDisable alias resolution with \u003ccode\u003emaxAliasCount:0\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/eemeli/yaml/issues/677\"\u003e#677\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHandle invalid unicode escapes (e1a1a77)\u003c/li\u003e\n\u003cli\u003eApply \u003ccode\u003eminFractionDigits\u003c/code\u003e only to decimal strings (\u003ca href=\"https://redirect.github.com/eemeli/yaml/issues/676\"\u003e#676\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.8.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003etrailingComma\u003c/code\u003e ToString option for multiline flow formatting (\u003ca href=\"https://redirect.github.com/eemeli/yaml/issues/670\"\u003e#670\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCatch stack overflow during node composition (1e84ebb)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eemeli/yaml/commit/1440ecd3d1bff41e4ac399f8f6839e810328bd16\"\u003e\u003ccode\u003e1440ecd\u003c/code\u003e\u003c/a\u003e 2.9.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eemeli/yaml/commit/c699bc575b46e1dd3c05f1ffcf3f20f14085f8d8\"\u003e\u003ccode\u003ec699bc5\u003c/code\u003e\u003c/a\u003e fix: Simplify line unfolding during quoted string parsing (\u003ca href=\"https://redirect.github.com/eemeli/yaml/issues/714\"\u003e#714\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eemeli/yaml/commit/d11ce77c1adf022e9637f4d27b90fe9c96fe9743\"\u003e\u003ccode\u003ed11ce77\u003c/code\u003e\u003c/a\u003e fix: Limit recursive merge aliases (\u003ca href=\"https://redirect.github.com/eemeli/yaml/issues/713\"\u003e#713\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eemeli/yaml/commit/c5f49f4c616ea49239f010d5c9d8023e9667438a\"\u003e\u003ccode\u003ec5f49f4\u003c/code\u003e\u003c/a\u003e chore: Update docs-slate\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eemeli/yaml/commit/ddb21b04cb889722cec8f89dc1b67f19d62d7f7d\"\u003e\u003ccode\u003eddb21b0\u003c/code\u003e\u003c/a\u003e 2.9.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eemeli/yaml/commit/167365befdae1f03d53d47a8c6533140a9d48a75\"\u003e\u003ccode\u003e167365b\u003c/code\u003e\u003c/a\u003e docs: Clarify that not all errors can be avoided\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eemeli/yaml/commit/6eca2a7087548f86c4edb6a7cf2cdfe548759f06\"\u003e\u003ccode\u003e6eca2a7\u003c/code\u003e\u003c/a\u003e fix: Avoid calling Array.prototype.push.apply() with large source array\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eemeli/yaml/commit/0543cd57fd61ea15a58e9f0ec2064b8b408177d8\"\u003e\u003ccode\u003e0543cd5\u003c/code\u003e\u003c/a\u003e fix(lexer): Avoid recursive calls that may exhaust the call stack\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eemeli/yaml/commit/ccdf7439587544f64223429498a1d9ec514eaac1\"\u003e\u003ccode\u003eccdf743\u003c/code\u003e\u003c/a\u003e 2.8.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eemeli/yaml/commit/f625789dbd971c936ff66fe5c49e368062ae7b41\"\u003e\u003ccode\u003ef625789\u003c/code\u003e\u003c/a\u003e fix: Disable alias resolution with maxAliasCount:0 (\u003ca href=\"https://redirect.github.com/eemeli/yaml/issues/677\"\u003e#677\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/eemeli/yaml/compare/v2.8.2...v2.9.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@hono/node-server` from 1.19.9 to 1.19.17\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/honojs/node-server/releases\"\u003e@​hono/node-server's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.19.17\u003c/h2\u003e\n\u003cp\u003eNo release notes provided.\u003c/p\u003e\n\u003ch2\u003ev1.19.14\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: add custom inspect to lightweight Request/Response to prevent TypeError on console.log by \u003ca href=\"https://github.com/usualoma\"\u003e\u003ccode\u003e@​usualoma\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/340\"\u003ehonojs/node-server#340\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/node-server/compare/v1.19.13...v1.19.14\"\u003ehttps://github.com/honojs/node-server/compare/v1.19.13...v1.19.14\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.19.13\u003c/h2\u003e\n\u003ch2\u003eSecurity Fix\u003c/h2\u003e\n\u003cp\u003eFixed an issue in Serve Static Middleware where inconsistent handling of repeated slashes (\u003ccode\u003e//\u003c/code\u003e) between the router and static file resolution could allow middleware to be bypassed. Users of Serve Static Middleware are encouraged to upgrade to this version.\u003c/p\u003e\n\u003cp\u003eSee GHSA-92pp-h63x-v22m for details.\u003c/p\u003e\n\u003ch2\u003ev1.19.12\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore: ignore claude setting by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/314\"\u003ehonojs/node-server#314\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: request draining for early 413 responses by \u003ca href=\"https://github.com/usualoma\"\u003e\u003ccode\u003e@​usualoma\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/329\"\u003ehonojs/node-server#329\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/node-server/compare/v1.19.11...v1.19.12\"\u003ehttps://github.com/honojs/node-server/compare/v1.19.11...v1.19.12\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.19.11\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: do not overwrite Content-Length in the fast path pattern if Content-Length already exists. by \u003ca href=\"https://github.com/usualoma\"\u003e\u003ccode\u003e@​usualoma\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/309\"\u003ehonojs/node-server#309\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/node-server/compare/v1.19.10...v1.19.11\"\u003ehttps://github.com/honojs/node-server/compare/v1.19.10...v1.19.11\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.19.10\u003c/h2\u003e\n\u003ch2\u003eSecurity Fix\u003c/h2\u003e\n\u003cp\u003eFixed an authorization bypass in Serve Static Middleware caused by inconsistent URL decoding (\u003ccode\u003e%2F\u003c/code\u003e handling) between the router and static file resolution. Users of Serve Static Middleware are encouraged to upgrade to this version.\u003c/p\u003e\n\u003cp\u003eSee GHSA-wc8c-qw6v-h7f6 for details.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/71941daede982571f18d2774951f37c475cccefc\"\u003e\u003ccode\u003e71941da\u003c/code\u003e\u003c/a\u003e 1.19.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/0208500d8f11b33dd03b50c86df8e132307adf1e\"\u003e\u003ccode\u003e0208500\u003c/code\u003e\u003c/a\u003e ci: add \u003ccode\u003estage\u003c/code\u003e option for publishing (\u003ca href=\"https://redirect.github.com/honojs/node-server/issues/386\"\u003e#386\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/cbdf713a67ef38f6a5304488e294381230a52e46\"\u003e\u003ccode\u003ecbdf713\u003c/code\u003e\u003c/a\u003e 1.19.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/86e96c24045411b3e3c4a9b61a4c1e755c398a44\"\u003e\u003ccode\u003e86e96c2\u003c/code\u003e\u003c/a\u003e ci: add an action for trusted publisher (\u003ca href=\"https://redirect.github.com/honojs/node-server/issues/385\"\u003e#385\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/99c1a1abd702132302f3da72600d383a25eba32c\"\u003e\u003ccode\u003e99c1a1a\u003c/code\u003e\u003c/a\u003e ci: run on v1.x branch pushes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/84cb2ee25f567d812b76e0cff4c36899acb157eb\"\u003e\u003ccode\u003e84cb2ee\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/b5e63a366d9b0ef62ac65fcafd7f69b383b03ff5\"\u003e\u003ccode\u003eb5e63a3\u003c/code\u003e\u003c/a\u003e 1.19.14\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/c02d7770a2d29ea473403211bef0a60639885a28\"\u003e\u003ccode\u003ec02d777\u003c/code\u003e\u003c/a\u003e fix: add custom inspect to lightweight Request/Response to prevent TypeError ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/fd64e659a34ec661fd9ccda00d1b9dff88dfaf90\"\u003e\u003ccode\u003efd64e65\u003c/code\u003e\u003c/a\u003e 1.19.13\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/025c30f55d589ddbe6048b151d77e904f67a8cc2\"\u003e\u003ccode\u003e025c30f\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/honojs/node-server/compare/v1.19.9...v1.19.17\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​hono/node-server\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@vitest/mocker` from 4.0.18 to 4.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitest-dev/vitest/releases\"\u003e@​vitest/mocker's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.1.0\u003c/h2\u003e\n\u003cp\u003eVitest 4.1 is out!\u003c/p\u003e\n\u003cp\u003eThis release page lists all changes made to the project during the 4.1 beta. To get a review of all the new features, read our \u003ca href=\"https://vitest.dev/blog/vitest-4-1\"\u003eblog post\u003c/a\u003e.\u003c/p\u003e\n\u003ch3\u003e   🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReturn a disposable from doMock()  -  by \u003ca href=\"https://github.com/kirkwaiblinger\"\u003e\u003ccode\u003e@​kirkwaiblinger\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9332\"\u003evitest-dev/vitest#9332\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/e3e659a96\"\u003e\u003c!-- raw HTML omitted --\u003e(e3e65)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded chai style assertions  -  by \u003ca href=\"https://github.com/ronnakamoto\"\u003e\u003ccode\u003e@​ronnakamoto\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/8842\"\u003evitest-dev/vitest#8842\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/841df9ac5\"\u003e\u003c!-- raw HTML omitted --\u003e(841df)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate to sinon/fake-timers v15 and add \u003ccode\u003esetTickMode\u003c/code\u003e to timer controls  -  by \u003ca href=\"https://github.com/atscott\"\u003e\u003ccode\u003e@​atscott\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/8726\"\u003evitest-dev/vitest#8726\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/4b480aaed\"\u003e\u003c!-- raw HTML omitted --\u003e(4b480)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExpose matcher types  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9448\"\u003evitest-dev/vitest#9448\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/3e4b913b1\"\u003e\u003c!-- raw HTML omitted --\u003e(3e4b9)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003etoTestSpecification\u003c/code\u003e to reported tasks  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9464\"\u003evitest-dev/vitest#9464\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/1a4705da9\"\u003e\u003c!-- raw HTML omitted --\u003e(1a470)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eShow a warning if \u003ccode\u003evi.mock\u003c/code\u003e or \u003ccode\u003evi.hoisted\u003c/code\u003e are declared outside of top level of the module  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9387\"\u003evitest-dev/vitest#9387\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/5db54a468\"\u003e\u003c!-- raw HTML omitted --\u003e(5db54)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTrack and display expectedly failed tests (.fails) in UI and CLI  -  by \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003esheremet-va\u003c/strong\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9476\"\u003evitest-dev/vitest#9476\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/77d75fd34\"\u003e\u003c!-- raw HTML omitted --\u003e(77d75)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport tags  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9478\"\u003evitest-dev/vitest#9478\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/de7c8a521\"\u003e\u003c!-- raw HTML omitted --\u003e(de7c8)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplement \u003ccode\u003earoundEach\u003c/code\u003e and \u003ccode\u003earoundAll\u003c/code\u003e hooks  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9450\"\u003evitest-dev/vitest#9450\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/2a8cb9dc2\"\u003e\u003c!-- raw HTML omitted --\u003e(2a8cb)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eStabilize experimental features  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9529\"\u003evitest-dev/vitest#9529\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/b5fd2a16a\"\u003e\u003c!-- raw HTML omitted --\u003e(b5fd2)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAccept \u003ccode\u003enew\u003c/code\u003e or \u003ccode\u003eall\u003c/code\u003e in \u003ccode\u003e--update\u003c/code\u003e flag  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9543\"\u003evitest-dev/vitest#9543\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/a5acf28a5\"\u003e\u003c!-- raw HTML omitted --\u003e(a5acf)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport \u003ccode\u003emeta\u003c/code\u003e in test options  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9535\"\u003evitest-dev/vitest#9535\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/7d622e3d1\"\u003e\u003c!-- raw HTML omitted --\u003e(7d622)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport type inference with a new \u003ccode\u003etest.extend\u003c/code\u003e syntax  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9550\"\u003evitest-dev/vitest#9550\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/e53854fcc\"\u003e\u003c!-- raw HTML omitted --\u003e(e5385)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport vite 8 beta, fix type issues in the config with different vite versions  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9587\"\u003evitest-dev/vitest#9587\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/990281dfd\"\u003e\u003c!-- raw HTML omitted --\u003e(99028)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd assertion helper to hide internal stack traces  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e and \u003cstrong\u003eClaude Opus 4.6\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9594\"\u003evitest-dev/vitest#9594\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/eeb0ae2f8\"\u003e\u003c!-- raw HTML omitted --\u003e(eeb0a)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eStore failure screenshots using artifacts API  -  by \u003ca href=\"https://github.com/macarie\"\u003e\u003ccode\u003e@​macarie\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9588\"\u003evitest-dev/vitest#9588\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/24603e3c4\"\u003e\u003c!-- raw HTML omitted --\u003e(24603)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAllow \u003ccode\u003evitest list\u003c/code\u003e to statically collect tests instead of running files to collect them  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9630\"\u003evitest-dev/vitest#9630\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/7a8e7fc20\"\u003e\u003c!-- raw HTML omitted --\u003e(7a8e7)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003e--detect-async-leaks\u003c/code\u003e  -  by \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9528\"\u003evitest-dev/vitest#9528\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/c594d4af3\"\u003e\u003c!-- raw HTML omitted --\u003e(c594d)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplement \u003ccode\u003emockThrow\u003c/code\u003e and \u003ccode\u003emockThrowOnce\u003c/code\u003e  -  by \u003ca href=\"https://github.com/thor-juhasz\"\u003e\u003ccode\u003e@​thor-juhasz\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9512\"\u003evitest-dev/vitest#9512\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/619179fb7\"\u003e\u003c!-- raw HTML omitted --\u003e(61917)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport \u003ccode\u003eupdate: \u0026quot;none\u0026quot;\u003c/code\u003e and add docs about snapshots behavior on CI  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9700\"\u003evitest-dev/vitest#9700\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/05f1854e2\"\u003e\u003c!-- raw HTML omitted --\u003e(05f18)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport playwright \u003ccode\u003elaunchOptions\u003c/code\u003e with \u003ccode\u003econnectOptions\u003c/code\u003e  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9702\"\u003evitest-dev/vitest#9702\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/f0ff1b2a0\"\u003e\u003c!-- raw HTML omitted --\u003e(f0ff1)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003epage/locator.mark\u003c/code\u003e API to enhance playwright trace  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9652\"\u003evitest-dev/vitest#9652\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/d0ee546fe\"\u003e\u003c!-- raw HTML omitted --\u003e(d0ee5)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eapi\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eSupport tests starting or ending with \u003ccode\u003etest\u003c/code\u003e in \u003ccode\u003eexperimental_parseSpecification\u003c/code\u003e  -  by \u003ca href=\"https://github.com/jgillick\"\u003e\u003ccode\u003e@​jgillick\u003c/code\u003e\u003c/a\u003e and \u003cstrong\u003eJeremy Gillick\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9235\"\u003evitest-dev/vitest#9235\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/2f367fad3\"\u003e\u003c!-- raw HTML omitted --\u003e(2f367)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd filters to \u003ccode\u003ecreateSpecification\u003c/code\u003e  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9336\"\u003evitest-dev/vitest#9336\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/c8e6c7fbf\"\u003e\u003c!-- raw HTML omitted --\u003e(c8e6c)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExpose \u003ccode\u003erunTestFiles\u003c/code\u003e as alternative to \u003ccode\u003erunTestSpecifications\u003c/code\u003e  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9443\"\u003evitest-dev/vitest#9443\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/43d761821\"\u003e\u003c!-- raw HTML omitted --\u003e(43d76)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eallowWrite\u003c/code\u003e and \u003ccode\u003eallowExec\u003c/code\u003e options to \u003ccode\u003eapi\u003c/code\u003e  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9350\"\u003evitest-dev/vitest#9350\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/20e00ef78\"\u003e\u003c!-- raw HTML omitted --\u003e(20e00)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAllow passing down test cases to \u003ccode\u003etoTestSpecification\u003c/code\u003e  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9627\"\u003evitest-dev/vitest#9627\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/6f17d5ddf\"\u003e\u003c!-- raw HTML omitted --\u003e(6f17d)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebrowser\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003euserEvent.wheel\u003c/code\u003e API  -  by \u003ca href=\"https://github.com/macarie\"\u003e\u003ccode\u003e@​macarie\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9188\"\u003evitest-dev/vitest#9188\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/660801979\"\u003e\u003c!-- raw HTML omitted --\u003e(66080)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003efilterNode\u003c/code\u003e option to prettyDOM for filtering browser assertion error output  -  by \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003esheremet-va\u003c/strong\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9475\"\u003evitest-dev/vitest#9475\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/d3220fcd8\"\u003e\u003c!-- raw HTML omitted --\u003e(d3220)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport playwright persistent context  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eClaude Opus 4.6\u003c/strong\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9229\"\u003evitest-dev/vitest#9229\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/f865d2ba4\"\u003e\u003c!-- raw HTML omitted --\u003e(f865d)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003edetailsPanelPosition\u003c/code\u003e option and button  -  by \u003ca href=\"https://github.com/shairez\"\u003e\u003ccode\u003e@​shairez\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9525\"\u003evitest-dev/vitest#9525\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/c8a31147c\"\u003e\u003c!-- raw HTML omitted --\u003e(c8a31)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse BlazeDiff instead of pixelmatch  -  by \u003ca href=\"https://github.com/macarie\"\u003e\u003ccode\u003e@​macarie\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9514\"\u003evitest-dev/vitest#9514\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/309362089\"\u003e\u003c!-- raw HTML omitted --\u003e(30936)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003efindElement\u003c/code\u003e and enable strict mode in webdriverio and preview  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9677\"\u003evitest-dev/vitest#9677\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/c3f37721c\"\u003e\u003c!-- raw HTML omitted --\u003e(c3f37)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecli\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eAdd \u003ca href=\"https://github.com/bomb\"\u003e\u003ccode\u003e@​bomb\u003c/code\u003e\u003c/a\u003e.sh/tab completions  -  by \u003ca href=\"https://github.com/AmirSa12\"\u003e\u003ccode\u003e@​AmirSa12\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/8639\"\u003evitest-dev/vitest#8639\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/200f31704\"\u003e\u003c!-- raw HTML omitted --\u003e(200f3)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecoverage\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eSupport \u003ccode\u003eignore start/stop\u003c/code\u003e ignore hints  -  by \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9204\"\u003evitest-dev/vitest#9204\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/e59c94ba6\"\u003e\u003c!-- raw HTML omitted --\u003e(e59c9)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003ecoverage.changed\u003c/code\u003e option to report only changed files  -  by \u003ca href=\"https://github.com/kykim00\"\u003e\u003ccode\u003e@​kykim00\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9521\"\u003evitest-dev/vitest#9521\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/1d9392c67\"\u003e\u003c!-- raw HTML omitted --\u003e(1d939)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexperimental\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003eonModuleRunner\u003c/code\u003e hook to \u003ccode\u003eworker.init\u003c/code\u003e  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9286\"\u003evitest-dev/vitest#9286\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/e977f3deb\"\u003e\u003c!-- raw HTML omitted --\u003e(e977f)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eOption to disable the module runner  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9210\"\u003evitest-dev/vitest#9210\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/9be6121ee\"\u003e\u003c!-- raw HTML omitted --\u003e(9be61)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/4150b913171bda3971a4a4c47c633c26d0c6ae45\"\u003e\u003ccode\u003e4150b91\u003c/code\u003e\u003c/a\u003e chore: release v4.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/36f9a81a2b6406bac601f42019215a4637cad943\"\u003e\u003ccode\u003e36f9a81\u003c/code\u003e\u003c/a\u003e fix(mocker): update vite's peer dependency range (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/mocker/issues/9808\"\u003e#9808\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/0c2c01361a95dd26d0d7fd7bc38bcca8dbc6e5d2\"\u003e\u003ccode\u003e0c2c013\u003c/code\u003e\u003c/a\u003e chore: release v4.1.0-beta.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/94eb73b519cb5ecd06c9aa178a3f0e161c96236f\"\u003e\u003ccode\u003e94eb73b\u003c/code\u003e\u003c/a\u003e chore(deps): update eslint packages (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/mocker/issues/9615\"\u003e#9615\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/8c96bb0023f551c78a81461d5c9aaedee634fe99\"\u003e\u003ccode\u003e8c96bb0\u003c/code\u003e\u003c/a\u003e refator: update links to npmx (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/mocker/issues/9783\"\u003e#9783\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/aaf775896af2356f5c710c54ec6e624fe8e4eef9\"\u003e\u003ccode\u003eaaf7758\u003c/code\u003e\u003c/a\u003e chore: standardize packages README (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/mocker/issues/9776\"\u003e#9776\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/79672d7e1586981f04dce7619cbd8c3a31eff284\"\u003e\u003ccode\u003e79672d7\u003c/code\u003e\u003c/a\u003e chore: release v4.1.0-beta.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/84c69497ff7841c9ddeeaf1641e17a85b5cf4c6a\"\u003e\u003ccode\u003e84c6949\u003c/code\u003e\u003c/a\u003e fix: make \u003ccode\u003emockObject\u003c/code\u003e change backwards compatible (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/mocker/issues/9744\"\u003e#9744\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/695a86b41ef01c60f3574ab1bbddfe38c74c402b\"\u003e\u003ccode\u003e695a86b\u003c/code\u003e\u003c/a\u003e fix: recursively autospy module object (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/mocker/issues/9687\"\u003e#9687\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/1d9e3b3315024e3443a5a72fa8387508f4223528\"\u003e\u003ccode\u003e1d9e3b3\u003c/code\u003e\u003c/a\u003e chore: release v4.1.0-beta.4\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vitest-dev/vitest/commits/v4.1.0/packages/mocker\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `esbuild` from 0.27.2 to 0.28.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/evanw/esbuild/releases\"\u003eesbuild's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.28.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix tree shaking bug due to TypeScript import alias (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4507\"\u003e#4507\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific \u003ccode\u003eimport\u003c/code\u003e assignment and looks something like this:\u003c/p\u003e\n\u003cpre lang=\"ts\"\u003e\u003ccode\u003eimport Base from './dep.js';\r\nimport Alias = Base.SomeType;\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix CSS minification bug involving \u003ccode\u003e\u0026amp;\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4497\"\u003e#4497\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug where esbuild's CSS minifier incorrectly removed a \u003ccode\u003e\u0026amp;\u003c/code\u003e when it was unsafe to do so. Here is an example:\u003c/p\u003e\n\u003cpre lang=\"css\"\u003e\u003ccode\u003e/* Original code */\r\n.a .b {\r\n  \u0026amp; .b:not(\u0026amp; .c) {\r\n    color: red;\r\n  }\r\n}\r\n\u003cp\u003e/* Old output (with --minify) */\u003cbr /\u003e\n.a .b{.b:not(\u0026amp; .c){color:red}}\u003c/p\u003e\n\u003cp\u003e/* New output (with --minify) */\u003cbr /\u003e\n.a .b{\u0026amp; .b:not(\u0026amp; .c){color:red}}\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eThis should match \u003ccode\u003e\u0026lt;span class=\u0026quot;a\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;yes\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u003c/code\u003e but not \u003ccode\u003e\u0026lt;span class=\u0026quot;a\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;no\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u003c/code\u003e. The old output incorrectly matched both.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAvoid overwriting input files without \u003ccode\u003e--allow-overwrite\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4484\"\u003e#4484\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eFor example: \u003ccode\u003eesbuild input.js --outfile=input.js\u003c/code\u003e tells esbuild to overwrite \u003ccode\u003einput.js\u003c/code\u003e with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.\u003c/p\u003e\n\u003cp\u003eThis release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless \u003ccode\u003e--allow-overwrite\u003c/code\u003e is explicitly present. This is done by not writing out any files when a build error is encountered.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix incorrect code generated when using top-level await (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4498\"\u003e#4498\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003ePreviously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing \u003ccode\u003easync\u003c/code\u003e on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an \u003ccode\u003easync\u003c/code\u003e module wrapper.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix a minification bug with lowered logical assignment operators (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4508\"\u003e#4508\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Original code\r\nfunction foo() {\r\n  let x\r\n  bar(x ||= {})\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/evanw/esbuild/blob/main/CHANGELOG-2025.md\"\u003eesbuild's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog: 2025\u003c/h1\u003e\n\u003cp\u003eThis changelog documents all esbuild versions published in the year 2025 (versions 0.25.0 through 0.27.2).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/609683d892977362a0f99026cb74b96263d728a9\"\u003e\u003ccode\u003e609683d\u003c/code\u003e\u003c/a\u003e publish 0.28.2 to npm\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/11b1fe48df6859393d9469f323b5ebd17baaf989\"\u003e\u003ccode\u003e11b1fe4\u003c/code\u003e\u003c/a\u003e add to release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/ab50d91559a27e54cd0a27a403389130ea10d97d\"\u003e\u003ccode\u003eab50d91\u003c/code\u003e\u003c/a\u003e css: fix green/blue channel swap in oklch gamut mapping (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4488\"\u003e#4488\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/04627b6cf99b4a7491bebb0268173a7c77a85030\"\u003e\u003ccode\u003e04627b6\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4498\"\u003e#4498\u003c/a\u003e: \u003ccode\u003easync\u003c/code\u003e TLA checks need a worklist\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/5c15177a308c7224604058a769c4abf0a66b0a36\"\u003e\u003ccode\u003e5c15177\u003c/code\u003e\u003c/a\u003e disable \u003ccode\u003egopls\u003c/code\u003e in the \u003ccode\u003ego\u003c/code\u003e folder\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/fc2ee9babc5a2e8ea7ec7c10dd5850b71f7cec7e\"\u003e\u003ccode\u003efc2ee9b\u003c/code\u003e\u003c/a\u003e css: adjust parser to allow \u003ccode\u003e--foo: {...}\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/209db54371e62ad1c50e12e56bb93c74c53b0408\"\u003e\u003ccode\u003e209db54\u003c/code\u003e\u003c/a\u003e release notes for css nesting bugfix\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/c625d31bf08a0647ec724bf76c7115f7aec55971\"\u003e\u003ccode\u003ec625d31\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4497\"\u003e#4497\u003c/a\u003e: preserve nested ampersands during minification (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4500\"\u003e#4500\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/34474e278528a60f58c959c0f422d2bfa6f6886d\"\u003e\u003ccode\u003e34474e2\u003c/code\u003e\u003c/a\u003e better isolation of current part in js parser\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/07f6e8c50677e0b41e5ed726c08b0ea200b14e5b\"\u003e\u003ccode\u003e07f6e8c\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4507\"\u003e#4507\u003c/a\u003e: \u003ccode\u003eimport\u003c/code\u003e assignment tree-shaking bug\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/evanw/esbuild/compare/v0.27.2...v0.28.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-uri` from 3.1.0 to 3.1.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.0...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `hono` from 4.12.3 to 4.13.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/honojs/hono/releases\"\u003ehono's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.13.7\u003c/h2\u003e\n\u003ch2\u003eSecurity fixes\u003c/h2\u003e\n\u003cp\u003eThis release includes a fix for the following security issue:\u003c/p\u003e\n\u003ch3\u003e\u003ccode\u003ehono/jsx\u003c/code\u003e renders plain strings unescaped in boundary components, leading to XSS\u003c/h3\u003e\n\u003cp\u003eAffects: \u003ccode\u003eSuspense\u003c/code\u003e, \u003ccode\u003eErrorBoundary\u003c/code\u003e, and \u003ccode\u003eContext.Provider\u003c/code\u003e in \u003ccode\u003ehono/jsx\u003c/code\u003e, and \u003ccode\u003erenderToString()\u003c/code\u003e / \u003ccode\u003erenderToReadableStream()\u003c/code\u003e in \u003ccode\u003ehono/jsx/dom/server\u003c/code\u003e. Fixes missing HTML escaping for a plain string placed directly as a child or \u003ccode\u003efallback\u003c/code\u003e of these components, or as the root value of the server rendering functions, so untrusted strings could be emitted as markup. GHSA-hxh3-vqpv-xpqv\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003eUsers who render untrusted strings inside \u003ccode\u003eSuspense\u003c/code\u003e, \u003ccode\u003eErrorBoundary\u003c/code\u003e, or \u003ccode\u003eContext.Provider\u003c/code\u003e, or pass them directly to \u003ccode\u003ehono/jsx/dom/server\u003c/code\u003e, are strongly encouraged to upgrade to this version.\u003c/p\u003e\n\u003ch2\u003ev4.13.6\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(client): keep a param value of \u0026quot;index\u0026quot; in $url() and $path() in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5297\"\u003ehonojs/hono#5297\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(client): normalize root WebSocket URLs in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5291\"\u003ehonojs/hono#5291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(types): allow symbol keys in Context\u003c!-- raw HTML omitted --\u003e get and set fallbacks in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5300\"\u003ehonojs/hono#5300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump \u003ccode\u003eeditorconfig-checker\u003c/code\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5336\"\u003ehonojs/hono#5336\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor(on-handler): use forEach for consistent handler iteration in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5326\"\u003ehonojs/hono#5326\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/hono/compare/v4.13.5...v4.13.6\"\u003ehttps://github.com/honojs/hono/compare/v4.13.5...v4.13.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev4.13.5\u003c/h2\u003e\n\u003ch2\u003eSecurity fixes\u003c/h2\u003e\n\u003cp\u003eThis release includes fixes for the following security issues:\u003c/p\u003e\n\u003ch3\u003eQuery parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials\u003c/h3\u003e\n\u003cp\u003eAffects: Cache Middleware and applications behind a proxy, WAF, or logging layer that inspects query strings. Fixes query parsing that did not stop at the URL fragment, so a \u003ccode\u003e?\u003c/code\u003e after a \u003ccode\u003e#\u003c/code\u003e was treated as the start of a query string and the application could read parameters that the other component never saw. GHSA-crvj-82cr-hjcx\u003c/p\u003e\n\u003ch3\u003eIncomplete fix for CVE-2026-39408: \u003ccode\u003etoSSG()\u003c/code\u003e still writes files outside the output directory\u003c/h3\u003e\n\u003cp\u003eAffects: \u003ccode\u003etoSSG()\u003c/code\u003e for Static Site Generation. Fixes a path normalization gap where consecutive parent-directory segments in \u003ccode\u003essgParams\u003c/code\u003e values were not fully collapsed, bypassing the containment check added in 4.12.12. GHSA-gqvv-2mrq-wpjv\u003c/p\u003e\n\u003ch3\u003eUnbounded dot-notation nesting in \u003ccode\u003eparseBody()\u003c/code\u003e can cause memory exhaustion\u003c/h3\u003e\n\u003cp\u003eAffects: \u003ccode\u003eparseBody()\u003c/code\u003e when dot-notation parsing is enabled. Fixes unbounded expansion of dot-separated field names, where a small request body could allocate a disproportionately large object graph and concurrent requests could exhaust the heap. GHSA-g6gw-c38x-mqfc\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003eUsers who use Cache Middleware, deploy behind a proxy or WAF that inspects query strings, use Static Site Generation, or use \u003ccode\u003eparseBody({ dot: true })\u003c/code\u003e are strongly encouraged to upgrade to this version.\u003c/p\u003e\n\u003ch2\u003ev4.13.4\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(request): handle params on unmatched requests in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5268\"\u003ehonojs/hono#5268\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(jsx/dom): execute previous ref cleanup when ref prop changes on re-render  in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5264\"\u003ehonojs/hono#5264\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(reg-exp-router): associate wildcard middleware with matching routes in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5266\"\u003ehonojs/hono#5266\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf(router): share null object creation in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5267\"\u003ehonojs/hono#5267\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/hono/commit/eebdf7be39abf0a872671835ccce0c4f03ea497a\"\u003e\u003ccode\u003eeebdf7b\u003c/code\u003e\u003c/a\u003e 4.13.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/hono/commit/2b8ed402cdab6dfc5e829b480806dcd8db94161e\"\u003e\u003ccode\u003e2b8ed40\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/hono/commit/cac0c4d3fe29aca4e426031067cbbb3b9131e30c\"\u003e\u003ccode\u003ecac0c4d\u003c/code\u003e\u003c/a\u003e 4.13.6\u003c/li\u003e\n...\n\n_Description has been truncated_","html_url":"https://github.com/justshhhhhhh-au/copilot-sdk/pull/1","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/justshhhhhhh-au%2Fcopilot-sdk/issues/1","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1/packages"}},{"old_version":"3.1.2","new_version":"3.1.7","update_type":"patch","path":null,"pr_created_at":"2026-09-13T13:17:53.000Z","version_change":"3.1.2 → 3.1.7","issue":{"uuid":"5440272467","node_id":"PR_kwDOTIbqCs8AAAABDVhaIA","number":4,"state":"closed","title":"build(deps): bump fast-uri from 3.1.2 to 3.1.7","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-13T13:27:01.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-13T13:17:53.000Z","updated_at":"2026-09-13T13:27:02.000Z","time_to_close":548,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps)","packages":[{"name":"fast-uri","old_version":"3.1.2","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"}],"path":null,"ecosystem":"npm"},"body":"Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.2 to 3.1.7.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=fast-uri\u0026package-manager=npm_and_yarn\u0026previous-version=3.1.2\u0026new-version=3.1.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/CedricConday/xe-mcp/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/CedricConday/xe-mcp/pull/4","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/CedricConday%2Fxe-mcp/issues/4","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/4/packages"}},{"old_version":"3.1.5","new_version":"3.1.7","update_type":"patch","path":null,"pr_created_at":"2026-09-13T12:03:05.000Z","version_change":"3.1.5 → 3.1.7","issue":{"uuid":"5439925042","node_id":"PR_kwDOPmcHEM8AAAABDVQnVg","number":248,"state":"open","title":"build(deps): bump the npm_and_yarn group across 1 directory with 2 updates","user":"dependabot[bot]","labels":["dependencies","javascript","size/XS"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-13T12:03:05.000Z","updated_at":"2026-09-13T12:03:11.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"npm_and_yarn","update_count":2,"packages":[{"name":"fast-uri","old_version":"3.1.5","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"js-yaml","old_version":"4.3.1","new_version":"4.3.2"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 1 update in the / directory: [fast-uri](https://github.com/fastify/fast-uri).\n\nUpdates `fast-uri` from 3.1.5 to 3.1.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `js-yaml` from 4.3.1 to 4.3.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md\"\u003ejs-yaml's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.3.2 - 2026-08-26\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Hard-limit merge sequence size to 100.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Count empty mappings in merge sequences toward \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e\nto limit CPU usage, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/797\"\u003e#797\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/79ca68d90f333fbe6d9e42827527e62636200191\"\u003e\u003ccode\u003e79ca68d\u003c/code\u003e\u003c/a\u003e 4.3.2 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/d90b6612a5a84385bdcb556c44578eac76dc0f6b\"\u003e\u003ccode\u003ed90b661\u003c/code\u003e\u003c/a\u003e Backport merge limits from v5.4.1\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodeca/js-yaml/compare/4.3.1...4.3.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/LarsArtmann/typespec-asyncapi/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/LarsArtmann/typespec-asyncapi/pull/248","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/LarsArtmann%2Ftypespec-asyncapi/issues/248","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/248/packages"}},{"old_version":"3.1.0","new_version":"3.1.7","update_type":"patch","path":null,"pr_created_at":"2026-09-13T11:39:46.000Z","version_change":"3.1.0 → 3.1.7","issue":{"uuid":"5439815033","node_id":"PR_kwDOQxPRE88AAAABDVLNwA","number":6,"state":"open","title":"Bump the npm_and_yarn group across 1 directory with 13 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":5,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-13T11:39:46.000Z","updated_at":"2026-09-13T11:40:10.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"npm_and_yarn","update_count":13,"packages":[{"name":"@modelcontextprotocol/sdk","old_version":"1.25.1","new_version":"1.26.0","repository_url":"https://github.com/modelcontextprotocol/typescript-sdk"},{"name":"uuid","old_version":"9.0.1","new_version":"14.0.0","repository_url":"https://github.com/uuidjs/uuid"},{"name":"brace-expansion","old_version":"1.1.12","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"ajv","old_version":"6.12.6","new_version":"6.15.0","repository_url":"https://github.com/ajv-validator/ajv"},{"name":"body-parser","old_version":"2.2.1","new_version":"2.3.0","repository_url":"https://github.com/expressjs/body-parser"},{"name":"body-parser","old_version":"1.20.4","new_version":"1.20.8","repository_url":"https://github.com/expressjs/body-parser"},{"name":"fast-uri","old_version":"3.1.0","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"flatted","old_version":"3.3.3","new_version":"3.4.4","repository_url":"https://github.com/WebReflection/flatted"},{"name":"js-yaml","old_version":"4.1.1","new_version":"4.3.2","repository_url":"https://github.com/nodeca/js-yaml"},{"name":"path-to-regexp","old_version":"8.3.0","new_version":"8.4.2","repository_url":"https://github.com/pillarjs/path-to-regexp"},{"name":"path-to-regexp","old_version":"0.1.12","new_version":"0.1.13","repository_url":"https://github.com/pillarjs/path-to-regexp"},{"name":"picomatch","old_version":"2.3.1","new_version":"2.3.2","repository_url":"https://github.com/micromatch/picomatch"},{"name":"qs","old_version":"6.14.1","new_version":"6.16.0","repository_url":"https://github.com/ljharb/qs"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 11 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.25.1` | `1.26.0` |\n| [uuid](https://github.com/uuidjs/uuid) | `9.0.1` | `14.0.0` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.12` | `1.1.18` |\n| [ajv](https://github.com/ajv-validator/ajv) | `6.12.6` | `6.15.0` |\n| [body-parser](https://github.com/expressjs/body-parser) | `2.2.1` | `2.3.0` |\n| [body-parser](https://github.com/expressjs/body-parser) | `1.20.4` | `1.20.8` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.0` | `3.1.7` |\n| [flatted](https://github.com/WebReflection/flatted) | `3.3.3` | `3.4.4` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.1` | `4.3.2` |\n| [path-to-regexp](https://github.com/pillarjs/path-to-regexp) | `8.3.0` | `8.4.2` |\n| [path-to-regexp](https://github.com/pillarjs/path-to-regexp) | `0.1.12` | `0.1.13` |\n| [picomatch](https://github.com/micromatch/picomatch) | `2.3.1` | `2.3.2` |\n| [qs](https://github.com/ljharb/qs) | `6.14.1` | `6.16.0` |\n\n\nUpdates `@modelcontextprotocol/sdk` from 1.25.1 to 1.26.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/releases\"\u003e@​modelcontextprotocol/sdk's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.26.0\u003c/h2\u003e\n\u003cp\u003eAddresses \u0026quot;Sharing server/transport instances can leak cross-client response data\u0026quot; in this GHSA \u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/security/advisories/GHSA-345p-7cg4-v4c7\"\u003ehttps://github.com/modelcontextprotocol/typescript-sdk/security/advisories/GHSA-345p-7cg4-v4c7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore: bump v1.25.3 for backport fixes by \u003ca href=\"https://github.com/pcarleton\"\u003e\u003ccode\u003e@​pcarleton\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1412\"\u003emodelcontextprotocol/typescript-sdk#1412\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(deps): resolve npm audit vulnerabilities and bump dependencies (v1.x backport) by \u003ca href=\"https://github.com/samuv\"\u003e\u003ccode\u003e@​samuv\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1382\"\u003emodelcontextprotocol/typescript-sdk#1382\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1430\"\u003e#1430\u003c/a\u003e: Client Credentials providers scopes support (backported) by \u003ca href=\"https://github.com/NSeydoux\"\u003e\u003ccode\u003e@​NSeydoux\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1442\"\u003emodelcontextprotocol/typescript-sdk#1442\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump version to 1.26.0 by \u003ca href=\"https://github.com/pcarleton\"\u003e\u003ccode\u003e@​pcarleton\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1479\"\u003emodelcontextprotocol/typescript-sdk#1479\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/samuv\"\u003e\u003ccode\u003e@​samuv\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1382\"\u003emodelcontextprotocol/typescript-sdk#1382\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NSeydoux\"\u003e\u003ccode\u003e@​NSeydoux\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1442\"\u003emodelcontextprotocol/typescript-sdk#1442\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/compare/v1.25.3...v1.26.0\"\u003ehttps://github.com/modelcontextprotocol/typescript-sdk/compare/v1.25.3...v1.26.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.25.3\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[v1.x backport] Use correct schema for client sampling validation when tools are present by \u003ca href=\"https://github.com/olaservo\"\u003e\u003ccode\u003e@​olaservo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1407\"\u003emodelcontextprotocol/typescript-sdk#1407\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: prevent Hono from overriding global Response object (v1.x) by \u003ca href=\"https://github.com/mattzcarey\"\u003e\u003ccode\u003e@​mattzcarey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1411\"\u003emodelcontextprotocol/typescript-sdk#1411\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/compare/v1.25.2...v1.25.3\"\u003ehttps://github.com/modelcontextprotocol/typescript-sdk/compare/v1.25.2...v1.25.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.25.2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eci: trigger workflow on v1.x branch by \u003ca href=\"https://github.com/felixweinberger\"\u003e\u003ccode\u003e@​felixweinberger\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1319\"\u003emodelcontextprotocol/typescript-sdk#1319\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: README badges links destinations by \u003ca href=\"https://github.com/antonpk1\"\u003e\u003ccode\u003e@​antonpk1\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/907\"\u003emodelcontextprotocol/typescript-sdk#907\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: prevent ReDoS in UriTemplate regex patterns (v1.x backport) by \u003ca href=\"https://github.com/pcarleton\"\u003e\u003ccode\u003e@​pcarleton\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1365\"\u003emodelcontextprotocol/typescript-sdk#1365\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/antonpk1\"\u003e\u003ccode\u003e@​antonpk1\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/907\"\u003emodelcontextprotocol/typescript-sdk#907\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/compare/1.25.1...v1.25.2\"\u003ehttps://github.com/modelcontextprotocol/typescript-sdk/compare/1.25.1...v1.25.2\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/fe9c07b465871394c7069207c86513df9c1194a4\"\u003e\u003ccode\u003efe9c07b\u003c/code\u003e\u003c/a\u003e chore: bump version to 1.26.0 (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1479\"\u003e#1479\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/4f01e7e0708e1a85ccc7dbf39e850005f2d9ff03\"\u003e\u003ccode\u003e4f01e7e\u003c/code\u003e\u003c/a\u003e fix: add non-null assertions for optional setupServer fields in stateful test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/a05be176cabeae1f933b676e3ce024bf02e2314d\"\u003e\u003ccode\u003ea05be17\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/50d9fa3cd12e807e7963bcb9e1548786d3d5d941\"\u003e\u003ccode\u003e50d9fa3\u003c/code\u003e\u003c/a\u003e Fix \u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1430\"\u003e#1430\u003c/a\u003e: Client Credentials providers scopes support (backported) (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1442\"\u003e#1442\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/aa81a66556fb4434d8a6d1b70f7ac9fc40b5d325\"\u003e\u003ccode\u003eaa81a66\u003c/code\u003e\u003c/a\u003e fix(deps): resolve npm audit vulnerabilities and bump dependencies (v1.x back...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/6aba0659654e1ff0699844524595922a61e44cb9\"\u003e\u003ccode\u003e6aba065\u003c/code\u003e\u003c/a\u003e chore: bump v1.25.3 for backport fixes (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1412\"\u003e#1412\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/6e8f7e1a43a819ae230373c62b82228dafd892c6\"\u003e\u003ccode\u003e6e8f7e1\u003c/code\u003e\u003c/a\u003e fix: prevent Hono from overriding global Response object (v1.x) (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1411\"\u003e#1411\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/12ae856cee6ca58499cce24e80f650e78a0c7610\"\u003e\u003ccode\u003e12ae856\u003c/code\u003e\u003c/a\u003e [v1.x backport] Use correct schema for client sampling validation when tools ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/b392f02ffcf37c088dbd114fedf25026ec3913d3\"\u003e\u003ccode\u003eb392f02\u003c/code\u003e\u003c/a\u003e fix: prevent ReDoS in UriTemplate regex patterns (v1.x backport) (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1365\"\u003e#1365\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/commit/a0c9b13484748acab9e5dc8317a7e89c06b52e37\"\u003e\u003ccode\u003ea0c9b13\u003c/code\u003e\u003c/a\u003e fix: README badges links destinations (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/907\"\u003e#907\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/modelcontextprotocol/typescript-sdk/compare/1.25.1...v1.26.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `uuid` from 9.0.1 to 14.0.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/uuidjs/uuid/releases\"\u003euuid's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev14.0.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/uuidjs/uuid/compare/v13.0.0...v14.0.0\"\u003e14.0.0\u003c/a\u003e (2026-04-19)\u003c/h2\u003e\n\u003ch3\u003e⚠ BREAKING CHANGES\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eexpect \u003ccode\u003ecrypto\u003c/code\u003e to be global everywhere (requires node@20+) (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/935\"\u003e#935\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edrop node@18 support (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/934\"\u003e#934\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003edrop node@18 support (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/934\"\u003e#934\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/dc4ddb87272ed2843faccd130bcc41d492688bd3\"\u003edc4ddb8\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eexpect \u003ccode\u003ecrypto\u003c/code\u003e to be global everywhere (requires node@20+) (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/935\"\u003e#935\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/f2c235f93059325fa43e1106e624b5291bb523c4\"\u003ef2c235f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUse GITHUB_TOKEN for release-please and enable npm provenance (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/925\"\u003e#925\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/ffa31383e8e4e1f0b4e22e504561272041b8738c\"\u003effa3138\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev13.0.2\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/uuidjs/uuid/compare/v13.0.1...v13.0.2\"\u003e13.0.2\u003c/a\u003e (2026-05-04)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ererelease to fix provenance. (\u003ca href=\"https://github.com/uuidjs/uuid/commit/49ccb35f78c0c4ce1409dd2f1d89f83caadba10b\"\u003e49ccb35\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev13.0.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/uuidjs/uuid/compare/v13.0.0...v13.0.1\"\u003e13.0.1\u003c/a\u003e (2026-04-27)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ebackport fix for GHSA-w5hq-g745-h8pq (\u003ca href=\"https://github.com/uuidjs/uuid/commit/9d27ddf7046ce496ef39569ff84d948eeff9cb2a\"\u003e9d27ddf\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev13.0.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/uuidjs/uuid/compare/v12.0.0...v13.0.0\"\u003e13.0.0\u003c/a\u003e (2025-09-08)\u003c/h2\u003e\n\u003ch3\u003e⚠ BREAKING CHANGES\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003emake browser exports the default (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/901\"\u003e#901\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003emake browser exports the default (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/901\"\u003e#901\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/bce9d72a3ae5b9a3dcd8eb21ef6d1820288a427a\"\u003ebce9d72\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev12.0.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/uuidjs/uuid/compare/v12.0.0...v12.0.1\"\u003e12.0.1\u003c/a\u003e (2026-04-29)\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md\"\u003euuid's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/uuidjs/uuid/compare/v13.0.0...v14.0.0\"\u003e14.0.0\u003c/a\u003e (2026-04-19)\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixes \u003ca href=\"https://github.com/uuidjs/uuid/security/advisories/GHSA-w5hq-g745-h8pq\"\u003eGHSA-w5hq-g745-h8pq\u003c/a\u003e: \u003ccode\u003ev3()\u003c/code\u003e, \u003ccode\u003ev5()\u003c/code\u003e, and \u003ccode\u003ev6()\u003c/code\u003e did not validate that writes would remain within the bounds of a caller-supplied buffer, allowing out-of-bounds writes when an invalid \u003ccode\u003eoffset\u003c/code\u003e was provided. A \u003ccode\u003eRangeError\u003c/code\u003e is now thrown if \u003ccode\u003eoffset \u0026lt; 0\u003c/code\u003e or \u003ccode\u003eoffset + 16 \u0026gt; buf.length\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e⚠ BREAKING CHANGES\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ecrypto\u003c/code\u003e is now expected to be globally defined (requires node@20+) (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/935\"\u003e#935\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edrop node@18 support (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/934\"\u003e#934\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupgrade minimum supported TypeScript version to 5.4.3, in keeping with the project's policy of supporting TypeScript versions released within the last two years\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/uuidjs/uuid/compare/v12.0.0...v13.0.0\"\u003e13.0.0\u003c/a\u003e (2025-09-08)\u003c/h2\u003e\n\u003ch3\u003e⚠ BREAKING CHANGES\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003emake browser exports the default (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/901\"\u003e#901\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003emake browser exports the default (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/901\"\u003e#901\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/bce9d72a3ae5b9a3dcd8eb21ef6d1820288a427a\"\u003ebce9d72\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/uuidjs/uuid/compare/v11.1.0...v12.0.0\"\u003e12.0.0\u003c/a\u003e (2025-09-05)\u003c/h2\u003e\n\u003ch3\u003e⚠ BREAKING CHANGES\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eupdate to typescript@5.2 (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/887\"\u003e#887\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eremove CommonJS support (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/886\"\u003e#886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edrop node@16 support (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/883\"\u003e#883\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eadd node@24 to ci matrix (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/879\"\u003e#879\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/42b6178aa21a593257f0a72abacd220f0b7b8a92\"\u003e42b6178\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edrop node@16 support (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/883\"\u003e#883\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/0f38cf10366ab074f9328ae2021eea04d5f2e530\"\u003e0f38cf1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eremove CommonJS support (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/886\"\u003e#886\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/ae786e27265f50bcf7cead196c29f1869297c42f\"\u003eae786e2\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate to typescript@5.2 (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/887\"\u003e#887\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/c7ee40598ed78584d81ab78dffded9fe5ff20b01\"\u003ec7ee405\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eimprove v4() performance (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/894\"\u003e#894\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/5fd974c12718c8848035650b69b8948f12ace197\"\u003e5fd974c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erestore node: prefix (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/889\"\u003e#889\u003c/a\u003e) (\u003ca href=\"https://github.com/uuidjs/uuid/commit/e1f42a354593093ba0479f0b4047dae82d28c507\"\u003ee1f42a3\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/uuidjs/uuid/compare/v11.0.5...v11.1.0\"\u003e11.1.0\u003c/a\u003e (2025-02-19)\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uuidjs/uuid/commit/7c1ea087a8149b57380fc8bb7f68c3a215cb6e4b\"\u003e\u003ccode\u003e7c1ea08\u003c/code\u003e\u003c/a\u003e chore(main): release 14.0.0 (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/926\"\u003e#926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uuidjs/uuid/commit/3d2c5b0342f0fcb52a5ac681c3d47c13e7444b34\"\u003e\u003ccode\u003e3d2c5b0\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uuidjs/uuid/commit/f2c235f93059325fa43e1106e624b5291bb523c4\"\u003e\u003ccode\u003ef2c235f\u003c/code\u003e\u003c/a\u003e fix!: expect \u003ccode\u003ecrypto\u003c/code\u003e to be global everywhere (requires node@20+) (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/935\"\u003e#935\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uuidjs/uuid/commit/529ef0899f5dd503d2ee90d690585d63d78bc212\"\u003e\u003ccode\u003e529ef08\u003c/code\u003e\u003c/a\u003e chore: upgrade TypeScript and fixup types (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/927\"\u003e#927\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uuidjs/uuid/commit/086fd7976f11433edf9ac80be876b3ad243fe087\"\u003e\u003ccode\u003e086fd79\u003c/code\u003e\u003c/a\u003e chore: update dependencies (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/933\"\u003e#933\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uuidjs/uuid/commit/dc4ddb87272ed2843faccd130bcc41d492688bd3\"\u003e\u003ccode\u003edc4ddb8\u003c/code\u003e\u003c/a\u003e feat!: drop node@18 support (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/934\"\u003e#934\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uuidjs/uuid/commit/0f1f9c9c9cedbae5a1d363d5406c5dfbabe81404\"\u003e\u003ccode\u003e0f1f9c9\u003c/code\u003e\u003c/a\u003e chore: switch to Biome for parsing and linting (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/932\"\u003e#932\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uuidjs/uuid/commit/e2879e64bf125add903c1eff6e0860542c605013\"\u003e\u003ccode\u003ee2879e6\u003c/code\u003e\u003c/a\u003e chore: use maintained version of npm-run-all (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/930\"\u003e#930\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uuidjs/uuid/commit/ffa31383e8e4e1f0b4e22e504561272041b8738c\"\u003e\u003ccode\u003effa3138\u003c/code\u003e\u003c/a\u003e fix: Use GITHUB_TOKEN for release-please and enable npm provenance (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/925\"\u003e#925\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uuidjs/uuid/commit/0423d49df2dc8efc300c804731d25f4d7e0fccc4\"\u003e\u003ccode\u003e0423d49\u003c/code\u003e\u003c/a\u003e docs: remove obsolete v1 option notes (\u003ca href=\"https://redirect.github.com/uuidjs/uuid/issues/915\"\u003e#915\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/uuidjs/uuid/compare/v9.0.1...v14.0.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for uuid since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eInstall script changes\u003c/summary\u003e\n\u003cp\u003eThis version adds \u003ccode\u003eprepare\u003c/code\u003e script that runs during installation. Review the package contents before updating.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.12 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24\"\u003e\u003ccode\u003e2203f4f\u003c/code\u003e\u003c/a\u003e 1.1.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd\"\u003e\u003ccode\u003e0b09384\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/10c05fcf3699b1a29ef5e611c011af3d3c97e6e3\"\u003e\u003ccode\u003e10c05fc\u003c/code\u003e\u003c/a\u003e 1.1.14\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.12...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@hono/node-server` from 1.19.7 to 1.19.17\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/honojs/node-server/releases\"\u003e@​hono/node-server's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.19.17\u003c/h2\u003e\n\u003cp\u003eNo release notes provided.\u003c/p\u003e\n\u003ch2\u003ev1.19.14\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: add custom inspect to lightweight Request/Response to prevent TypeError on console.log by \u003ca href=\"https://github.com/usualoma\"\u003e\u003ccode\u003e@​usualoma\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/340\"\u003ehonojs/node-server#340\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/node-server/compare/v1.19.13...v1.19.14\"\u003ehttps://github.com/honojs/node-server/compare/v1.19.13...v1.19.14\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.19.13\u003c/h2\u003e\n\u003ch2\u003eSecurity Fix\u003c/h2\u003e\n\u003cp\u003eFixed an issue in Serve Static Middleware where inconsistent handling of repeated slashes (\u003ccode\u003e//\u003c/code\u003e) between the router and static file resolution could allow middleware to be bypassed. Users of Serve Static Middleware are encouraged to upgrade to this version.\u003c/p\u003e\n\u003cp\u003eSee GHSA-92pp-h63x-v22m for details.\u003c/p\u003e\n\u003ch2\u003ev1.19.12\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore: ignore claude setting by \u003ca href=\"https://github.com/yusukebe\"\u003e\u003ccode\u003e@​yusukebe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/314\"\u003ehonojs/node-server#314\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: request draining for early 413 responses by \u003ca href=\"https://github.com/usualoma\"\u003e\u003ccode\u003e@​usualoma\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/329\"\u003ehonojs/node-server#329\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/node-server/compare/v1.19.11...v1.19.12\"\u003ehttps://github.com/honojs/node-server/compare/v1.19.11...v1.19.12\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.19.11\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: do not overwrite Content-Length in the fast path pattern if Content-Length already exists. by \u003ca href=\"https://github.com/usualoma\"\u003e\u003ccode\u003e@​usualoma\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/309\"\u003ehonojs/node-server#309\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/node-server/compare/v1.19.10...v1.19.11\"\u003ehttps://github.com/honojs/node-server/compare/v1.19.10...v1.19.11\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.19.10\u003c/h2\u003e\n\u003ch2\u003eSecurity Fix\u003c/h2\u003e\n\u003cp\u003eFixed an authorization bypass in Serve Static Middleware caused by inconsistent URL decoding (\u003ccode\u003e%2F\u003c/code\u003e handling) between the router and static file resolution. Users of Serve Static Middleware are encouraged to upgrade to this version.\u003c/p\u003e\n\u003cp\u003eSee GHSA-wc8c-qw6v-h7f6 for details.\u003c/p\u003e\n\u003ch2\u003ev1.19.9\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(globals): Stop overwriting global.fetch by \u003ca href=\"https://github.com/usualoma\"\u003e\u003ccode\u003e@​usualoma\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/295\"\u003ehonojs/node-server#295\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/honojs/node-server/compare/v1.19.8...v1.19.9\"\u003ehttps://github.com/honojs/node-server/compare/v1.19.8...v1.19.9\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.19.8\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocs: add guide for listening to UNIX domain socket by \u003ca href=\"https://github.com/TransparentLC\"\u003e\u003ccode\u003e@​TransparentLC\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/292\"\u003ehonojs/node-server#292\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(serve-static): Use Readable.toWeb in serveStatic by \u003ca href=\"https://github.com/otya128\"\u003e\u003ccode\u003e@​otya128\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/honojs/node-server/pull/293\"\u003ehonojs/node-server#293\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/71941daede982571f18d2774951f37c475cccefc\"\u003e\u003ccode\u003e71941da\u003c/code\u003e\u003c/a\u003e 1.19.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/0208500d8f11b33dd03b50c86df8e132307adf1e\"\u003e\u003ccode\u003e0208500\u003c/code\u003e\u003c/a\u003e ci: add \u003ccode\u003estage\u003c/code\u003e option for publishing (\u003ca href=\"https://redirect.github.com/honojs/node-server/issues/386\"\u003e#386\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/cbdf713a67ef38f6a5304488e294381230a52e46\"\u003e\u003ccode\u003ecbdf713\u003c/code\u003e\u003c/a\u003e 1.19.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/86e96c24045411b3e3c4a9b61a4c1e755c398a44\"\u003e\u003ccode\u003e86e96c2\u003c/code\u003e\u003c/a\u003e ci: add an action for trusted publisher (\u003ca href=\"https://redirect.github.com/honojs/node-server/issues/385\"\u003e#385\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/99c1a1abd702132302f3da72600d383a25eba32c\"\u003e\u003ccode\u003e99c1a1a\u003c/code\u003e\u003c/a\u003e ci: run on v1.x branch pushes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/84cb2ee25f567d812b76e0cff4c36899acb157eb\"\u003e\u003ccode\u003e84cb2ee\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/b5e63a366d9b0ef62ac65fcafd7f69b383b03ff5\"\u003e\u003ccode\u003eb5e63a3\u003c/code\u003e\u003c/a\u003e 1.19.14\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/c02d7770a2d29ea473403211bef0a60639885a28\"\u003e\u003ccode\u003ec02d777\u003c/code\u003e\u003c/a\u003e fix: add custom inspect to lightweight Request/Response to prevent TypeError ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/fd64e659a34ec661fd9ccda00d1b9dff88dfaf90\"\u003e\u003ccode\u003efd64e65\u003c/code\u003e\u003c/a\u003e 1.19.13\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/honojs/node-server/commit/025c30f55d589ddbe6048b151d77e904f67a8cc2\"\u003e\u003ccode\u003e025c30f\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/honojs/node-server/compare/v1.19.7...v1.19.17\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​hono/node-server\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ajv` from 6.12.6 to 6.15.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ajv-validator/ajv/commit/184bc32745d9d33b2322949b9f3cb5f7609bf5ec\"\u003e\u003ccode\u003e184bc32\u003c/code\u003e\u003c/a\u003e 6.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ajv-validator/ajv/commit/fea46afd1a76b12ff89493f6dc1bc46730c6d379\"\u003e\u003ccode\u003efea46af\u003c/code\u003e\u003c/a\u003e test/fix prototype pollution via $data ref with format keyword (\u003ca href=\"https://redirect.github.com/ajv-validator/ajv/issues/2606\"\u003e#2606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ajv-validator/ajv/commit/e3af0a723b4b7ad86eff43be355c706d31e0e915\"\u003e\u003ccode\u003ee3af0a7\u003c/code\u003e\u003c/a\u003e 6.14.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ajv-validator/ajv/commit/b552ed66191eb338498df3196065c777e3bb71f2\"\u003e\u003ccode\u003eb552ed6\u003c/code\u003e\u003c/a\u003e add regExp option to address $data exploit via a regular expression (CVE-2025...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ajv-validator/ajv/commit/72f228665859eed5e2be3a66f8c4a7aff6b34dcf\"\u003e\u003ccode\u003e72f2286\u003c/code\u003e\u003c/a\u003e docs: update v7 info\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ajv-validator/ajv/commit/231e52b3bca62559202b95e5fb5cee02145b226a\"\u003e\u003ccode\u003e231e52b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/ajv-validator/ajv/issues/1320\"\u003e#1320\u003c/a\u003e from philsturgeon/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ajv-validator/ajv/commit/d3475fc20416c33fe030c8aa3b09fa411f325bbd\"\u003e\u003ccode\u003ed3475fc\u003c/code\u003e\u003c/a\u003e Add spectral, an AJV util from a sponsor\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ajv-validator/ajv/commit/413afe01f518ea74d1740a7cb211df787c585544\"\u003e\u003ccode\u003e413afe0\u003c/code\u003e\u003c/a\u003e docs: v7.0.0-beta.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ajv-validator/ajv/commit/11e997bda2f3eecb445c1e5a07d96ef7e81c5f5d\"\u003e\u003ccode\u003e11e997b\u003c/code\u003e\u003c/a\u003e update readme for v7\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/ajv-validator/ajv/compare/v6.12.6...v6.15.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `body-parser` from 2.2.1 to 2.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/body-parser/releases\"\u003ebody-parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.3.0\u003c/h2\u003e\n\u003ch2\u003eImportant: Security\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity fix for \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2025-13466\"\u003eCVE-2026-12590\u003c/a\u003e (\u003ca href=\"https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6\"\u003eGHSA-v422-hmwv-36x6\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps): bump actions/download-artifact from 6.0.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/681\"\u003eexpressjs/body-parser#681\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/checkout from 5.0.0 to 6.0.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/682\"\u003eexpressjs/body-parser#682\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.0.0 to 6.1.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/683\"\u003eexpressjs/body-parser#683\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/685\"\u003eexpressjs/body-parser#685\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.31.2 to 4.31.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/684\"\u003eexpressjs/body-parser#684\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf(urlencoded): move empty-body guard to avoid extra function closure by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/647\"\u003eexpressjs/body-parser#647\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove ESM compatibility by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/697\"\u003eexpressjs/body-parser#697\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: add recommendations for configuring payload limits by \u003ca href=\"https://github.com/bjohansebas\"\u003e\u003ccode\u003e@​bjohansebas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/699\"\u003eexpressjs/body-parser#699\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.1.0 to 6.2.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/701\"\u003eexpressjs/body-parser#701\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.31.10 to 4.32.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/702\"\u003eexpressjs/body-parser#702\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/checkout from 6.0.1 to 6.0.2 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/700\"\u003eexpressjs/body-parser#700\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore:  add explicit type commonjs to package.json by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/711\"\u003eexpressjs/body-parser#711\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edeps: update dependencies to latest versions by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/708\"\u003eexpressjs/body-parser#708\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/download-artifact from 7.0.0 to 8.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/712\"\u003eexpressjs/body-parser#712\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.32.0 to 4.32.4 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/713\"\u003eexpressjs/body-parser#713\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/714\"\u003eexpressjs/body-parser#714\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: improve limit option validation by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/698\"\u003eexpressjs/body-parser#698\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.32.4 to 4.35.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/719\"\u003eexpressjs/body-parser#719\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.2.0 to 6.3.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/718\"\u003eexpressjs/body-parser#718\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/download-artifact from 8.0.0 to 8.0.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/717\"\u003eexpressjs/body-parser#717\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: eliminate conditional check in json strict mode hot path by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/651\"\u003eexpressjs/body-parser#651\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: add node.js 26 to text matrix by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/726\"\u003eexpressjs/body-parser#726\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.3.0 to 6.4.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/725\"\u003eexpressjs/body-parser#725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/724\"\u003eexpressjs/body-parser#724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.35.1 to 4.35.3 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/723\"\u003eexpressjs/body-parser#723\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade \u0026quot;content-type\u0026quot; by \u003ca href=\"https://github.com/blakeembrey\"\u003e\u003ccode\u003e@​blakeembrey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/728\"\u003eexpressjs/body-parser#728\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor: switch to const/let and enable eslint no-var rule by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/729\"\u003eexpressjs/body-parser#729\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate outdated reference to MDN docs by \u003ca href=\"https://github.com/krzysdz\"\u003e\u003ccode\u003e@​krzysdz\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/730\"\u003eexpressjs/body-parser#730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.35.3 to 4.36.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/731\"\u003eexpressjs/body-parser#731\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/checkout from 6.0.2 to 6.0.3 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/732\"\u003eexpressjs/body-parser#732\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: updated deps to latest by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/733\"\u003eexpressjs/body-parser#733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e2.3.0 by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/735\"\u003eexpressjs/body-parser#735\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/krzysdz\"\u003e\u003ccode\u003e@​krzysdz\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/730\"\u003eexpressjs/body-parser#730\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/v2.2.2...v2.3.0\"\u003ehttps://github.com/expressjs/body-parser/compare/v2.2.2...v2.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.2.2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocs: update README links by \u003ca href=\"https://github.com/efekrskl\"\u003e\u003ccode\u003e@​efekrskl\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/673\"\u003eexpressjs/body-parser#673\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: release notes for the v1.20.4 release by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/674\"\u003eexpressjs/body-parser#674\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: update URL-encoded parser description to include ISO-8859-1 encoding support by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/679\"\u003eexpressjs/body-parser#679\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: use standard jsdoc tags everywhere by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/677\"\u003eexpressjs/body-parser#677\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/body-parser/blob/master/HISTORY.md\"\u003ebody-parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e2.3.0 / 2026-06-15\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity fix for \u003ca href=\"https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6\"\u003eGHSA-v422-hmwv-36x6\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: use static exports instead of lazy getters to improve ESM compatibility\u003c/li\u003e\n\u003cli\u003efeat: add subpath exports for individual parsers\u003c/li\u003e\n\u003cli\u003efix: improve \u003ccode\u003elimit\u003c/code\u003e option validation (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/698\"\u003e#698\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003eInvalid \u003ccode\u003elimit\u003c/code\u003e values (e.g. unparseable strings or \u003ccode\u003eNaN\u003c/code\u003e) now throw instead of being silently ignored, which previously disabled size limit enforcement\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003enull\u003c/code\u003e and \u003ccode\u003eundefined\u003c/code\u003e fall back to the default 100kb limit\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003edeps:\n\u003cul\u003e\n\u003cli\u003econtent-type@^2.0.0\u003c/li\u003e\n\u003cli\u003ehttp-errors@^2.0.1\u003c/li\u003e\n\u003cli\u003eiconv-lite^0.7.2\u003c/li\u003e\n\u003cli\u003eqs@^6.15.2\u003c/li\u003e\n\u003cli\u003eraw-body@^3.0.2\u003c/li\u003e\n\u003cli\u003etype-is@^2.1.0\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e2.2.2 / 2026-01-07\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003edeps: qs@^6.14.1\u003c/li\u003e\n\u003cli\u003erefactor(json): simplify strict mode error string construction\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/d0f2ace6c74769da7d19b8661b9a01c01bdb0bf7\"\u003e\u003ccode\u003ed0f2ace\u003c/code\u003e\u003c/a\u003e 2.3.0 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/735\"\u003e#735\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/7d03f2f9d561dafd1576b137713353c95253512c\"\u003e\u003ccode\u003e7d03f2f\u003c/code\u003e\u003c/a\u003e chore: updated deps to latest (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/733\"\u003e#733\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/8024ba7a813e6647ed63832d209a2abb8531267a\"\u003e\u003ccode\u003e8024ba7\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/checkout from 6.0.2 to 6.0.3 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/732\"\u003e#732\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/32b4ed4639281f04563adcd41d724ab06c9105d4\"\u003e\u003ccode\u003e32b4ed4\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action from 4.35.3 to 4.36.1 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/731\"\u003e#731\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/ff0f6b907106ec5a1b81c80f5a552d921c1bc9a5\"\u003e\u003ccode\u003eff0f6b9\u003c/code\u003e\u003c/a\u003e docs: update outdated reference to MDN docs (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/730\"\u003e#730\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/14d001a9c90abc05891d895ad3e9cf0a65b7b34a\"\u003e\u003ccode\u003e14d001a\u003c/code\u003e\u003c/a\u003e refactor: switch to const/let and enable eslint no-var rule (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/729\"\u003e#729\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/37f36a27528e65d7216f2c31c7039d3458c72147\"\u003e\u003ccode\u003e37f36a2\u003c/code\u003e\u003c/a\u003e deps: update content-type and type-is (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/728\"\u003e#728\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/e1c244bf55fb00a6de4be882b4ed9fc20807d864\"\u003e\u003ccode\u003ee1c244b\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action from 4.35.1 to 4.35.3 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/723\"\u003e#723\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/e01087f52192e20e2d0f8726d4f28a8d49d06c87\"\u003e\u003ccode\u003ee01087f\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/724\"\u003e#724\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/a7698d30280a3e931ea8841396e5d0ac5414e429\"\u003e\u003ccode\u003ea7698d3\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/setup-node from 6.3.0 to 6.4.0 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/725\"\u003e#725\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/expressjs/body-parser/compare/v2.2.1...v2.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `body-parser` from 1.20.4 to 1.20.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/body-parser/releases\"\u003ebody-parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.3.0\u003c/h2\u003e\n\u003ch2\u003eImportant: Security\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity fix for \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2025-13466\"\u003eCVE-2026-12590\u003c/a\u003e (\u003ca href=\"https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6\"\u003eGHSA-v422-hmwv-36x6\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps): bump actions/download-artifact from 6.0.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/681\"\u003eexpressjs/body-parser#681\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/checkout from 5.0.0 to 6.0.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/682\"\u003eexpressjs/body-parser#682\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.0.0 to 6.1.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/683\"\u003eexpressjs/body-parser#683\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/685\"\u003eexpressjs/body-parser#685\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.31.2 to 4.31.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/684\"\u003eexpressjs/body-parser#684\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf(urlencoded): move empty-body guard to avoid extra function closure by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/647\"\u003eexpressjs/body-parser#647\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove ESM compatibility by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/697\"\u003eexpressjs/body-parser#697\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: add recommendations for configuring payload limits by \u003ca href=\"https://github.com/bjohansebas\"\u003e\u003ccode\u003e@​bjohansebas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/699\"\u003eexpressjs/body-parser#699\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.1.0 to 6.2.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/701\"\u003eexpressjs/body-parser#701\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.31.10 to 4.32.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/702\"\u003eexpressjs/body-parser#702\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/checkout from 6.0.1 to 6.0.2 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/700\"\u003eexpressjs/body-parser#700\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore:  add explicit type commonjs to package.json by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/711\"\u003eexpressjs/body-parser#711\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edeps: update dependencies to latest versions by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/708\"\u003eexpressjs/body-parser#708\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/download-artifact from 7.0.0 to 8.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/712\"\u003eexpressjs/body-parser#712\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.32.0 to 4.32.4 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/713\"\u003eexpressjs/body-parser#713\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/714\"\u003eexpressjs/body-parser#714\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: improve limit option validation by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/698\"\u003eexpressjs/body-parser#698\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.32.4 to 4.35.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/719\"\u003eexpressjs/body-parser#719\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.2.0 to 6.3.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/718\"\u003eexpressjs/body-parser#718\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/download-artifact from 8.0.0 to 8.0.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/717\"\u003eexpressjs/body-parser#717\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: eliminate conditional check in json strict mode hot path by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/651\"\u003eexpressjs/body-parser#651\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: add node.js 26 to text matrix by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/726\"\u003eexpressjs/body-parser#726\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-node from 6.3.0 to 6.4.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/725\"\u003eexpressjs/body-parser#725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/724\"\u003eexpressjs/body-parser#724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.35.1 to 4.35.3 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/723\"\u003eexpressjs/body-parser#723\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade \u0026quot;content-type\u0026quot; by \u003ca href=\"https://github.com/blakeembrey\"\u003e\u003ccode\u003e@​blakeembrey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/728\"\u003eexpressjs/body-parser#728\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor: switch to const/let and enable eslint no-var rule by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/729\"\u003eexpressjs/body-parser#729\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate outdated reference to MDN docs by \u003ca href=\"https://github.com/krzysdz\"\u003e\u003ccode\u003e@​krzysdz\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/730\"\u003eexpressjs/body-parser#730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action from 4.35.3 to 4.36.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/731\"\u003eexpressjs/body-parser#731\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/checkout from 6.0.2 to 6.0.3 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/732\"\u003eexpressjs/body-parser#732\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: updated deps to latest by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/733\"\u003eexpressjs/body-parser#733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e2.3.0 by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/735\"\u003eexpressjs/body-parser#735\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/krzysdz\"\u003e\u003ccode\u003e@​krzysdz\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/730\"\u003eexpressjs/body-parser#730\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/v2.2.2...v2.3.0\"\u003ehttps://github.com/expressjs/body-parser/compare/v2.2.2...v2.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.2.2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocs: update README links by \u003ca href=\"https://github.com/efekrskl\"\u003e\u003ccode\u003e@​efekrskl\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/673\"\u003eexpressjs/body-parser#673\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: release notes for the v1.20.4 release by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/674\"\u003eexpressjs/body-parser#674\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: update URL-encoded parser description to include ISO-8859-1 encoding support by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/679\"\u003eexpressjs/body-parser#679\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: use standard jsdoc tags everywhere by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/677\"\u003eexpressjs/body-parser#677\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/body-parser/blob/master/HISTORY.md\"\u003ebody-parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e2.3.0 / 2026-06-15\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity fix for \u003ca href=\"https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6\"\u003eGHSA-v422-hmwv-36x6\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: use static exports instead of lazy getters to improve ESM compatibility\u003c/li\u003e\n\u003cli\u003efeat: add subpath exports for individual parsers\u003c/li\u003e\n\u003cli\u003efix: improve \u003ccode\u003elimit\u003c/code\u003e option validation (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/698\"\u003e#698\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003eInvalid \u003ccode\u003elimit\u003c/code\u003e values (e.g. unparseable strings or \u003ccode\u003eNaN\u003c/code\u003e) now throw instead of being silently ignored, which previously disabled size limit enforcement\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003enull\u003c/code\u003e and \u003ccode\u003eundefined\u003c/code\u003e fall back to the default 100kb limit\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003edeps:\n\u003cul\u003e\n\u003cli\u003econtent-type@^2.0.0\u003c/li\u003e\n\u003cli\u003ehttp-errors@^2.0.1\u003c/li\u003e\n\u003cli\u003eiconv-lite^0.7.2\u003c/li\u003e\n\u003cli\u003eqs@^6.15.2\u003c/li\u003e\n\u003cli\u003eraw-body@^3.0.2\u003c/li\u003e\n\u003cli\u003etype-is@^2.1.0\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e2.2.2 / 2026-01-07\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003edeps: qs@^6.14.1\u003c/li\u003e\n\u003cli\u003erefactor(json): simplify strict mode error string construction\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/d0f2ace6c74769da7d19b8661b9a01c01bdb0bf7\"\u003e\u003ccode\u003ed0f2ace\u003c/code\u003e\u003c/a\u003e 2.3.0 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/735\"\u003e#735\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/7d03f2f9d561dafd1576b137713353c95253512c\"\u003e\u003ccode\u003e7d03f2f\u003c/code\u003e\u003c/a\u003e chore: updated deps to latest (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/733\"\u003e#733\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/8024ba7a813e6647ed63832d209a2abb8531267a\"\u003e\u003ccode\u003e8024ba7\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/checkout from 6.0.2 to 6.0.3 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/732\"\u003e#732\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/32b4ed4639281f04563adcd41d724ab06c9105d4\"\u003e\u003ccode\u003e32b4ed4\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action from 4.35.3 to 4.36.1 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/731\"\u003e#731\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/ff0f6b907106ec5a1b81c80f5a552d921c1bc9a5\"\u003e\u003ccode\u003eff0f6b9\u003c/code\u003e\u003c/a\u003e docs: update outdated reference to MDN docs (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/730\"\u003e#730\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/14d001a9c90abc05891d895ad3e9cf0a65b7b34a\"\u003e\u003ccode\u003e14d001a\u003c/code\u003e\u003c/a\u003e refactor: switch to const/let and enable eslint no-var rule (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/729\"\u003e#729\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/37f36a27528e65d7216f2c31c7039d3458c72147\"\u003e\u003ccode\u003e37f36a2\u003c/code\u003e\u003c/a\u003e deps: update content-type and type-is (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/728\"\u003e#728\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/e1c244bf55fb00a6de4be882b4ed9fc20807d864\"\u003e\u003ccode\u003ee1c244b\u003c/code\u003e\u003c/a\u003e build(deps): bump github/codeql-action from 4.35.1 to 4.35.3 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/723\"\u003e#723\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/e01087f52192e20e2d0f8726d4f28a8d49d06c87\"\u003e\u003ccode\u003ee01087f\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/724\"\u003e#724\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/a7698d30280a3e931ea8841396e5d0ac5414e429\"\u003e\u003ccode\u003ea7698d3\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/setup-node from 6.3.0 to 6.4.0 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/725\"\u003e#725\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/expressjs/body-parser/compare/v2.2.1...v2.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-uri` from 3.1.0 to 3.1.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.0...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `flatted` from 3.3.3 to 3.4.4\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/e6f5ca700c4ca8104a6a83472c8219e267bd5e84\"\u003e\u003ccode\u003ee6f5ca7\u003c/code\u003e\u003c/a\u003e 3.4.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/47f14fac0b1a41989f216b0cda4c50596ca339f6\"\u003e\u003ccode\u003e47f14fa\u003c/code\u003e\u003c/a\u003e removed E_STRICT from PHP\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/40505688464c49fe6374e7bc4cdd9bd2e9e6f330\"\u003e\u003ccode\u003e4050568\u003c/code\u003e\u003c/a\u003e fixced go-lang issues in CI\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/4303f4db38ba0ba8d5e2ed6e9689cefc74c46b63\"\u003e\u003ccode\u003e4303f4d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/WebReflection/flatted/issues/101\"\u003e#101\u003c/a\u003e from mfinelli/gocriticfixes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/106735b609c15df51539a0d7c0a270182efd904c\"\u003e\u003ccode\u003e106735b\u003c/code\u003e\u003c/a\u003e updated package-lock.json\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/670a1bdf9dcfba02111c3034294366f10696fb53\"\u003e\u003ccode\u003e670a1bd\u003c/code\u003e\u003c/a\u003e 3.4.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/50a61a90ea5ca64c114f0aa040ad127e3a97feff\"\u003e\u003ccode\u003e50a61a9\u003c/code\u003e\u003c/a\u003e Fix \u003ca href=\"https://redirect.github.com/WebReflection/flatted/issues/104\"\u003e#104\u003c/a\u003e - allow \u003ccode\u003enull\u003c/code\u003e as replacer value\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/8aa64f460cf0c4dac9cc214c831aade28f8f2c6e\"\u003e\u003ccode\u003e8aa64f4\u003c/code\u003e\u003c/a\u003e solved crytical errors over dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/b85577f39ff85959d02e8862cc0dde8114b43762\"\u003e\u003ccode\u003eb85577f\u003c/code\u003e\u003c/a\u003e Fix go-critic errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/WebReflection/flatted/commit/bb8c63cea5befd4315519cb4458c6fc07bb9cf7b\"\u003e\u003ccode\u003ebb8c63c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/WebReflection/flatted/issues/100\"\u003e#100\u003c/a\u003e from WebReflection/WebReflection-patch-1\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/WebReflection/flatted/compare/v3.3.3...v3.4.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `hono` from 4.11.3 to 4.13.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/honojs/hono/releases\"\u003ehono's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.13.7\u003c/h2\u003e\n\u003ch2\u003eSecurity fixes\u003c/h2\u003e\n\u003cp\u003eThis release includes a fix for the following security issue:\u003c/p\u003e\n\u003ch3\u003e\u003ccode\u003ehono/jsx\u003c/code\u003e renders plain strings unescaped in boundary components, leading to XSS\u003c/h3\u003e\n\u003cp\u003eAffects: \u003ccode\u003eSuspense\u003c/code\u003e, \u003ccode\u003eErrorBoundary\u003c/code\u003e, and \u003ccode\u003eContext.Provider\u003c/code\u003e in \u003ccode\u003ehono/jsx\u003c/code\u003e, and \u003ccode\u003erenderToString()\u003c/code\u003e / \u003ccode\u003erenderToReadableStream()\u003c/code\u003e in \u003ccode\u003ehono/jsx/dom/server\u003c/code\u003e. Fixes missing HTML escaping for a plain string placed directly as a child or \u003ccode\u003efallback\u003c/code\u003e of these components, or as the root value of the server rendering functions, so untrusted strings could be emitted as markup. GHSA-hxh3-vqpv-xpqv\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003eUsers who render untrusted strings inside \u003ccode\u003eSuspense\u003c/code\u003e, \u003ccode\u003eErrorBoundary\u003c/code\u003e, or \u003ccode\u003eContext.Provider\u003c/code\u003e, or pass them directly to \u003ccode\u003ehono/jsx/dom/server\u003c/code\u003e, are strongly encouraged to upgrade to this version.\u003c/p\u003e\n\u003ch2\u003ev4.13.6\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(client): keep a param value of \u0026quot;index\u0026quot; in $url() and $path() in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5297\"\u003ehonojs/hono#5297\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(client): normalize root WebSocket URLs in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5291\"\u003ehonojs/hono#5291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(types): allow symbol keys in Context\u003c!-- raw HTML omitted --\u003e get and set fallbacks in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5300\"\u003ehonojs/hono#5300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump \u003ccode\u003eeditorconfig-checker\u003c/code\u003e in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5336\"\u003ehonojs/hono#5336\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor(on-handler): use forEach for consistent handler iteration in \u003ca href=\"https://redirect.github.com/honojs/hono/pull/5326\"\u003ehonojs/hono#5326\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong...\n\n_Description has been truncated_","html_url":"https://github.com/canstralian/MCPServerforRedTeamAgenticWorkflowszip/pull/6","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/canstralian%2FMCPServerforRedTeamAgenticWorkflowszip/issues/6","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/6/packages"}},{"old_version":"3.1.0","new_version":"3.1.7","update_type":"patch","path":null,"pr_created_at":"2026-09-13T11:36:28.000Z","version_change":"3.1.0 → 3.1.7","issue":{"uuid":"5439800891","node_id":"PR_kwDOO7ALIM8AAAABDVKiGg","number":24,"state":"open","title":"chore(deps): bump fast-uri from 3.1.0 to 3.1.7","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-13T11:36:28.000Z","updated_at":"2026-09-13T11:36:35.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"fast-uri","old_version":"3.1.0","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"}],"path":null,"ecosystem":"npm"},"body":"Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.0 to 3.1.7.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.0...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=fast-uri\u0026package-manager=npm_and_yarn\u0026previous-version=3.1.0\u0026new-version=3.1.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/executiveusa/claude-task-master/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/executiveusa/claude-task-master/pull/24","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/executiveusa%2Fclaude-task-master/issues/24","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/24/packages"}},{"old_version":"3.1.0","new_version":"3.1.7","update_type":"patch","path":null,"pr_created_at":"2026-09-13T11:30:52.000Z","version_change":"3.1.0 → 3.1.7","issue":{"uuid":"5439774092","node_id":"PR_kwDOQ43m0c8AAAABDVJOtw","number":21,"state":"open","title":"Bump the npm_and_yarn group across 1 directory with 10 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-13T11:30:52.000Z","updated_at":"2026-09-13T11:34:15.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"npm_and_yarn","update_count":10,"packages":[{"name":"next","old_version":"16.2.4","new_version":"16.3.5","repository_url":"https://github.com/vercel/next.js"},{"name":"@babel/core","old_version":"7.29.0","new_version":"7.29.7","repository_url":"https://github.com/babel/babel"},{"name":"@humanfs/node","old_version":"0.16.7","new_version":"0.16.8","repository_url":"https://github.com/humanwhocodes/humanfs"},{"name":"@opentelemetry/core","old_version":"2.6.1","new_version":"2.11.0","repository_url":"https://github.com/open-telemetry/opentelemetry-js"},{"name":"brace-expansion","old_version":"1.1.14","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"fast-uri","old_version":"3.1.0","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"js-yaml","old_version":"4.1.1","new_version":"4.3.2","repository_url":"https://github.com/nodeca/js-yaml"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 7 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [next](https://github.com/vercel/next.js) | `16.2.4` | `16.3.5` |\n| [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) | `7.29.0` | `7.29.7` |\n| [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node) | `0.16.7` | `0.16.8` |\n| [@opentelemetry/core](https://github.com/open-telemetry/opentelemetry-js) | `2.6.1` | `2.11.0` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.14` | `1.1.18` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.0` | `3.1.7` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.1` | `4.3.2` |\n\n\nUpdates `next` from 16.2.4 to 16.3.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003enext's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.5\u003c/h2\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does not include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003enext/image: Skip 0-byte entries when initializing disk LRU cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98185\"\u003e#98185\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enext/image: Reject empty images when reading/writing to the disk cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98186\"\u003e#98186\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEmit whole-app server NFTs when \u003ccode\u003eoutput: 'standalone'\u003c/code\u003e is used with an adapter (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98167\"\u003e#98167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd CSP nonce to script tags of loading and template files (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98403\"\u003e#98403\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003euse cache\u003c/code\u003e prerender signal retention (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98448\"\u003e#98448\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.4\u003c/h2\u003e\n\u003cp\u003eFollow-up release to \u003ca href=\"https://github.com/vercel/next.js/releases/tag/v16.3.3\"\u003ev16.3.3\u003c/a\u003e re-enabling AVIF Image Optimization (\u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97949\"\u003e#97949\u003c/a\u003e).\u003c/p\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003etestmode: Fix infinite recursion in testmode passthrough fetch (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97691\"\u003e#97691\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix build error when aliasing typescript to \u003ccode\u003e@​typescript/typescript6\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97997\"\u003e#97997\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix unset crossOrigin in Turbopack manifests (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97930\"\u003e#97930\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.3\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eCritical:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36\"\u003eUnauthenticated Remote Code Execution on windows-hosted servers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4\"\u003eUnauthenticated Remote Code Execution in Image Optimization API when AVIF files are used\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.2\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Scope app-entry export validation to files inside the app directory (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97357\"\u003e#97357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[backport] Fix catch-all index page being served for every other slug (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97416\"\u003e#97416\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: don't trace embedded WASM loader helpers (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97353\"\u003e#97353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97463\"\u003e#97463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: retain conditions when replacing resolve request keys (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97453\"\u003e#97453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Fix Turbopack worker chunk loading with asset prefix (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97419\"\u003e#97419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97603\"\u003e#97603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/lubieowoce\"\u003e\u003ccode\u003e@​lubieowoce\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[16.x] Turbopack: don't strip async-module runtime from shared runtime chunks by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96653\"\u003evercel/next.js#96653\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/ca2c75eb7f8d9dd012a8bb83c06132149fe221f9\"\u003e\u003ccode\u003eca2c75e\u003c/code\u003e\u003c/a\u003e v16.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/14fb290de65077e9f1e22ef56d8de6cc1e63d436\"\u003e\u003ccode\u003e14fb290\u003c/code\u003e\u003c/a\u003e [backport] Fix use cache prerender signal retention (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98448\"\u003e#98448\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/2b1f28dbe1de344807ec0946a85171bc890a6047\"\u003e\u003ccode\u003e2b1f28d\u003c/code\u003e\u003c/a\u003e [16.3.x] Add CSP nonce to script tags of loading and template files (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98403\"\u003e#98403\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/4b56cee3f01d3b249edcd798b51895d5126a4170\"\u003e\u003ccode\u003e4b56cee\u003c/code\u003e\u003c/a\u003e [16.3.x] Backport docs fixes (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98317\"\u003e#98317\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/5568a02a7d47f9cb088e58350f2c2e68d9e93a00\"\u003e\u003ccode\u003e5568a02\u003c/code\u003e\u003c/a\u003e [backport] docs: local development: Rewrite docker section, add Windows Dev D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/93249ab2144132abfd4a8d611dad5b5978107ee2\"\u003e\u003ccode\u003e93249ab\u003c/code\u003e\u003c/a\u003e [16.3.X] Emit whole-app server NFTs when \u003ccode\u003eoutput: 'standalone'\u003c/code\u003e is used with ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/6549fd7c4e15a8883b0ad1c2ef67dec287a44f12\"\u003e\u003ccode\u003e6549fd7\u003c/code\u003e\u003c/a\u003e [16.3.x] next/image: reject empty image on read/write to disk cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98186\"\u003e#98186\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/d9eac96e7526ff0b9cb51db9801f06e741fe1960\"\u003e\u003ccode\u003ed9eac96\u003c/code\u003e\u003c/a\u003e [16.3.x] next/image: skip 0-byte entries when initializing disk LRU cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/9\"\u003e#9\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/84b35feccb2b53a563e41ad2dfe7a5fe08c58d3f\"\u003e\u003ccode\u003e84b35fe\u003c/code\u003e\u003c/a\u003e [test] Fix 16.3 deploy test assertions (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98133\"\u003e#98133\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/14f9c1ac4e084a44633c354476ddeaf70969cd90\"\u003e\u003ccode\u003e14f9c1a\u003c/code\u003e\u003c/a\u003e [16.3.x][ci] Run flake detection and new deploy tests when merged and on back...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/compare/v16.2.4...v16.3.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for next since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@babel/core` from 7.29.0 to 7.29.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/babel/babel/releases\"\u003e@​babel/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.7 (2026-05-25)\u003c/h2\u003e\n\u003cp\u003eRe-release all packages with npm provenance attestations\u003c/p\u003e\n\u003ch2\u003ev7.29.6 (2026-05-25)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18014\"\u003e#18014\u003c/a\u003e Catchup source map position in preserveFormat (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18001\"\u003e#18001\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e, \u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17998\"\u003e#17998\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 3\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMateusz Burzyński (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.5 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:house:  Internal\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@babel/*\u003c/code\u003e dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.4 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17974\"\u003e#17974\u003c/a\u003e [7.x backport]fix(systemjs): improve module string name support (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 1\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.3 (2026-04-30)\u003c/h2\u003e\n\u003ch4\u003e:eyeglasses: Spec Compliance\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17923\"\u003e#17923\u003c/a\u003e Support flow extends bound (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-helper-create-class-features-plugin\u003c/code\u003e, \u003ccode\u003ebabel-plugin-proposal-decorators\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17931\"\u003e#17931\u003c/a\u003e fix(decorators): replace super within all removed static elements (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-register\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17915\"\u003e#17915\u003c/a\u003e Fix thread synchronization issues in \u003ccode\u003e@babel/register\u003c/code\u003e (\u003ca href=\"https://github.com/liuxingbaoyu\"\u003e\u003ccode\u003e@​liuxingbaoyu\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-compat-data\u003c/code\u003e, \u003ccode\u003ebabel-plugin-bugfix-safari-rest-destructuring-rhs-array\u003c/code\u003e, \u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17788\"\u003e#17788\u003c/a\u003e Add bugfix plugin for Safari array rest destructuring bug (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:nail_care: Polish\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/4fba7541180bf5f58256d8e358b544e3831ad090\"\u003e\u003ccode\u003e4fba754\u003c/code\u003e\u003c/a\u003e v7.29.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/04ea6b27fdac8f40c3481aec2080ac9678779509\"\u003e\u003ccode\u003e04ea6b2\u003c/code\u003e\u003c/a\u003e v7.29.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/99f498a9b9fa0b900d603fbe8f6601bb3b9e42bb\"\u003e\u003ccode\u003e99f498a\u003c/code\u003e\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/18001\"\u003e#18001\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/feba0a3654c596bd369d1ef1231f5d56666d56dc\"\u003e\u003ccode\u003efeba0a3\u003c/code\u003e\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17998\"\u003e#17998\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/babel/babel/commits/v7.29.7/packages/babel-core\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@humanfs/node` from 0.16.7 to 0.16.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/humanwhocodes/humanfs/releases\"\u003e@​humanfs/node's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003enode: v0.16.8\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/compare/node-v0.16.7...node-v0.16.8\"\u003e0.16.8\u003c/a\u003e (2026-04-17)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eInclude type dependencies at runtime (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e956ce7a\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/humanwhocodes/humanfs/issues/145\"\u003e#145\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe following workspace dependencies were updated\n\u003cul\u003e\n\u003cli\u003edependencies\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​humanfs/core\u003c/code\u003e bumped from ^0.19.1 to ^0.19.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/humanwhocodes/humanfs/blob/main/packages/node/CHANGELOG.md\"\u003e@​humanfs/node's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/compare/node-v0.16.7...node-v0.16.8\"\u003e0.16.8\u003c/a\u003e (2026-04-17)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEnsure symlinks are copied as symlinks in \u003ccode\u003ecopy()\u003c/code\u003e and \u003ccode\u003ecopyAll()\u003c/code\u003e (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/22bbaa4487a3e6c1197ca619840de4615d0c3404\"\u003e22bbaa44\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eInclude type dependencies at runtime (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e956ce7a\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/humanwhocodes/humanfs/issues/145\"\u003e#145\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe following workspace dependencies were updated\n\u003cul\u003e\n\u003cli\u003edependencies\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​humanfs/core\u003c/code\u003e bumped from ^0.19.1 to ^0.19.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/e96070e897f017ae8abd2b0676d98d14e49665cc\"\u003e\u003ccode\u003ee96070e\u003c/code\u003e\u003c/a\u003e chore: release main (\u003ca href=\"https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node/issues/146\"\u003e#146\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/22bbaa4487a3e6c1197ca619840de4615d0c3404\"\u003e\u003ccode\u003e22bbaa4\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e\u003ccode\u003e956ce7a\u003c/code\u003e\u003c/a\u003e fix: Include type dependencies at runtime\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/humanwhocodes/humanfs/commits/node-v0.16.8/packages/node\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@opentelemetry/core` from 2.6.1 to 2.11.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/releases\"\u003e@​opentelemetry/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.11.0\u003c/h2\u003e\n\u003ch2\u003e2.11.0\u003c/h2\u003e\n\u003ch3\u003e:rocket: Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(context-async-hooks): implement \u003ccode\u003eattach()\u003c/code\u003e on \u003ccode\u003eAsyncLocalStorageContextManager\u003c/code\u003e \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6845\"\u003e#6845\u003c/a\u003e \u003ca href=\"https://github.com/pichlermarc\"\u003e\u003ccode\u003e@​pichlermarc\u003c/code\u003e\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003eOn Node.js 25.9+, delegates to \u003ccode\u003eAsyncLocalStorage.withScope()\u003c/code\u003e returning a native \u003ccode\u003eRunScope\u003c/code\u003e. On older Node.js, falls back to \u003ccode\u003eenterWith()\u003c/code\u003e with a manual disposable wrapper.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003efeat(sdk-trace): allow configuring the force flush timeout per call \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6929\"\u003e#6929\u003c/a\u003e \u003ca href=\"https://github.com/LarryHu0217\"\u003e\u003ccode\u003e@​LarryHu0217\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(sdk-metrics): ignore \u003ccode\u003eInfinity\u003c/code\u003e in exponential histograms \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/7015\"\u003e#7015\u003c/a\u003e \u003ca href=\"https://github.com/mwear\"\u003e\u003ccode\u003e@​mwear\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:house: Internal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eperf(sdk-metrics): reuse a single DataView for exponential histogram bit reads \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6998\"\u003e#6998\u003c/a\u003e \u003ca href=\"https://github.com/mwear\"\u003e\u003ccode\u003e@​mwear\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(ci): run documentation tests on a weekly schedule \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6920\"\u003e#6920\u003c/a\u003e \u003ca href=\"https://github.com/LarryHu0217\"\u003e\u003ccode\u003e@​LarryHu0217\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(ci): support pre-releases and major version bumps in the release workflow \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6768\"\u003e#6768\u003c/a\u003e \u003ca href=\"https://github.com/pichlermarc\"\u003e\u003ccode\u003e@​pichlermarc\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(resources): Ensure that multiple uses of serviceInstanceIdDetector.detect() return the \u003cem\u003esame\u003c/em\u003e value for \u003ccode\u003eservice.instance.id\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.10.0\u003c/h2\u003e\n\u003ch2\u003e2.10.0\u003c/h2\u003e\n\u003ch3\u003e:rocket: Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(sdk-logs): implement log processor metrics \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6554\"\u003e#6554\u003c/a\u003e \u003ca href=\"https://github.com/anuraaga\"\u003e\u003ccode\u003e@​anuraaga\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(otlp-exporter): implement exporter metrics \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6480\"\u003e#6480\u003c/a\u003e \u003ca href=\"https://github.com/anuraaga\"\u003e\u003ccode\u003e@​anuraaga\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(propagator-jaeger):  \u003cem\u003eNotice\u003c/em\u003e: The \u003ccode\u003e@opentelemetry/propagator-jaeger\u003c/code\u003e package will be removed in SDK 3.x, planned for approximately September 2026. \u003ca href=\"https://github.com/pichlermarc\"\u003e\u003ccode\u003e@​pichlermarc\u003c/code\u003e\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003eThe Jaeger propagator has been deprecated by the OpenTelemetry specification in favor of \u003ccode\u003eW3CTraceContextPropagator\u003c/code\u003e. This package will be removed in a future release.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(sdk-trace): reject \u003ccode\u003eSimpleSpanProcessor.forceFlush()\u003c/code\u003e when a pending export fails \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6771\"\u003e#6771\u003c/a\u003e \u003ca href=\"https://github.com/LarryHu0217\"\u003e\u003ccode\u003e@​LarryHu0217\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(sdk-trace): include trace IDs at the ratio 1 upper bound in \u003ccode\u003eTraceIdRatioBasedSampler\u003c/code\u003e \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6890\"\u003e#6890\u003c/a\u003e \u003ca href=\"https://github.com/LarryHu0217\"\u003e\u003ccode\u003e@​LarryHu0217\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:house: Internal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003echore: build on Node 26 in CI \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6887\"\u003e#6887\u003c/a\u003e \u003ca href=\"https://github.com/overbalance\"\u003e\u003ccode\u003e@​overbalance\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump to typescript@5.2.2 \u003ca href=\"https://github.com/pichlermarc\"\u003e\u003ccode\u003e@​pichlermarc\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.9.0\u003c/h2\u003e\n\u003ch2\u003e2.9.0\u003c/h2\u003e\n\u003ch3\u003e:boom: Breaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003edocs(shim-opentracing): \u003cem\u003eNotice\u003c/em\u003e: The \u003ccode\u003e@opentelemetry/shim-opentracing\u003c/code\u003e package will be removed in SDK 3.x, planned for approximately September 2026.\n\u003cul\u003e\n\u003cli\u003eThe \u003ca href=\"https://opentelemetry.io/blog/2026/deprecating-opencensus-compatibility/\"\u003eOpenCensus\u003c/a\u003e and \u003ca href=\"https://opentelemetry.io/blog/2026/deprecating-opentracing-compatibility/\"\u003eOpenTracing\u003c/a\u003e compatibility requirements in the OpenTelemetry specification have been deprecated.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md\"\u003e@​opentelemetry/core's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.11.0\u003c/h2\u003e\n\u003ch3\u003e:rocket: Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(context-async-hooks): implement \u003ccode\u003eattach()\u003c/code\u003e on \u003ccode\u003eAsyncLocalStorageContextManager\u003c/code\u003e \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6845\"\u003e#6845\u003c/a\u003e \u003ca href=\"https://github.com/pichlermarc\"\u003e\u003ccode\u003e@​pichlermarc\u003c/code\u003e\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003eOn Node.js 25.9+, delegates to \u003ccode\u003eAsyncLocalStorage.withScope()\u003c/code\u003e returning a native \u003ccode\u003eRunScope\u003c/code\u003e. On older Node.js, falls back to \u003ccode\u003eenterWith()\u003c/code\u003e with a manual disposable wrapper.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003efeat(sdk-trace): allow configuring the force flush timeout per call \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6929\"\u003e#6929\u003c/a\u003e \u003ca href=\"https://github.com/LarryHu0217\"\u003e\u003ccode\u003e@​LarryHu0217\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(sdk-trace-base): avoid a Webpack self-reference error in CommonJS output \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6981\"\u003e#6981\u003c/a\u003e \u003ca href=\"https://github.com/sansynx\"\u003e\u003ccode\u003e@​sansynx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(sdk-metrics): ignore \u003ccode\u003eInfinity\u003c/code\u003e in exponential histograms \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/7015\"\u003e#7015\u003c/a\u003e \u003ca href=\"https://github.com/mwear\"\u003e\u003ccode\u003e@​mwear\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:house: Internal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eperf(sdk-metrics): reuse a single DataView for exponential histogram bit reads \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6998\"\u003e#6998\u003c/a\u003e \u003ca href=\"https://github.com/mwear\"\u003e\u003ccode\u003e@​mwear\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(ci): run documentation tests on a weekly schedule \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6920\"\u003e#6920\u003c/a\u003e \u003ca href=\"https://github.com/LarryHu0217\"\u003e\u003ccode\u003e@​LarryHu0217\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(ci): support pre-releases and major version bumps in the release workflow \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6768\"\u003e#6768\u003c/a\u003e \u003ca href=\"https://github.com/pichlermarc\"\u003e\u003ccode\u003e@​pichlermarc\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(resources): Ensure that multiple uses of serviceInstanceIdDetector.detect() return the \u003cem\u003esame\u003c/em\u003e value for \u003ccode\u003eservice.instance.id\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.10.0\u003c/h2\u003e\n\u003ch3\u003e:rocket: Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(sdk-logs): implement log processor metrics \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6554\"\u003e#6554\u003c/a\u003e \u003ca href=\"https://github.com/anuraaga\"\u003e\u003ccode\u003e@​anuraaga\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(otlp-exporter): implement exporter metrics \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6480\"\u003e#6480\u003c/a\u003e \u003ca href=\"https://github.com/anuraaga\"\u003e\u003ccode\u003e@​anuraaga\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(propagator-jaeger):  \u003cem\u003eNotice\u003c/em\u003e: The \u003ccode\u003e@opentelemetry/propagator-jaeger\u003c/code\u003e package will be removed in SDK 3.x, planned for approximately September 2026. \u003ca href=\"https://github.com/pichlermarc\"\u003e\u003ccode\u003e@​pichlermarc\u003c/code\u003e\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003eThe Jaeger propagator has been deprecated by the OpenTelemetry specification in favor of \u003ccode\u003eW3CTraceContextPropagator\u003c/code\u003e. This package will be removed in a future release.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(sdk-trace): reject \u003ccode\u003eSimpleSpanProcessor.forceFlush()\u003c/code\u003e when a pending export fails \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6771\"\u003e#6771\u003c/a\u003e \u003ca href=\"https://github.com/LarryHu0217\"\u003e\u003ccode\u003e@​LarryHu0217\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(sdk-trace): include trace IDs at the ratio 1 upper bound in \u003ccode\u003eTraceIdRatioBasedSampler\u003c/code\u003e \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6890\"\u003e#6890\u003c/a\u003e \u003ca href=\"https://github.com/LarryHu0217\"\u003e\u003ccode\u003e@​LarryHu0217\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:house: Internal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003echore: build on Node 26 in CI \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6887\"\u003e#6887\u003c/a\u003e \u003ca href=\"https://github.com/overbalance\"\u003e\u003ccode\u003e@​overbalance\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump to typescript@5.2.2 \u003ca href=\"https://github.com/pichlermarc\"\u003e\u003ccode\u003e@​pichlermarc\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.9.0\u003c/h2\u003e\n\u003ch3\u003e:boom: Breaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003edocs(shim-opentracing): \u003cem\u003eNotice\u003c/em\u003e: The \u003ccode\u003e@opentelemetry/shim-opentracing\u003c/code\u003e package will be removed in SDK 3.x, planned for approximately September 2026.\n\u003cul\u003e\n\u003cli\u003eThe \u003ca href=\"https://opentelemetry.io/blog/2026/deprecating-opencensus-compatibility/\"\u003eOpenCensus\u003c/a\u003e and \u003ca href=\"https://opentelemetry.io/blog/2026/deprecating-opentracing-compatibility/\"\u003eOpenTracing\u003c/a\u003e compatibility requirements in the OpenTelemetry specification have been deprecated.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:rocket: Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(sdk-metrics): add maxExportBatchSize option to PeriodicExportingMetricReader \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6655\"\u003e#6655\u003c/a\u003e \u003ca href=\"https://github.com/psx95\"\u003e\u003ccode\u003e@​psx95\u003c/code\u003e\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003eOptimized \u003ccode\u003ePeriodicExportingMetricReader.forceFlush\u003c/code\u003e to prevent redundant concurrent export cycles. Concurrent calls to forceFlush will now await any ongoing export and reuse a fresh export cycle if one is started concurrently by another caller. This ensures the latest metrics are always exported efficiently without triggering duplicate collection and export cycles.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/0b72a81636fa476e8f1f1afd2ae0c90a1362194c\"\u003e\u003ccode\u003e0b72a81\u003c/code\u003e\u003c/a\u003e chore: prepare next release (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/7044\"\u003e#7044\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/a9c5338a9f485f1433df9308f24bd7397a4a0321\"\u003e\u003ccode\u003ea9c5338\u003c/code\u003e\u003c/a\u003e ci: roll prerelease changelog into one final release changelog (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/7045\"\u003e#7045\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/f41805e769ba10fb6dae72a4b7a5a3dc67cca82e\"\u003e\u003ccode\u003ef41805e\u003c/code\u003e\u003c/a\u003e chore: prepare next release (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/7042\"\u003e#7042\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/b85eb28343ff6234e2bb4d46b7b4a3d360e5ea2f\"\u003e\u003ccode\u003eb85eb28\u003c/code\u003e\u003c/a\u003e chore(instrumentation-http): fix lint errors (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/7039\"\u003e#7039\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/3f9253009be2ae48419432e79a597ead7be8be6a\"\u003e\u003ccode\u003e3f92530\u003c/code\u003e\u003c/a\u003e ci: support pre-releases and major version bumps in release workflow (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/7035\"\u003e#7035\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/82a58316a63b6fde62afd268e145b82222d328cf\"\u003e\u003ccode\u003e82a5831\u003c/code\u003e\u003c/a\u003e docs(otlp-exporter-base): document HTTP exporter options (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6735\"\u003e#6735\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/e086dec7f9304107ef6d50b5877be88895c06aa7\"\u003e\u003ccode\u003ee086dec\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/59dac70d00d46fa56b2b921cf721fd922730f23d\"\u003e\u003ccode\u003e59dac70\u003c/code\u003e\u003c/a\u003e chore(deps): update jamesives/github-pages-deploy-action action to v4.9.0 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/7\"\u003e#7\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/d0ce7532b058631ec9eec111c04fefe7fd873e1f\"\u003e\u003ccode\u003ed0ce753\u003c/code\u003e\u003c/a\u003e chore: add \u003ca href=\"https://github.com/maryliag\"\u003e\u003ccode\u003e@​maryliag\u003c/code\u003e\u003c/a\u003e to maintainers (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/7024\"\u003e#7024\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/03469a129f97265c8eec93d566e9e00d4f741db3\"\u003e\u003ccode\u003e03469a1\u003c/code\u003e\u003c/a\u003e chore(deps): update open-telemetry/shared-workflows action to v0.10.0 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/7032\"\u003e#7032\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/compare/v2.6.1...v2.11.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.14 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24\"\u003e\u003ccode\u003e2203f4f\u003c/code\u003e\u003c/a\u003e 1.1.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd\"\u003e\u003ccode\u003e0b09384\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-uri` from 3.1.0 to 3.1.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.0...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `js-yaml` from 4.1.1 to 4.3.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md\"\u003ejs-yaml's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.3.2 - 2026-08-26\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Hard-limit merge sequence size to 100.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Count empty mappings in merge sequences toward \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e\nto limit CPU usage, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/797\"\u003e#797\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.3.1 - 2026-07-31\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Remove quadratic complexity from \u003ccode\u003e!!omap\u003c/code\u003e duplicate key detection.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.3.0 - 2026-06-27\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Added \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e (10000) loader option to limit the total number of\nkeys processed by YAML merge (\u003ccode\u003e\u0026lt;\u0026lt;\u003c/code\u003e) across one \u003ccode\u003eload()\u003c/code\u003e / \u003ccode\u003eloadAll()\u003c/code\u003e call.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRestore umd builds back to es5.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRemoved\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e replaced with \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e for limiting YAML merge\nprocessing.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[4.2.0] - 2026-06-01\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003edocs/safety.md\u003c/code\u003e with notes about processing untrusted YAML.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003emaxDepth\u003c/code\u003e (100) loader option. Not a problem, but gives a better\nexception instead of RangeError on stack overflow.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e (20) loader option. Not a problem after \u003ccode\u003emerge\u003c/code\u003e fix,\nbut an additional restriction for safety.\u003c/li\u003e\n\u003cli\u003eAdded sourcemaps to \u003ccode\u003edist/\u003c/code\u003e builds.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStop resolving numbers with underscores as numeric scalars, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/627\"\u003e#627\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eSwitched dev toolchains to Vite / neostandard.\u003c/li\u003e\n\u003cli\u003eUpdated demo.\u003c/li\u003e\n\u003cli\u003eReorganized tests.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edist/\u003c/code\u003e files are no longer kept in the repository.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix parsing of properties on the first implicit block mapping key, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/62\"\u003e#62\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix trailing whitespace handling when folding flow scalar lines, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/307\"\u003e#307\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eReject top-level block scalars without content indentation, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/280\"\u003e#280\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eEnsure numbers survive round-trip, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/737\"\u003e#737\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix test coverage for issue \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/221\"\u003e#221\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix flow scalar trailing whitespace folding, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/307\"\u003e#307\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/79ca68d90f333fbe6d9e42827527e62636200191\"\u003e\u003ccode\u003e79ca68d\u003c/code\u003e\u003c/a\u003e 4.3.2 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/d90b6612a5a84385bdcb556c44578eac76dc0f6b\"\u003e\u003ccode\u003ed90b661\u003c/code\u003e\u003c/a\u003e Backport merge limits from v5.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/86e91b815b8794c3c73a179c1770871e37ec2df8\"\u003e\u003ccode\u003e86e91b8\u003c/code\u003e\u003c/a\u003e 4.3.1 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/c3cc4b0bb9ddb9af2dd9b61e0d56f5ce7983cd4a\"\u003e\u003ccode\u003ec3cc4b0\u003c/code\u003e\u003c/a\u003e Backport quadratic complexity fix for !!omap\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/33d05b5d29a8c21360f620f7e1c1706e24522eda\"\u003e\u003ccode\u003e33d05b5\u003c/code\u003e\u003c/a\u003e 4.3.0 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/663bfab6db2b4a146a9366fd685f069345be4ddb\"\u003e\u003ccode\u003e663bfab\u003c/code\u003e\u003c/a\u003e Drop demo publish, to not override new v5 one.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/1cb8c7b94bf75e15116869c1c0482dcb22785986\"\u003e\u003ccode\u003e1cb8c7b\u003c/code\u003e\u003c/a\u003e Add v4-legacy tag for publish\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/02f27afad532763263cd2b6be35c24ee8e1f6157\"\u003e\u003ccode\u003e02f27af\u003c/code\u003e\u003c/a\u003e Restore umd builds back to es5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/8be84edaf15e7c394fa3b813179d1bcc280e87fb\"\u003e\u003ccode\u003e8be84ed\u003c/code\u003e\u003c/a\u003e Fix es5 compatibility\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/59423c6f8cdc78742ac00e25a4dd39ef16b702e4\"\u003e\u003ccode\u003e59423c6\u003c/code\u003e\u003c/a\u003e Replace \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e option with \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e (more robust). Ba...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodeca/js-yaml/compare/4.1.1...4.3.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nanoid` from 3.3.11 to 3.3.19\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/releases\"\u003enanoid's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed breaking Nano ID by requesting big ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/blob/main/CHANGELOG.md\"\u003enanoid's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID (by \u003ca href=\"https://github.com/geoffrey-diederichs\"\u003e\u003ccode\u003e@​geoffrey-diederichs\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed breaking Nano ID by requesting big ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/eb63bd6775188dc35d143bf24868be094f19b5ee\"\u003e\u003ccode\u003eeb63bd6\u003c/code\u003e\u003c/a\u003e Release 3.3.19 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9067e0361a643ab2c94ddd67606efbf275f6c0dd\"\u003e\u003ccode\u003e9067e03\u003c/code\u003e\u003c/a\u003e Sync CJS and ESM\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9ad98052b316c5e707f8098ace509d2ae165e54d\"\u003e\u003ccode\u003e9ad9805\u003c/code\u003e\u003c/a\u003e Release 3.3.18 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/55e50a0621ec084b4bb4000ea4e86e1191bd3da8\"\u003e\u003ccode\u003e55e50a0\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e10f8d40ce9d1ab47f66d65a16b48086432730d0\"\u003e\u003ccode\u003ee10f8d4\u003c/code\u003e\u003c/a\u003e Update index.native.js (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/606\"\u003e#606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/73d67168136b36fd3b644159b0cff149da4905d9\"\u003e\u003ccode\u003e73d6716\u003c/code\u003e\u003c/a\u003e Release 3.3.17 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/f9d13f150847d117877adee3460a46eceb0cf49b\"\u003e\u003ccode\u003ef9d13f1\u003c/code\u003e\u003c/a\u003e Sync 0 size behaviour with PostCSS 5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9760e112757cf7d46a79abd7a133bc4958757bb8\"\u003e\u003ccode\u003e9760e11\u003c/code\u003e\u003c/a\u003e Release 3.3.16 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66d\"\u003e\u003ccode\u003ee835c9b\u003c/code\u003e\u003c/a\u003e fix(non-secure): clamp negative size to prevent infinite loop (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/601\"\u003e#601\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/96dd086eb24396a275fa93ee78d73b2fece35809\"\u003e\u003ccode\u003e96dd086\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ai/nanoid/compare/3.3.11...3.3.19\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for nanoid since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.4.31 to 8.5.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003epostcss-scss\u003c/code\u003e commend regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed reading any file via user-generated CSS.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eopts.unsafeMap\u003c/code\u003e to disable checks.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed nested brackets parsing performance (by \u003ca href=\"https://github.com/offset\"\u003e\u003ccode\u003e@​offset\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.10\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed XSS via unescaped \u003ccode\u003e\u0026lt;/style\u0026gt;\u003c/code\u003e in non-bundler cases (by \u003ca href=\"https://github.com/TharVid\"\u003e\u003ccode\u003e@​TharVid\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8\"\u003e\u003ccode\u003e7beca13\u003c/code\u003e\u003c/a\u003e Does no load source map file without opts.from\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/decea51421682341401575b3740709fda0e12930\"\u003e\u003ccode\u003edecea51\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/c18e30d126395d42a0726aa00e03a8f1088985ae\"\u003e\u003ccode\u003ec18e30d\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/98a39ad73d163a90be924d5126c771262110f1fc\"\u003e\u003ccode\u003e98a39ad\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/a3e48c492ddec0e4879d513b8b995fee887af352\"\u003e\u003ccode\u003ea3e48c4\u003c/code\u003e\u003c/a\u003e Release 8.5.22 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f49d6911795f53b2cfe023bb686bf1144ec30618\"\u003e\u003ccode\u003ef49d691\u003c/code\u003e\u003c/a\u003e Fix custom property losing its semicolon before a comment (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2117\"\u003e#2117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/28e0daf8f2fe5ba9e19ea3f8c27c8fe176f9419e\"\u003e\u003ccode\u003e28e0daf\u003c/code\u003e\u003c/a\u003e Release 8.5.21 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3d2b4e43e38274f233b5609d09687cadad8215d9\"\u003e\u003ccode\u003e3d2b4e4\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.4.31...8.5.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `sharp` from 0.34.5 to 0.35.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lovell/sharp/releases\"\u003esharp's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.35.4\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\"\u003ehttps://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.35.4-rc.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpgrade to libvips v8.18.6 for upstream bug fixes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7f1a0a22cc285fe180766f4935d50b55af6e8432\"\u003e\u003ccode\u003e7f1a0a2\u003c/code\u003e\u003c/a\u003e Release v0.35.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/f927818924bc5a9493d822a4e8b23ec5857c52e1\"\u003e\u003ccode\u003ef927818\u003c/code\u003e\u003c/a\u003e Upgrade to sharp-libvips v1.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e80209240d005c71e1173a50dd9cd4db4ce2a9e6\"\u003e\u003ccode\u003ee802092\u003c/code\u003e\u003c/a\u003e Prerelease v0.35.4-rc.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e13eb2f97a0a22f1ef726e8d0cd33f7c56835945\"\u003e\u003ccode\u003ee13eb2f\u003c/code\u003e\u003c/a\u003e CI: Fix wasm32 build (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4589\"\u003e#4589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/a82a0b3d58bc25854ad1e925e6eb0a50725d1489\"\u003e\u003ccode\u003ea82a0b3\u003c/code\u003e\u003c/a\u003e Upgrade to libvips v8.18.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/8044fe43e36d0ea7f8beb89f79a37bb0f3342e84\"\u003e\u003ccode\u003e8044fe4\u003c/code\u003e\u003c/a\u003e Bound resize dimensions to coordinate limit\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/147f8591a153bc4a1e199c3fe3150fac2931b30c\"\u003e\u003ccode\u003e147f859\u003c/code\u003e\u003c/a\u003e Docs: changelog entries for \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4578\"\u003e#4578\u003c/a\u003e \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ee5bfb853de75a611c64381783b04032a3a897d8\"\u003e\u003ccode\u003eee5bfb8\u003c/code\u003e\u003c/a\u003e Tests: use yauzl directly rather than via extract-zip wrapper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7a7788928f8a2a429f45039010a87cee35401694\"\u003e\u003ccode\u003e7a77889\u003c/code\u003e\u003c/a\u003e Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4588\"\u003e#4588\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ea5bef24c187b2c7ee3fe3cad3b45c8cb67a46fd\"\u003e\u003ccode\u003eea5bef2\u003c/code\u003e\u003c/a\u003e Improve support for input Streams finishing before output is requested (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/lovell/sharp/compare/v0.34.5...v0.35.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/KryssNa/utilbyte/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/KryssNa/utilbyte/pull/21","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/KryssNa%2Futilbyte/issues/21","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/21/packages"}},{"old_version":"3.1.2","new_version":"3.1.7","update_type":"patch","path":null,"pr_created_at":"2026-09-13T10:10:48.000Z","version_change":"3.1.2 → 3.1.7","issue":{"uuid":"5439439227","node_id":"PR_kwDOQRS3g88AAAABDU5SyQ","number":558,"state":"closed","title":"chore(deps): bump the npm_and_yarn group across 1 directory with 12 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-13T12:06:08.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-13T10:10:48.000Z","updated_at":"2026-09-13T12:06:10.000Z","time_to_close":6920,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":12,"packages":[{"name":"baseline-browser-mapping","old_version":"2.10.40","new_version":"2.11.23","repository_url":"https://github.com/web-platform-dx/baseline-browser-mapping"},{"name":"body-parser","old_version":"1.20.5","new_version":"1.20.8","repository_url":"https://github.com/expressjs/body-parser"},{"name":"brace-expansion","old_version":"2.1.1","new_version":"2.1.4","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"browserslist","old_version":"4.28.4","new_version":"4.28.9","repository_url":"https://github.com/browserslist/browserslist"},{"name":"colord","old_version":"2.9.3","new_version":"2.10.0","repository_url":"https://github.com/omgovich/colord"},{"name":"fast-uri","old_version":"3.1.2","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"joi","old_version":"17.13.4","new_version":"17.13.8","repository_url":"https://github.com/hapijs/joi"},{"name":"nanoid","old_version":"3.3.12","new_version":"3.3.19","repository_url":"https://github.com/ai/nanoid"},{"name":"postcss","old_version":"8.5.15","new_version":"8.5.28","repository_url":"https://github.com/postcss/postcss"},{"name":"shell-quote","old_version":"1.8.4","new_version":"1.10.0","repository_url":"https://github.com/ljharb/shell-quote"},{"name":"svgo","old_version":"3.3.3","new_version":"3.3.5","repository_url":"https://github.com/svg/svgo"},{"name":"undici","old_version":"7.28.0","new_version":"7.29.1","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 12 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) | `2.10.40` | `2.11.23` |\n| [body-parser](https://github.com/expressjs/body-parser) | `1.20.5` | `1.20.8` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `2.1.1` | `2.1.4` |\n| [browserslist](https://github.com/browserslist/browserslist) | `4.28.4` | `4.28.9` |\n| [colord](https://github.com/omgovich/colord) | `2.9.3` | `2.10.0` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.2` | `3.1.7` |\n| [joi](https://github.com/hapijs/joi) | `17.13.4` | `17.13.8` |\n| [nanoid](https://github.com/ai/nanoid) | `3.3.12` | `3.3.19` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.15` | `8.5.28` |\n| [shell-quote](https://github.com/ljharb/shell-quote) | `1.8.4` | `1.10.0` |\n| [svgo](https://github.com/svg/svgo) | `3.3.3` | `3.3.5` |\n| [undici](https://github.com/nodejs/undici) | `7.28.0` | `7.29.1` |\n\n\nUpdates `baseline-browser-mapping` from 2.10.40 to 2.11.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/releases\"\u003ebaseline-browser-mapping's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.11.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed in 2.11.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: Adds a new \u003ccode\u003egetTimeline()\u003c/code\u003e method for getting the series of minimum browser changes, either grouped by date or by browser.\u003c/li\u003e\n\u003cli\u003erefactor: Substantial refactoring of the data compression process that replaces the full list of browsers from \u003ccode\u003e@mdn/browser-compat-data\u003c/code\u003e and \u003ccode\u003edownstream-browsers.json\u003c/code\u003e and features from \u003ccode\u003eweb-features\u003c/code\u003e (in their very pared down form) with a change-list timeline that reflects which versions supported Baseline (newly available) on a given date.  Thanks to \u003ca href=\"https://github.com/swwind\"\u003e\u003ccode\u003e@​swwind\u003c/code\u003e\u003c/a\u003e for the idea!\u003c/li\u003e\n\u003cli\u003erefactor: Some common functions have been moved to a \u003ccode\u003eutil.ts\u003c/code\u003e module for use in other scripts.\u003c/li\u003e\n\u003cli\u003efix: Removes \u003ccode\u003eprocess.exit()\u003c/code\u003e calls when unsupported option combinations are passed to getCompatibleVersions() and \u003ccode\u003egetAllVersions()\u003c/code\u003e in favour of throwing an \u003ccode\u003eError\u003c/code\u003e.  There is a small security risk with \u003ccode\u003eprocess.exit()\u003c/code\u003e calls that sites accepting unsanitised inputs could be the subject of attacks.  Unsupported config options now throw and Error which should allow for more graceful handling.  Thanks to \u003ca href=\"https://github.com/bnbdr\"\u003e\u003ccode\u003e@​bnbdr\u003c/code\u003e\u003c/a\u003e for flagging this as vulnerability CVE-2026-45819 .\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFixes \u003ca href=\"https://redirect.github.com/web-platform-dx/baseline-browser-mapping/issues/134\"\u003e#134\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.10.44...v2.11.0\"\u003ehttps://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.10.44...v2.11.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/ebdc72f5637922808cfe1fbf9e67897ba9f89677\"\u003e\u003ccode\u003eebdc72f\u003c/code\u003e\u003c/a\u003e Patch to 2.11.23 because browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/55fa3a1503097faad7a9806d6c08029a36cb19e3\"\u003e\u003ccode\u003e55fa3a1\u003c/code\u003e\u003c/a\u003e Browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/5ac60db1f4eedbd9b61dfa6db0cab10cccc19c2a\"\u003e\u003ccode\u003e5ac60db\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/af7c3c4ebc2692844e521fada6c8d49250795f10\"\u003e\u003ccode\u003eaf7c3c4\u003c/code\u003e\u003c/a\u003e Patch to 2.11.22 because browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/7e10cadb03c00cb5eab538d62b6d16511cd93841\"\u003e\u003ccode\u003e7e10cad\u003c/code\u003e\u003c/a\u003e Browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/ebb97027ff15d916e66b02feb9e019d8c7bab081\"\u003e\u003ccode\u003eebb9702\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/ecc57a365d502e0c85574e45751c1b7475689936\"\u003e\u003ccode\u003eecc57a3\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/0e5ed80e21dda23cac3dc1f6ec37e6b5fc4ea734\"\u003e\u003ccode\u003e0e5ed80\u003c/code\u003e\u003c/a\u003e Patch to 2.11.21 because browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/11da0b699d6d03a1e30b37a8fe7a4f8d96e06f4d\"\u003e\u003ccode\u003e11da0b6\u003c/code\u003e\u003c/a\u003e Browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/69fcc81987ecc7dbbf4d21e17be8c4adf642aa2b\"\u003e\u003ccode\u003e69fcc81\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.10.40...v2.11.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `body-parser` from 1.20.5 to 1.20.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/body-parser/releases\"\u003ebody-parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.20.8\u003c/h2\u003e\n\u003ch2\u003eImportant\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eSame code base as \u003ca href=\"https://github.com/expressjs/body-parser/releases/tag/1.20.7\"\u003e1.20.7\u003c/a\u003e. This was created to test the new release process.\u003c/strong\u003e\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eci: backport npm-publish workflow from master by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/769\"\u003eexpressjs/body-parser#769\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e1.20.8 by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/770\"\u003eexpressjs/body-parser#770\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.7...1.20.8\"\u003ehttps://github.com/expressjs/body-parser/compare/1.20.7...1.20.8\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.20.7\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocs: include security fix in 1.20.6 changes by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/747\"\u003eexpressjs/body-parser#747\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edeps: qs@~6.16.0 by \u003ca href=\"https://github.com/krzysdz\"\u003e\u003ccode\u003e@​krzysdz\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/761\"\u003eexpressjs/body-parser#761\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e1.20.7 by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/767\"\u003eexpressjs/body-parser#767\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.6...1.20.7\"\u003ehttps://github.com/expressjs/body-parser/compare/1.20.6...1.20.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.20.6\u003c/h2\u003e\n\u003ch2\u003eImportant: Security\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity fix for \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2025-13466\"\u003eCVE-2026-12590\u003c/a\u003e (\u003ca href=\"https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6\"\u003eGHSA-v422-hmwv-36x6\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: improve limit option validation by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/741\"\u003eexpressjs/body-parser#741\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.5...1.20.6\"\u003ehttps://github.com/expressjs/body-parser/compare/1.20.5...1.20.6\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/body-parser/blob/1.20.8/HISTORY.md\"\u003ebody-parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e1.20.8\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eSame code base as 1.20.7. This was created to test the new release process.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.20.7\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003edeps: qs@~6.16.0\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.20.6\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity fix for \u003ca href=\"https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6\"\u003eGHSA-v422-hmwv-36x6\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: improve \u003ccode\u003elimit\u003c/code\u003e option validation (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/698\"\u003e#698\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003eInvalid \u003ccode\u003elimit\u003c/code\u003e values (e.g. unparseable strings or \u003ccode\u003eNaN\u003c/code\u003e) now throw instead of being silently ignored, which previously disabled size limit enforcement\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003enull\u003c/code\u003e and \u003ccode\u003eundefined\u003c/code\u003e fall back to the default 100kb limit\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/5c08c2008eac79abddb8abfa5095491d02958d56\"\u003e\u003ccode\u003e5c08c20\u003c/code\u003e\u003c/a\u003e 1.20.8 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/770\"\u003e#770\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/0cea4f42a40996eafac441d0e71084afbe1407d4\"\u003e\u003ccode\u003e0cea4f4\u003c/code\u003e\u003c/a\u003e ci: backport npm-publish workflow from master (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/769\"\u003e#769\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/0f0f0d7f96fc7444407aef85a6d1fa363279e654\"\u003e\u003ccode\u003e0f0f0d7\u003c/code\u003e\u003c/a\u003e 1.20.7 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/767\"\u003e#767\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/355eb04ade7c27f57f93a0e90e26ed6f121becc5\"\u003e\u003ccode\u003e355eb04\u003c/code\u003e\u003c/a\u003e deps: qs@~6.16.0 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/761\"\u003e#761\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/8be369a5f8b0f4070ebb7a0ae9aca12db9d8f947\"\u003e\u003ccode\u003e8be369a\u003c/code\u003e\u003c/a\u003e docs: include security fix in 1.20.6 changes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/5cc4fb8867c93a3aa4455927e38858c9ab89ff43\"\u003e\u003ccode\u003e5cc4fb8\u003c/code\u003e\u003c/a\u003e 1.20.6 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/746\"\u003e#746\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/3492672eee593d5c158f239b6e9115498a5dbeac\"\u003e\u003ccode\u003e3492672\u003c/code\u003e\u003c/a\u003e fix: improve limit option validation (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/741\"\u003e#741\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.5...1.20.8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for body-parser since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 2.1.1 to 2.1.4\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/b25213dff0446d622f97d736420b9830ee1abc32\"\u003e\u003ccode\u003eb25213d\u003c/code\u003e\u003c/a\u003e 2.1.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac\"\u003e\u003ccode\u003e1e30c93\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/878df3989e816dfb28cbe0d64de0b88738ff0ed6\"\u003e\u003ccode\u003e878df39\u003c/code\u003e\u003c/a\u003e 2.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/c8bd93cfff4e45cb295557d2be17e1d1d4e52a11\"\u003e\u003ccode\u003ec8bd93c\u003c/code\u003e\u003c/a\u003e npm ignore .claude\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d13ff455a58b0d56704f0111e3c2a0b16ceb06eb\"\u003e\u003ccode\u003ed13ff45\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/130\"\u003e#130\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/9e67a3b151e418679ac4800f31f874ec6d220b4a\"\u003e\u003ccode\u003e9e67a3b\u003c/code\u003e\u003c/a\u003e 2.1.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/835d6be91201122d9adffb0c0c8c094189ace265\"\u003e\u003ccode\u003e835d6be\u003c/code\u003e\u003c/a\u003e fix: v2 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/123\"\u003e#123\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v2.1.1...v2.1.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `browserslist` from 4.28.4 to 4.28.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/releases\"\u003ebrowserslist's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eincluding kaios\u003c/code\u003e in baseline queries (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved parsing performance.\u003c/li\u003e\n\u003cli\u003eFixed unbounded memory growth (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed prototype write issue (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Electron version queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003e\u0026gt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;=\u003c/code\u003e queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md\"\u003ebrowserslist's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eincluding kaios\u003c/code\u003e in baseline queries (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved parsing performance.\u003c/li\u003e\n\u003cli\u003eFixed unbounded memory growth (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed prototype write issue (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Electron version queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003e\u0026gt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;=\u003c/code\u003e queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/12ed5252dabc14fee4e97b465894b2f90910ca62\"\u003e\u003ccode\u003e12ed525\u003c/code\u003e\u003c/a\u003e Release 4.28.9 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/b1d8cf9d7a7dc76f6585425a8360218289194297\"\u003e\u003ccode\u003eb1d8cf9\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/21517b651c915cdbbfb8c122268bc36f5cabb7ef\"\u003e\u003ccode\u003e21517b6\u003c/code\u003e\u003c/a\u003e Improve \u003ccode\u003eor\u003c/code\u003e parsing performance\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/f2f2e6cfb01bb4942941d328737546f4e2ae41ad\"\u003e\u003ccode\u003ef2f2e6c\u003c/code\u003e\u003c/a\u003e Release 4.28.8 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/d0787c88fa29ba895fea51cfe921232c7b5d1377\"\u003e\u003ccode\u003ed0787c8\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/fcf8fa9857b30ccdf801a548f5d09d3c4ff0d43f\"\u003e\u003ccode\u003efcf8fa9\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/browserslist/browserslist/issues/939\"\u003e#939\u003c/a\u003e from Jaybhade/fix/baseline-kaios-without-downstream\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/57ecd64454e9252afdd6a7e76926e13dda48a38c\"\u003e\u003ccode\u003e57ecd64\u003c/code\u003e\u003c/a\u003e fix: support \u0026quot;including kaios\u0026quot; without downstream\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/093a0f67bb0becda55235d767b134df3197c54a1\"\u003e\u003ccode\u003e093a0f6\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/b637868045806d2fba4c24eb0060e4cc8b1db276\"\u003e\u003ccode\u003eb637868\u003c/code\u003e\u003c/a\u003e Release 4.28.7 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/313f4659b9f985ade89d1d6a54a860371c41cc46\"\u003e\u003ccode\u003e313f465\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/browserslist/browserslist/compare/4.28.4...4.28.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `colord` from 2.9.3 to 2.10.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/omgovich/colord/releases\"\u003ecolord's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.10 (RGB color mixing)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003emix\u003c/code\u003e, \u003ccode\u003etints\u003c/code\u003e, \u003ccode\u003eshades\u003c/code\u003e and \u003ccode\u003etones\u003c/code\u003e (\u003ccode\u003emix\u003c/code\u003e plugin) now accept an optional interpolation color space. LAB stays the default; pass \u003ccode\u003e\u0026quot;rgb\u0026quot;\u003c/code\u003e to interpolate RGB channels instead — the way browsers and design tools (such as Figma) composite translucent layers.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003eimport { colord, extend } from \u0026quot;colord\u0026quot;;\nimport mixPlugin from \u0026quot;colord/plugins/mix\u0026quot;;\n\u003cp\u003eextend([mixPlugin]);\u003c/p\u003e\n\u003cp\u003ecolord(\u0026quot;#ff0000\u0026quot;).mix(\u0026quot;#ffffff\u0026quot;, 0.5, \u0026quot;rgb\u0026quot;).toHex(); // \u0026quot;#ff8080\u0026quot;\ncolord(\u0026quot;#f0f3f1\u0026quot;).mix(\u0026quot;#007d40\u0026quot;, 0.14, \u0026quot;rgb\u0026quot;).toHex(); // \u0026quot;#cee2d8\u0026quot; — same as compositing rgba(0, 125, 64, 0.14) over #f0f3f1\ncolord(\u0026quot;#ff0000\u0026quot;).tints(3, \u0026quot;rgb\u0026quot;).map((c) =\u0026gt; c.toHex()); // [\u0026quot;#ff0000\u0026quot;, \u0026quot;#ff8080\u0026quot;, \u0026quot;#ffffff\u0026quot;]\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/omgovich/colord/blob/master/CHANGELOG.md\"\u003ecolord's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch3\u003e2.10.0\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003emix\u003c/code\u003e plugin by adding an optional \u003ccode\u003e\u0026quot;rgb\u0026quot;\u003c/code\u003e interpolation mode to \u003ccode\u003emix\u003c/code\u003e, \u003ccode\u003etints\u003c/code\u003e, \u003ccode\u003etones\u003c/code\u003e and \u003ccode\u003eshades\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e2.9.7\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eMake HEX parsing and serialization more than 2x faster\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e2.9.6\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix: Rotate the unrounded hue so \u003ccode\u003erotate\u003c/code\u003e and \u003ccode\u003eharmonies\u003c/code\u003e preserve the original color\u003c/li\u003e\n\u003cli\u003eFix: Normalize HWB whiteness + blackness over 100% to gray ❤️ \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e2.9.5\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix: Use adjusted chroma for the CIEDE2000 rotation term ❤️ \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix: Keep the hue within \u003ccode\u003e[0, 360)\u003c/code\u003e in every color model ❤️ \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eBoth fixes change returned numbers for a small set of colors; \u003ccode\u003etoHex()\u003c/code\u003e output is unchanged. Snapshots holding \u003ccode\u003eh: 360\u003c/code\u003e, \u003ccode\u003e\u0026quot;hsl(360, …)\u0026quot;\u003c/code\u003e or a \u003ccode\u003edelta()\u003c/code\u003e value may need updating.\u003c/p\u003e\n\u003ch3\u003e2.9.4\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix: Reject malformed color strings in linear time ❤️ \u003ca href=\"https://github.com/GAP-dev\"\u003e\u003ccode\u003e@​GAP-dev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/omgovich/colord/commits/v2.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-uri` from 3.1.2 to 3.1.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `joi` from 17.13.4 to 17.13.8\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/4ae6af96f7990fdb336aa8ad7dee5e9f847d084a\"\u003e\u003ccode\u003e4ae6af9\u003c/code\u003e\u003c/a\u003e 17.13.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/b3ed6fbdf123f4d77755e6a5df2d6a7af27cd9e8\"\u003e\u003ccode\u003eb3ed6fb\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hapijs/joi/issues/3153\"\u003e#3153\u003c/a\u003e from hapijs/fix/messages-proto-flat-v17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/1d2001cad9971327a62c9fd8eb1afec20cd784d2\"\u003e\u003ccode\u003e1d2001c\u003c/code\u003e\u003c/a\u003e chore: backport \u003ca href=\"https://redirect.github.com/hapijs/joi/issues/3151\"\u003e#3151\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/ed9d7cdd11ef5f7751fd46886f38dc605c9c3995\"\u003e\u003ccode\u003eed9d7cd\u003c/code\u003e\u003c/a\u003e 17.13.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/f2729f71839c57c94ac500b4be9e4b5b26d4e637\"\u003e\u003ccode\u003ef2729f7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hapijs/joi/issues/3145\"\u003e#3145\u003c/a\u003e from hapijs/backport/isodate-timeshift-v17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/c43fc964799c9b5f0c6921bf788162b67066ae81\"\u003e\u003ccode\u003ec43fc96\u003c/code\u003e\u003c/a\u003e chore: add regression test for \u003ca href=\"https://redirect.github.com/hapijs/joi/issues/3143\"\u003e#3143\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/115e7b58d5eaaecc5e9b7093d41899ad6fb053ec\"\u003e\u003ccode\u003e115e7b5\u003c/code\u003e\u003c/a\u003e fix(isoDate): pad a bare-hour timeshift with a colon, not just zeros\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/850be1ee24be8d548bb09359bdb0cf9fe41635ff\"\u003e\u003ccode\u003e850be1e\u003c/code\u003e\u003c/a\u003e 17.13.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/9faeecc48b18ec40e3881467645ae9074f0dfa3c\"\u003e\u003ccode\u003e9faeecc\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hapijs/joi/issues/3139\"\u003e#3139\u003c/a\u003e from hapijs/chore/backport-messages-proto\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/8d0b808f3e874d28f9078f61b7742290989afb36\"\u003e\u003ccode\u003e8d0b808\u003c/code\u003e\u003c/a\u003e fix: prevent messages proto injection\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hapijs/joi/compare/v17.13.4...v17.13.8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nanoid` from 3.3.12 to 3.3.19\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/releases\"\u003enanoid's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/blob/main/CHANGELOG.md\"\u003enanoid's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID (by \u003ca href=\"https://github.com/geoffrey-diederichs\"\u003e\u003ccode\u003e@​geoffrey-diederichs\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/eb63bd6775188dc35d143bf24868be094f19b5ee\"\u003e\u003ccode\u003eeb63bd6\u003c/code\u003e\u003c/a\u003e Release 3.3.19 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9067e0361a643ab2c94ddd67606efbf275f6c0dd\"\u003e\u003ccode\u003e9067e03\u003c/code\u003e\u003c/a\u003e Sync CJS and ESM\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9ad98052b316c5e707f8098ace509d2ae165e54d\"\u003e\u003ccode\u003e9ad9805\u003c/code\u003e\u003c/a\u003e Release 3.3.18 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/55e50a0621ec084b4bb4000ea4e86e1191bd3da8\"\u003e\u003ccode\u003e55e50a0\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e10f8d40ce9d1ab47f66d65a16b48086432730d0\"\u003e\u003ccode\u003ee10f8d4\u003c/code\u003e\u003c/a\u003e Update index.native.js (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/606\"\u003e#606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/73d67168136b36fd3b644159b0cff149da4905d9\"\u003e\u003ccode\u003e73d6716\u003c/code\u003e\u003c/a\u003e Release 3.3.17 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/f9d13f150847d117877adee3460a46eceb0cf49b\"\u003e\u003ccode\u003ef9d13f1\u003c/code\u003e\u003c/a\u003e Sync 0 size behaviour with PostCSS 5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9760e112757cf7d46a79abd7a133bc4958757bb8\"\u003e\u003ccode\u003e9760e11\u003c/code\u003e\u003c/a\u003e Release 3.3.16 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66d\"\u003e\u003ccode\u003ee835c9b\u003c/code\u003e\u003c/a\u003e fix(non-secure): clamp negative size to prevent infinite loop (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/601\"\u003e#601\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/96dd086eb24396a275fa93ee78d73b2fece35809\"\u003e\u003ccode\u003e96dd086\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ai/nanoid/compare/3.3.12...3.3.19\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for nanoid since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.15 to 8.5.28\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.28\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes types regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed removing any comments starting with \u003ccode\u003e/*#\u003c/code\u003e (by \u003ca href=\"https://github.com/dylanpulver\"\u003e\u003ccode\u003e@​dylanpulver\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e*\u003c/code\u003e hack before a comment in Custom Properties (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed empty values in the middle of \u003ccode\u003elist.comma()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed whitespace-only values in \u003ccode\u003elist.space()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed rule’s end position on space before semicolon (by \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/romainmenke\"\u003e\u003ccode\u003e@​romainmenke\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed Chinese text in deprecation warning (by \u003ca href=\"https://github.com/Jesse205\"\u003e\u003ccode\u003e@​Jesse205\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.28\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes types regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed removing any comments starting with \u003ccode\u003e/*#\u003c/code\u003e (by \u003ca href=\"https://github.com/dylanpulver\"\u003e\u003ccode\u003e@​dylanpulver\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e*\u003c/code\u003e hack before a comment in Custom Properties (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed empty values in the middle of \u003ccode\u003elist.comma()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed whitespace-only values in \u003ccode\u003elist.space()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed rule’s end position on space before semicolon (by \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/romainmenke\"\u003e\u003ccode\u003e@​romainmenke\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed Chinese text in deprecation warning (by \u003ca href=\"https://github.com/Jesse205\"\u003e\u003ccode\u003e@​Jesse205\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/e544bffc4f4b3966d8ec69c41744b3ed65afc64a\"\u003e\u003ccode\u003ee544bff\u003c/code\u003e\u003c/a\u003e Release 8.5.28 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f8fc2525717a6a7216659f7be43c525f60c6a15a\"\u003e\u003ccode\u003ef8fc252\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/5039fd78962d285abea5d7b3aebef32f053781ce\"\u003e\u003ccode\u003e5039fd7\u003c/code\u003e\u003c/a\u003e Add missed release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/ae40ca499cf6a9afdbb264c0ec09e71fe934e2af\"\u003e\u003ccode\u003eae40ca4\u003c/code\u003e\u003c/a\u003e Release 8.5.27 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/62b1626bb7fbb28eda616d002cbd525d239b18ba\"\u003e\u003ccode\u003e62b1626\u003c/code\u003e\u003c/a\u003e Fix linter\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/1dba9384515a2dbc64517697c2f738b6d5c3f9a4\"\u003e\u003ccode\u003e1dba938\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3e82edc9f037faa41647342dceceba9b841f9881\"\u003e\u003ccode\u003e3e82edc\u003c/code\u003e\u003c/a\u003e Keep non-annotation comments when the processor has no plugins (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2150\"\u003e#2150\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/6d23bc362203118478bc8051b81f2910907ebe6e\"\u003e\u003ccode\u003e6d23bc3\u003c/code\u003e\u003c/a\u003e Fix link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/508e9976be81536292e7666741e1c35e876b9a6a\"\u003e\u003ccode\u003e508e997\u003c/code\u003e\u003c/a\u003e Add GitHub Sponsors link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/e993739dc49b6055f7dfc59b161d75702f0b2b8b\"\u003e\u003ccode\u003ee993739\u003c/code\u003e\u003c/a\u003e Add CodeRabbit sponsor (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2145\"\u003e#2145\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.15...8.5.28\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `shell-quote` from 1.8.4 to 1.10.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md\"\u003eshell-quote's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.9.0...v1.10.0\"\u003ev1.10.0\u003c/a\u003e - 2026-07-10\u003c/h2\u003e\n\u003ch3\u003eMerged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[New] \u003ccode\u003eparse\u003c/code\u003e: add opt-in \u003ccode\u003esplitUnquoted\u003c/code\u003e option for shell field-splitting of unquoted expansions \u003ca href=\"https://redirect.github.com/ljharb/shell-quote/pull/1\"\u003e\u003ccode\u003e[#1](https://github.com/ljharb/shell-quote/issues/1)\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: match nested \u003ccode\u003e${...}\u003c/code\u003e braces so nested parameter expansion is consumed as one substitution \u003ca href=\"https://github.com/ljharb/shell-quote/commit/c0842c8a7a034066da2496a75e91cbe500ff736c\"\u003e\u003ccode\u003ec0842c8\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003eparse\u003c/code\u003e: pin single-quote literalness and unmatched-quote handling \u003ca href=\"https://github.com/ljharb/shell-quote/commit/a0d03e35c8ede24016502c4433b8f5d6b3100a62\"\u003e\u003ccode\u003ea0d03e3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] remove the space in js code fences so evalmd evaluates them \u003ca href=\"https://github.com/ljharb/shell-quote/commit/2116fa36aeea77fe8d561b0db46b1f9b26b8cf1b\"\u003e\u003ccode\u003e2116fa3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003equote\u003c/code\u003e: pin conservative escaping of \u003ccode\u003e=\u003c/code\u003e, \u003ccode\u003e@\u003c/code\u003e, \u003ccode\u003e^\u003c/code\u003e, \u003ccode\u003e,\u003c/code\u003e, \u003ccode\u003e:\u003c/code\u003e, \u003ccode\u003e!\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/1c36f3ff77d26d200620c1027e5c271050120b8e\"\u003e\u003ccode\u003e1c36f3f\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] document that \u003ccode\u003equote\u003c/code\u003e outputs POSIX quoting, not \u003ccode\u003ecmd.exe\u003c/code\u003e/PowerShell \u003ca href=\"https://github.com/ljharb/shell-quote/commit/100e96e0ffadcca97d63dda15651c70b9f83507c\"\u003e\u003ccode\u003e100e96e\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] document \u003ccode\u003eparse\u003c/code\u003e's supported parameter-expansion subset \u003ca href=\"https://github.com/ljharb/shell-quote/commit/e1c75cd6e4a3c60003792c7f2802587d328622cb\"\u003e\u003ccode\u003ee1c75cd\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: a backslash inside single quotes must not escape the closing quote \u003ca href=\"https://github.com/ljharb/shell-quote/commit/5d460a332b54b83153297fe7d1964330b28fa491\"\u003e\u003ccode\u003e5d460a3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] fix stale example outputs \u003ca href=\"https://github.com/ljharb/shell-quote/commit/2de86f5d44f44d3ac9df36413d8a05f3534cdec6\"\u003e\u003ccode\u003e2de86f5\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003equote\u003c/code\u003e: pin that a backslash with whitespace is not doubled in single quotes (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/14\"\u003e#14\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/190e236bcf1d81caa8e40e8ea3bb11998575be71\"\u003e\u003ccode\u003e190e236\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] \u003ccode\u003equote\u003c/code\u003e: use output verbatim; do not re-quote it (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/1b364683b1e9e8d078fd3017cde82cf10c9c04a5\"\u003e\u003ccode\u003e1b36468\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Refactor] \u003ccode\u003eparse\u003c/code\u003e: fix swapped \u003ccode\u003eSINGLE_QUOTE\u003c/code\u003e/\u003ccode\u003eDOUBLE_QUOTE\u003c/code\u003e variable names \u003ca href=\"https://github.com/ljharb/shell-quote/commit/801af5c935b27d6dcda63b3975d5e92a7b6f887f\"\u003e\u003ccode\u003e801af5c\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[types] fix an error TS v6 ignores but v7 fails on \u003ca href=\"https://github.com/ljharb/shell-quote/commit/59bbf8b81bf3236842deb72805744d489f650eba\"\u003e\u003ccode\u003e59bbf8b\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@arethetypeswrong/cli\u003c/code\u003e, \u003ccode\u003eevalmd\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/a04d47516e1cd5b1b4d3f720ddf97561ed0082fc\"\u003e\u003ccode\u003ea04d475\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@arethetypeswrong/ci\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/d390f9a92b97a04b1f799298634e90dc581021e6\"\u003e\u003ccode\u003ed390f9a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003equote\u003c/code\u003e: the tilde test escapes every \u003ccode\u003e~\u003c/code\u003e, not just a leading one (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/9\"\u003e#9\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/617d119795c7b44d6e49a4d41f80195c4aa5735c\"\u003e\u003ccode\u003e617d119\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.4...v1.9.0\"\u003ev1.9.0\u003c/a\u003e - 2026-06-24\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[New] add types \u003ca href=\"https://github.com/ljharb/shell-quote/commit/dca6e21a02df4cc1a83ed1b5baa4d82df134170a\"\u003e\u003ccode\u003edca6e21\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9aa9e8f60991f8c4053a29e476795d891ff851ad\"\u003e\u003ccode\u003e9aa9e8f\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: finalize tokens in linear time (GHSA-395f-4hp3-45gv) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7ff5488599d01c323514f02f5efb74088dd134ec\"\u003e\u003ccode\u003e7ff5488\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] update workflows \u003ca href=\"https://github.com/ljharb/shell-quote/commit/75e849741ffaf2d3aa53ae0e18ef6bf9929ef478\"\u003e\u003ccode\u003e75e8497\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] Windows + node 4/6/7: pin eslint to 9 before install, since npm 2/3 cannot stage eslint 10\u003ccode\u003e@types/esrecurse\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/3fb739de44b81c69431947d54fbfc18998dd6d72\"\u003e\u003ccode\u003e3fb739d\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] retry \u003ccode\u003enpm install\u003c/code\u003e on Windows to survive npm 2/3 staging-rename flake \u003ca href=\"https://github.com/ljharb/shell-quote/commit/abe0163293c82963fa8a16cfaa87181846d5aced\"\u003e\u003ccode\u003eabe0163\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] Windows + node 5/7: install deps with a modern node \u003ca href=\"https://github.com/ljharb/shell-quote/commit/b4bafa2e7e58d53d9839b1c24976f61e54b43326\"\u003e\u003ccode\u003eb4bafa2\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003equote\u003c/code\u003e: escape leading \u003ccode\u003e~\u003c/code\u003e to prevent shell tilde-expansion \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7a76c1a12d8461c2234a1c655b943cee84cbff91\"\u003e\u003ccode\u003e7a76c1a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003etape\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7184b4458b65c17b931e126d8cb5f586c6717dc8\"\u003e\u003ccode\u003e7184b44\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] apparently \u003ccode\u003ejackspeak\u003c/code\u003e is no longer in the graph \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9ba368a4057b9f498b0fef23b5b15543ef81b98c\"\u003e\u003ccode\u003e9ba368a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/64988d9a0e73a2ae710488952e3614958ef289d4\"\u003e\u003ccode\u003e64988d9\u003c/code\u003e\u003c/a\u003e v1.10.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/617d119795c7b44d6e49a4d41f80195c4aa5735c\"\u003e\u003ccode\u003e617d119\u003c/code\u003e\u003c/a\u003e [Tests] \u003ccode\u003equote\u003c/code\u003e: the tilde test escapes every \u003ccode\u003e~\u003c/code\u003e, not just a leading one (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/9\"\u003e#9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/59bbf8b81bf3236842deb72805744d489f650eba\"\u003e\u003ccode\u003e59bbf8b\u003c/code\u003e\u003c/a\u003e [types] fix an error TS v6 ignores but v7 fails on\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/190e236bcf1d81caa8e40e8ea3bb11998575be71\"\u003e\u003ccode\u003e190e236\u003c/code\u003e\u003c/a\u003e [Tests] \u003ccode\u003equote\u003c/code\u003e: pin that a backslash with whitespace is not doubled in singl...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/a04d47516e1cd5b1b4d3f720ddf97561ed0082fc\"\u003e\u003ccode\u003ea04d475\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003e@arethetypeswrong/cli\u003c/code\u003e, \u003ccode\u003eevalmd\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/b9545b39f4de17aa169410823c98acf58387e474\"\u003e\u003ccode\u003eb9545b3\u003c/code\u003e\u003c/a\u003e [New] \u003ccode\u003eparse\u003c/code\u003e: add opt-in \u003ccode\u003esplitUnquoted\u003c/code\u003e option for shell field-splitting of...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/1b364683b1e9e8d078fd3017cde82cf10c9c04a5\"\u003e\u003ccode\u003e1b36468\u003c/code\u003e\u003c/a\u003e [readme] \u003ccode\u003equote\u003c/code\u003e: use output verbatim; do not re-quote it (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/1c36f3ff77d26d200620c1027e5c271050120b8e\"\u003e\u003ccode\u003e1c36f3f\u003c/code\u003e\u003c/a\u003e [Tests] \u003ccode\u003equote\u003c/code\u003e: pin conservative escaping of \u003ccode\u003e=\u003c/code\u003e, \u003ccode\u003e@\u003c/code\u003e, \u003ccode\u003e^\u003c/code\u003e, \u003ccode\u003e,\u003c/code\u003e, \u003ccode\u003e:\u003c/code\u003e, \u003ccode\u003e!\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/e1c75cd6e4a3c60003792c7f2802587d328622cb\"\u003e\u003ccode\u003ee1c75cd\u003c/code\u003e\u003c/a\u003e [readme] document \u003ccode\u003eparse\u003c/code\u003e's supported parameter-expansion subset\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/c0842c8a7a034066da2496a75e91cbe500ff736c\"\u003e\u003ccode\u003ec0842c8\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003eparse\u003c/code\u003e: match nested \u003ccode\u003e${...}\u003c/code\u003e braces so nested parameter expansion is ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.4...v1.10.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `svgo` from 3.3.3 to 3.3.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/svg/svgo/releases\"\u003esvgo's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.3.5\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBackport the \u003ccode\u003eremoveScriptElement\u003c/code\u003e hardening from SVGO v4 in \u003ca href=\"https://redirect.github.com/svg/svgo/issues/2269\"\u003e#2269\u003c/a\u003e:\n\u003cul\u003e\n\u003cli\u003ereject executable \u003ccode\u003edata:\u003c/code\u003e URLs and legacy \u003ccode\u003evbscript:\u003c/code\u003e URLs\u003c/li\u003e\n\u003cli\u003esanitize executable HTML inside \u003ccode\u003e\u0026lt;foreignObject\u0026gt;\u003c/code\u003e elements\u003c/li\u003e\n\u003cli\u003ehandle namespace-prefixed SVG anchors and URL schemes containing ASCII tabs or newlines\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThis addresses \u003ca href=\"https://github.com/svg/svgo/security/advisories/GHSA-4vpr-x523-8j87\"\u003eGHSA-4vpr-x523-8j87\u003c/a\u003e and \u003ca href=\"https://github.com/svg/svgo/security/advisories/GHSA-w27v-7q3p-w38r\"\u003eGHSA-w27v-7q3p-w38r\u003c/a\u003e for the v3 release line.\u003c/p\u003e\n\u003ch2\u003eSupport\u003c/h2\u003e\n\u003cp\u003eSVGO v3 is not officially supported; please consider upgrading to SVGO v4. This security fix has been backported, but there is no commitment to backport more complex changes in the future.\u003c/p\u003e\n\u003cp\u003eSee the \u003ca href=\"https://svgo.dev/docs/migrations/migration-from-v3-to-v4/\"\u003emigration guide from v3 to v4\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003ev3.3.4\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://svgo.dev/docs/plugins/removeScripts/\"\u003eremoveScriptElement\u003c/a\u003e, remove JavaScript URIs case-insensitively and make \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e handling namespace aware. By \u003ca href=\"https://github.com/SethFalco\"\u003e\u003ccode\u003e@​SethFalco\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eSupport\u003c/h2\u003e\n\u003cp\u003eSVGO v3 is not officially supported, please consider upgrading to SVGO v4 instead. We've backported this fix as there are security implications, but there is no commitment to do this for more complex changes in future.\u003c/p\u003e\n\u003cp\u003eConsider reading our \u003ca href=\"https://svgo.dev/docs/migrations/migration-from-v3-to-v4/\"\u003eMigration Guide from v3 to v4\u003c/a\u003e which should ease the process.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/svg/svgo/commit/438059032950dde2c2d36ce45f912085947e60d0\"\u003e\u003ccode\u003e4380590\u003c/code\u003e\u003c/a\u003e ci: configure v3 publish tag in package metadata (\u003ca href=\"https://redirect.github.com/svg/svgo/issues/2271\"\u003e#2271\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/svg/svgo/commit/4c84fe7ef022f05350404a469ca66321e0afcb47\"\u003e\u003ccode\u003e4c84fe7\u003c/code\u003e\u003c/a\u003e ci: publish v3 with npm trusted publishing (\u003ca href=\"https://redirect.github.com/svg/svgo/issues/2270\"\u003e#2270\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/svg/svgo/commit/994a9f00d79ddec68ce19a1ce9eb8ca08d747e4f\"\u003e\u003ccode\u003e994a9f0\u003c/code\u003e\u003c/a\u003e fix(removeScriptElement): backport security hardening to v3 (\u003ca href=\"https://redirect.github.com/svg/svgo/issues/2269\"\u003e#2269\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/svg/svgo/commit/72a23886b4698b27624b936f3a15a80afd36d75f\"\u003e\u003ccode\u003e72a2388\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/svg/svgo/compare/v3.3.3...v3.3.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for svgo since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.28.0 to 7.29.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.1\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/f690157d728508652fef14673630c71515123e96\"\u003ef690157d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6615e0175e9b635bcd2e3e87a47daa82f6f5b728\"\u003e6615e017\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/63cf698b611fecc6ee0a17b185b930051e4b982f\"\u003e63cf698b\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1858656ebb1e919311c1f31613dfd581b7214349\"\u003e1858656e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/b6c5a00252c37da9dd2db9bead053bb843e1f988\"\u003eb6c5a002\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2c7d7e1227043c644c4c32cfd1e276f4fd4fcb11\"\u003e2c7d7e12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3c6726599cea8646384dde846c97d630da472a74\"\u003e3c672659\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/b61d9432bac7caac51273ad209862e4c0bf935ae\"\u003eb61d9432\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/21693f406f0142f3504192e9f9b022dcf84782ae\"\u003e21693f40\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cd8af90b38ae33c2838d54a2d629774122effe95\"\u003ecd8af90b\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[v7.x] drop: remove Node.js 26 from shared-builtin CI build by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5592\"\u003enodejs/undici#5592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): honour headersTimeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5604\"\u003enodejs/undici#5604\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): keep the connection ref'd while requests are outstanding by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5605\"\u003enodejs/undici#5605\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: increase Windows workflow timeout on v7.x by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5621\"\u003enodejs/undici#5621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): retire the request that completed, not the head of the queue by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5618\"\u003enodejs/undici#5618\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): settle a request whose stream is cancelled by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5607\"\u003enodejs/undici#5607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: reduce EventSourceStream parser allocations (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5032\"\u003e#5032\u003c/a\u003e) by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5646\"\u003enodejs/undici#5646\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): handle GOAWAY for CONNECT streams by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5640\"\u003enodejs/undici#5640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v7.x] perf(h1): drop idle-socket timer floor with a ref'd setImmediate (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5707\"\u003e#5707\u003c/a\u003e) by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5769\"\u003enodejs/undici#5769\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.29.0...v7.29.1\"\u003ehttps://github.com/nodejs/undici/compare/v7.29.0...v7.29.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d39a83e7b0d631590c3b85b5cc0dbeab66c3a1d8\"\u003e\u003ccode\u003ed39a83e\u003c/code\u003e\u003c/a\u003e Bumped v7.29.1 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5772\"\u003e#5772\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0d88464876d02bdb9cf27015d9d66500a8aaa782\"\u003e\u003ccode\u003e0d88464\u003c/code\u003e\u003c/a\u003e fix(test): remove unused EventEmitter import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f57411b894d45b89964252971497507500c32bc1\"\u003e\u003ccode\u003ef57411b\u003c/code\u003e\u003c/a\u003e perf(h1): drop idle-socket timer floor with a ref'd setImmediate (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5707\"\u003e#5707\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5769\"\u003e#5769\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3c6726599cea8646384dde846c97d630da472a74\"\u003e\u003ccode\u003e3c67265\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cd8af90b38ae33c2838d54a2d629774122effe95\"\u003e\u003ccode\u003ecd8af90\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6615e0175e9b635bcd2e3e87a47daa82f6f5b728\"\u003e\u003ccode\u003e6615e01\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2c7d7e1227043c644c4c32cfd1e276f4fd4fcb11\"\u003e\u003ccode\u003e2c7d7e1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b6c5a00252c37da9dd2db9bead053bb843e1f988\"\u003e\u003ccode\u003eb6c5a00\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/21693f406f0142f3504192e9f9b022dcf84782ae\"\u003e\u003ccode\u003e21693f4\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f690157d728508652fef14673630c71515123e96\"\u003e\u003ccode\u003ef690157\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot cr...\n\n_Description has been truncated_","html_url":"https://github.com/presiannedyalkov/eco-balance-documentation/pull/558","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/presiannedyalkov%2Feco-balance-documentation/issues/558","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/558/packages"}},{"old_version":"3.1.0","new_version":"3.1.7","update_type":"patch","path":null,"pr_created_at":"2026-09-13T08:16:33.000Z","version_change":"3.1.0 → 3.1.7","issue":{"uuid":"5439014474","node_id":"PR_kwDOKD4oKs8AAAABDUlQSg","number":310,"state":"closed","title":"chore(deps): bump the npm_and_yarn group across 1 directory with 23 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":"2026-09-13T08:16:41.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-13T08:16:33.000Z","updated_at":"2026-09-13T08:16:50.000Z","time_to_close":8,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":23,"packages":[{"name":"@astrojs/netlify","old_version":"6.6.5","new_version":"8.1.2","repository_url":"https://github.com/withastro/astro"},{"name":"astro","old_version":"5.18.1","new_version":"7.2.8","repository_url":"https://github.com/withastro/astro"},{"name":"@babel/core","old_version":"7.29.0","new_version":"7.29.7","repository_url":"https://github.com/babel/babel"},{"name":"@babel/plugin-transform-modules-systemjs","old_version":"7.29.0","new_version":"7.29.8","repository_url":"https://github.com/babel/babel"},{"name":"brace-expansion","old_version":"1.1.14","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"esbuild","old_version":"0.25.12","new_version":"0.28.2","repository_url":"https://github.com/evanw/esbuild"},{"name":"vite","old_version":"6.4.2","new_version":"7.3.6","repository_url":"https://github.com/vitejs/vite"},{"name":"baseline-browser-mapping","old_version":"2.10.19","new_version":"2.11.23","repository_url":"https://github.com/web-platform-dx/baseline-browser-mapping"},{"name":"browserslist","old_version":"4.28.2","new_version":"4.28.9","repository_url":"https://github.com/browserslist/browserslist"},{"name":"fast-uri","old_version":"3.1.0","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"postcss-selector-parser","old_version":"7.1.1","new_version":"7.1.6","repository_url":"https://github.com/postcss/postcss-selector-parser"},{"name":"serialize-javascript","old_version":"6.0.2","new_version":"7.1.1","repository_url":"https://github.com/yahoo/serialize-javascript"},{"name":"smol-toml","old_version":"1.6.1","new_version":"1.8.0","repository_url":"https://github.com/squirrelchat/smol-toml"},{"name":"svgo","old_version":"4.0.1","new_version":"4.1.0","repository_url":"https://github.com/svg/svgo"},{"name":"yaml","old_version":"2.7.1","new_version":"2.8.3","repository_url":"https://github.com/eemeli/yaml"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 15 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@astrojs/netlify](https://github.com/withastro/astro/tree/HEAD/packages/integrations/netlify) | `6.6.5` | `8.1.2` |\n| [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro) | `5.18.1` | `7.2.8` |\n| [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) | `7.29.0` | `7.29.7` |\n| [@babel/plugin-transform-modules-systemjs](https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs) | `7.29.0` | `7.29.8` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.14` | `1.1.18` |\n| [esbuild](https://github.com/evanw/esbuild) | `0.25.12` | `0.28.2` |\n| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `6.4.2` | `7.3.6` |\n| [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) | `2.10.19` | `2.11.23` |\n| [browserslist](https://github.com/browserslist/browserslist) | `4.28.2` | `4.28.9` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.0` | `3.1.7` |\n| [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) | `7.1.1` | `7.1.6` |\n| [serialize-javascript](https://github.com/yahoo/serialize-javascript) | `6.0.2` | `7.1.1` |\n| [smol-toml](https://github.com/squirrelchat/smol-toml) | `1.6.1` | `1.8.0` |\n| [svgo](https://github.com/svg/svgo) | `4.0.1` | `4.1.0` |\n| [yaml](https://github.com/eemeli/yaml) | `2.7.1` | `2.8.3` |\n\n\nUpdates `@astrojs/netlify` from 6.6.5 to 8.1.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/withastro/astro/blob/main/packages/integrations/netlify/CHANGELOG.md\"\u003e@​astrojs/netlify's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.1.2\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17368\"\u003e#17368\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/ee74c289bfe32fb6a7f59ed97c5c22db16394b72\"\u003e\u003ccode\u003eee74c28\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Fixes the generated Netlify Image CDN \u003ccode\u003eremote_images\u003c/code\u003e patterns so that regex metacharacters (such as \u003ccode\u003e.\u003c/code\u003e) in \u003ccode\u003eimage.remotePatterns\u003c/code\u003e (\u003ccode\u003ehostname\u003c/code\u003e, \u003ccode\u003epathname\u003c/code\u003e) and \u003ccode\u003eimage.domains\u003c/code\u003e are matched literally instead of behaving like wildcards. This makes the generated patterns consistent with how Astro matches these values elsewhere.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated dependencies []:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​astrojs/underscore-redirects\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.0.3\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.1.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies [\u003ca href=\"https://github.com/withastro/astro/commit/eb6f97e391ee587747e37609c255c7cd4b9cce3c\"\u003e\u003ccode\u003eeb6f97e\u003c/code\u003e\u003c/a\u003e]:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​astrojs/internal-helpers\u003c/code\u003e\u003ca href=\"https://github.com/0\"\u003e\u003ccode\u003e@​0\u003c/code\u003e\u003c/a\u003e.10.1\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​astrojs/underscore-redirects\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.0.3\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.1.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17245\"\u003e#17245\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/f56d9e7eb46ca59e70f636cb8cd281bdf41971c4\"\u003e\u003ccode\u003ef56d9e7\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/astrobot-houston\"\u003e\u003ccode\u003e@​astrobot-houston\u003c/code\u003e\u003c/a\u003e! - Adds \u003ccode\u003eedgeFunctions\u003c/code\u003e to the \u003ccode\u003edevFeatures\u003c/code\u003e adapter option, allowing users to disable Netlify Edge Function emulation during \u003ccode\u003eastro dev\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eSome npm packages that access the filesystem at initialization (e.g. \u003ccode\u003enode-html-parser\u003c/code\u003e) fail inside the edge function sandbox with \u0026quot;Reading or writing files with Edge Functions is not supported yet.\u0026quot; You can now disable edge function emulation to avoid this error:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003eimport netlify from '@astrojs/netlify';\nimport { defineConfig } from 'astro/config';\n\u003cp\u003eexport default defineConfig({\nadapter: netlify({\ndevFeatures: {\nedgeFunctions: false,\n},\n}),\n});\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eEdge functions will still work in production builds and via \u003ccode\u003enetlify dev\u003c/code\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17249\"\u003e#17249\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/02b73b0fc2e32102e788fd9031ce061337490a73\"\u003e\u003ccode\u003e02b73b0\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ematipico\"\u003e\u003ccode\u003e@​ematipico\u003c/code\u003e\u003c/a\u003e! - Fixes an issue where the \u003ccode\u003epeerDependencies\u003c/code\u003e field used incorrect dependencies.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated dependencies []:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​astrojs/underscore-redirects\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.0.3\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.0.0\u003c/h2\u003e\n\u003ch3\u003eMajor Changes\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/dec769217f62b4f7546b448c4e9f947bda4422c8\"\u003e\u003ccode\u003edec7692\u003c/code\u003e\u003c/a\u003e [ci] release (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/integrations/netlify/issues/17338\"\u003e#17338\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/ee74c289bfe32fb6a7f59ed97c5c22db16394b72\"\u003e\u003ccode\u003eee74c28\u003c/code\u003e\u003c/a\u003e Match remotePatterns and domains metacharacters literally in Netlify Image CD...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/a86160ee79e4600bf77f89eb2dc84782acdeab6f\"\u003e\u003ccode\u003ea86160e\u003c/code\u003e\u003c/a\u003e [ci] release (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/integrations/netlify/issues/17256\"\u003e#17256\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/7d8ec1f10365a1e99e226172e5694bf078b25a51\"\u003e\u003ccode\u003e7d8ec1f\u003c/code\u003e\u003c/a\u003e [ci] release (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/integrations/netlify/issues/17237\"\u003e#17237\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/3a36fffdb0b8a3337279aa3d21cff53acf95eb10\"\u003e\u003ccode\u003e3a36fff\u003c/code\u003e\u003c/a\u003e [ci] format\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/f56d9e7eb46ca59e70f636cb8cd281bdf41971c4\"\u003e\u003ccode\u003ef56d9e7\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003eedgeFunctions\u003c/code\u003e to Netlify adapter \u003ccode\u003edevFeatures\u003c/code\u003e to allow disabling edge ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/02b73b0fc2e32102e788fd9031ce061337490a73\"\u003e\u003ccode\u003e02b73b0\u003c/code\u003e\u003c/a\u003e fix: peer deps of packages (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/integrations/netlify/issues/17249\"\u003e#17249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/d5fbee8ec341049dc5ddc7b6c251b7a859abf437\"\u003e\u003ccode\u003ed5fbee8\u003c/code\u003e\u003c/a\u003e chore(deps): update sharp to v0.35 (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/integrations/netlify/issues/17234\"\u003e#17234\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/2bfb179545249786e9f395325c88a9dfef574acb\"\u003e\u003ccode\u003e2bfb179\u003c/code\u003e\u003c/a\u003e chore: simpler package.json types (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/integrations/netlify/issues/17229\"\u003e#17229\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/f55ba4caca7c587555da86e3211ae1f1b3407c5f\"\u003e\u003ccode\u003ef55ba4c\u003c/code\u003e\u003c/a\u003e [ci] release (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/integrations/netlify/issues/17132\"\u003e#17132\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/withastro/astro/commits/@astrojs/netlify@8.1.2/packages/integrations/netlify\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `astro` from 5.18.1 to 7.2.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/withastro/astro/releases\"\u003eastro's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eastro@7.2.8\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17837\"\u003e#17837\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/ecb4082131490b4fe9a56aa44fda84b54ef8967b\"\u003e\u003ccode\u003eecb4082\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Updates the minimum supported version of Sharp to 0.35.4\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17786\"\u003e#17786\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/db7c53b1707856866e06cdeeef1aa4ae3598b1f2\"\u003e\u003ccode\u003edb7c53b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/gameroman\"\u003e\u003ccode\u003e@​gameroman\u003c/code\u003e\u003c/a\u003e! - Replaces the internal \u003ccode\u003efind-process\u003c/code\u003e dependency with a smaller, lighter alternative\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eastro@7.2.7\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17415\"\u003e#17415\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/55d38c868b7cbf2266649929c60ddf442abe674f\"\u003e\u003ccode\u003e55d38c8\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/iseraph-dev\"\u003e\u003ccode\u003e@​iseraph-dev\u003c/code\u003e\u003c/a\u003e! - Deserializes each route once when loading the SSR manifest\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17772\"\u003e#17772\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/023b48b139a2c40420b340f61b53a62b47a557e5\"\u003e\u003ccode\u003e023b48b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Fixes route selection for normalized request paths in adapter and development request handling\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17819\"\u003e#17819\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/633855b0cabd55cc7b913eb556a739a6a2d93dd2\"\u003e\u003ccode\u003e633855b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Updates generated and default Cloudflare \u003ccode\u003ecompatibility_date\u003c/code\u003e values to match the installed runtime and requires Wrangler \u003ccode\u003e^4.125.0\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17813\"\u003e#17813\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/ae26d18c71515c47ecbd7e1ffe5c5dfc29fbd613\"\u003e\u003ccode\u003eae26d18\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ccode\u003erewrite()\u003c/code\u003e and \u003ccode\u003enext(payload)\u003c/code\u003e for GET and HEAD requests with host-provided bodies\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17816\"\u003e#17816\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/a0d2fe3af25a25bc9b808070f25886c37d5be6fc\"\u003e\u003ccode\u003ea0d2fe3\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes the experimental \u003ccode\u003esvgOptimizer\u003c/code\u003e not generating unique per-file ID prefixes when using SVGO's \u003ccode\u003eprefixIds\u003c/code\u003e plugin\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eastro@7.2.6\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17812\"\u003e#17812\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/29af6da5c11aff673133f96df029f40345674f0e\"\u003e\u003ccode\u003e29af6da\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Fixes a bug where \u003ccode\u003enew FetchState(request)\u003c/code\u003e could fail in development when server dependencies were optimized\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eastro@7.2.5\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17758\"\u003e#17758\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/5f419e25c570002a2ce0e10a973aa13336016b0c\"\u003e\u003ccode\u003e5f419e2\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes a bug where \u003ccode\u003eexperimental_getFontFileURL()\u003c/code\u003e rejected valid font URLs when using the Cloudflare adapter\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17416\"\u003e#17416\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/493796b4c318b19985eccaac7a11aa7b787e1efe\"\u003e\u003ccode\u003e493796b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/iseraph-dev\"\u003e\u003ccode\u003e@​iseraph-dev\u003c/code\u003e\u003c/a\u003e! - Skips no-op pathname writes when normalizing SSR request URLs\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17712\"\u003e#17712\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/bd374b7507de8d706c845946fd847e76de6fc06b\"\u003e\u003ccode\u003ebd374b7\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/fkatsuhiro\"\u003e\u003ccode\u003e@​fkatsuhiro\u003c/code\u003e\u003c/a\u003e! - Updates deprecation messages target from Astro 7 to 8\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17719\"\u003e#17719\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/dac17688f691c6cecdff969aa48523bf17fc0657\"\u003e\u003ccode\u003edac1768\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/astrobot-houston\"\u003e\u003ccode\u003e@​astrobot-houston\u003c/code\u003e\u003c/a\u003e! - Fixes session ID validation to reject non-UUID cookie values before using them as storage keys\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17770\"\u003e#17770\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/84eb7e7db99573b80c339efe0392d959e7a9b6cf\"\u003e\u003ccode\u003e84eb7e7\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ccode\u003e--mode\u003c/code\u003e, \u003ccode\u003e--site\u003c/code\u003e, \u003ccode\u003e--base\u003c/code\u003e, \u003ccode\u003e--out-dir\u003c/code\u003e, \u003ccode\u003e--verbose\u003c/code\u003e, \u003ccode\u003e--silent\u003c/code\u003e, and \u003ccode\u003e--open\u003c/code\u003e flags being silently dropped when using \u003ccode\u003eastro dev --background\u003c/code\u003e or \u003ccode\u003eastro preview --background\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17713\"\u003e#17713\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/d035290a14afac8834885b727327a7f44d3a3a48\"\u003e\u003ccode\u003ed035290\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/wakqasahmed\"\u003e\u003ccode\u003e@​wakqasahmed\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ccode\u003econtent-modules.mjs\u003c/code\u003e not removing entries for deleted or renamed content files, which could cause Vite to attempt to resolve non-existent modules\u003c/p\u003e\n\u003cp\u003eAs part of this fix, \u003ccode\u003e#moduleImports\u003c/code\u003e is now fully rebuilt from \u003ccode\u003edeferredRender\u003c/code\u003e entries before every write, so a module import added only through the public \u003ccode\u003eaddModuleImport()\u003c/code\u003e API without a corresponding \u003ccode\u003edeferredRender\u003c/code\u003e entry in the store will no longer be preserved across writes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17743\"\u003e#17743\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/adc750fa27ea1d4767e30fc12e64a342fbebbd89\"\u003e\u003ccode\u003eadc750f\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/contactjawad\"\u003e\u003ccode\u003e@​contactjawad\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ccode\u003eAstro.preferredLocale\u003c/code\u003e and \u003ccode\u003eAstro.preferredLocaleList\u003c/code\u003e ignoring \u003ccode\u003eAccept-Language\u003c/code\u003e quality values when they are absent or \u003ccode\u003e0\u003c/code\u003e. An entry without an explicit \u003ccode\u003eq=\u003c/code\u003e now correctly counts as quality \u003ccode\u003e1.0\u003c/code\u003e (per RFC 7231) and an entry with \u003ccode\u003eq=0\u003c/code\u003e is treated as not acceptable, so the highest-quality locale is selected regardless of header order.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17757\"\u003e#17757\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/660991c820fbeb087b2f27361e6ebaeba8285358\"\u003e\u003ccode\u003e660991c\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes build errors showing wrong file location, missing line:col, and misleading hints when a plugin error (e.g. from MDX) is wrapped by Vite's build error\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17783\"\u003e#17783\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/60b14ffff5b7a66b06d9b12e72933ba9222f519d\"\u003e\u003ccode\u003e60b14ff\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Fixes a type error when passing an image from a content collection \u003ccode\u003eimage()\u003c/code\u003e schema to a component or \u003ccode\u003e\u0026lt;Image /\u0026gt;\u003c/code\u003e. The schema returned by \u003ccode\u003eimage()\u003c/code\u003e was missing the \u003ccode\u003eapng\u003c/code\u003e format, so it no longer matched the type of an imported image.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17664\"\u003e#17664\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/d48312502ef33a32aef3f25b6b6035db8b38e189\"\u003e\u003ccode\u003ed483125\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/astrobot-houston\"\u003e\u003ccode\u003e@​astrobot-houston\u003c/code\u003e\u003c/a\u003e! - Fixes an issue where Astro CSP support didn't correctly handle cases \u003ccode\u003e\u0026quot;unsafe-inline\u0026quot;\u003c/code\u003e resource. Now when \u003ccode\u003e\u0026quot;unsafe-inline\u0026quot;\u003c/code\u003e, Astro won't emit hashes for the directive specified.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md\"\u003eastro's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e7.2.8\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17837\"\u003e#17837\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/ecb4082131490b4fe9a56aa44fda84b54ef8967b\"\u003e\u003ccode\u003eecb4082\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Updates the minimum supported version of Sharp to 0.35.4\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17786\"\u003e#17786\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/db7c53b1707856866e06cdeeef1aa4ae3598b1f2\"\u003e\u003ccode\u003edb7c53b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/gameroman\"\u003e\u003ccode\u003e@​gameroman\u003c/code\u003e\u003c/a\u003e! - Replaces the internal \u003ccode\u003efind-process\u003c/code\u003e dependency with a smaller, lighter alternative\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.2.7\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17415\"\u003e#17415\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/55d38c868b7cbf2266649929c60ddf442abe674f\"\u003e\u003ccode\u003e55d38c8\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/iseraph-dev\"\u003e\u003ccode\u003e@​iseraph-dev\u003c/code\u003e\u003c/a\u003e! - Deserializes each route once when loading the SSR manifest\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17772\"\u003e#17772\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/023b48b139a2c40420b340f61b53a62b47a557e5\"\u003e\u003ccode\u003e023b48b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Fixes route selection for normalized request paths in adapter and development request handling\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17819\"\u003e#17819\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/633855b0cabd55cc7b913eb556a739a6a2d93dd2\"\u003e\u003ccode\u003e633855b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Updates generated and default Cloudflare \u003ccode\u003ecompatibility_date\u003c/code\u003e values to match the installed runtime and requires Wrangler \u003ccode\u003e^4.125.0\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17813\"\u003e#17813\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/ae26d18c71515c47ecbd7e1ffe5c5dfc29fbd613\"\u003e\u003ccode\u003eae26d18\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ccode\u003erewrite()\u003c/code\u003e and \u003ccode\u003enext(payload)\u003c/code\u003e for GET and HEAD requests with host-provided bodies\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17816\"\u003e#17816\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/a0d2fe3af25a25bc9b808070f25886c37d5be6fc\"\u003e\u003ccode\u003ea0d2fe3\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes the experimental \u003ccode\u003esvgOptimizer\u003c/code\u003e not generating unique per-file ID prefixes when using SVGO's \u003ccode\u003eprefixIds\u003c/code\u003e plugin\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.2.6\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17812\"\u003e#17812\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/29af6da5c11aff673133f96df029f40345674f0e\"\u003e\u003ccode\u003e29af6da\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Fixes a bug where \u003ccode\u003enew FetchState(request)\u003c/code\u003e could fail in development when server dependencies were optimized\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.2.5\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17758\"\u003e#17758\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/5f419e25c570002a2ce0e10a973aa13336016b0c\"\u003e\u003ccode\u003e5f419e2\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes a bug where \u003ccode\u003eexperimental_getFontFileURL()\u003c/code\u003e rejected valid font URLs when using the Cloudflare adapter\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17416\"\u003e#17416\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/493796b4c318b19985eccaac7a11aa7b787e1efe\"\u003e\u003ccode\u003e493796b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/iseraph-dev\"\u003e\u003ccode\u003e@​iseraph-dev\u003c/code\u003e\u003c/a\u003e! - Skips no-op pathname writes when normalizing SSR request URLs\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17712\"\u003e#17712\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/bd374b7507de8d706c845946fd847e76de6fc06b\"\u003e\u003ccode\u003ebd374b7\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/fkatsuhiro\"\u003e\u003ccode\u003e@​fkatsuhiro\u003c/code\u003e\u003c/a\u003e! - Updates deprecation messages target from Astro 7 to 8\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17719\"\u003e#17719\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/dac17688f691c6cecdff969aa48523bf17fc0657\"\u003e\u003ccode\u003edac1768\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/astrobot-houston\"\u003e\u003ccode\u003e@​astrobot-houston\u003c/code\u003e\u003c/a\u003e! - Fixes session ID validation to reject non-UUID cookie values before using them as storage keys\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17770\"\u003e#17770\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/84eb7e7db99573b80c339efe0392d959e7a9b6cf\"\u003e\u003ccode\u003e84eb7e7\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ccode\u003e--mode\u003c/code\u003e, \u003ccode\u003e--site\u003c/code\u003e, \u003ccode\u003e--base\u003c/code\u003e, \u003ccode\u003e--out-dir\u003c/code\u003e, \u003ccode\u003e--verbose\u003c/code\u003e, \u003ccode\u003e--silent\u003c/code\u003e, and \u003ccode\u003e--open\u003c/code\u003e flags being silently dropped when using \u003ccode\u003eastro dev --background\u003c/code\u003e or \u003ccode\u003eastro preview --background\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17713\"\u003e#17713\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/d035290a14afac8834885b727327a7f44d3a3a48\"\u003e\u003ccode\u003ed035290\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/wakqasahmed\"\u003e\u003ccode\u003e@​wakqasahmed\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ccode\u003econtent-modules.mjs\u003c/code\u003e not removing entries for deleted or renamed content files, which could cause Vite to attempt to resolve non-existent modules\u003c/p\u003e\n\u003cp\u003eAs part of this fix, \u003ccode\u003e#moduleImports\u003c/code\u003e is now fully rebuilt from \u003ccode\u003edeferredRender\u003c/code\u003e entries before every write, so a module import added only through the public \u003ccode\u003eaddModuleImport()\u003c/code\u003e API without a corresponding \u003ccode\u003edeferredRender\u003c/code\u003e entry in the store will no longer be preserved across writes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17743\"\u003e#17743\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/adc750fa27ea1d4767e30fc12e64a342fbebbd89\"\u003e\u003ccode\u003eadc750f\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/contactjawad\"\u003e\u003ccode\u003e@​contactjawad\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ccode\u003eAstro.preferredLocale\u003c/code\u003e and \u003ccode\u003eAstro.preferredLocaleList\u003c/code\u003e ignoring \u003ccode\u003eAccept-Language\u003c/code\u003e quality values when they are absent or \u003ccode\u003e0\u003c/code\u003e. An entry without an explicit \u003ccode\u003eq=\u003c/code\u003e now correctly counts as quality \u003ccode\u003e1.0\u003c/code\u003e (per RFC 7231) and an entry with \u003ccode\u003eq=0\u003c/code\u003e is treated as not acceptable, so the highest-quality locale is selected regardless of header order.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17757\"\u003e#17757\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/660991c820fbeb087b2f27361e6ebaeba8285358\"\u003e\u003ccode\u003e660991c\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes build errors showing wrong file location, missing line:col, and misleading hints when a plugin error (e.g. from MDX) is wrapped by Vite's build error\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/7cadf1055a61c85d0b05f3c7d8c709f7faa5cf0d\"\u003e\u003ccode\u003e7cadf10\u003c/code\u003e\u003c/a\u003e [ci] release (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17826\"\u003e#17826\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/ecb4082131490b4fe9a56aa44fda84b54ef8967b\"\u003e\u003ccode\u003eecb4082\u003c/code\u003e\u003c/a\u003e Update Sharp to 0.35.4 (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17837\"\u003e#17837\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/8bf6f1af679947ffbc702db26425f3f13a7f3040\"\u003e\u003ccode\u003e8bf6f1a\u003c/code\u003e\u003c/a\u003e chore: split v5/v6 changelogs (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17825\"\u003e#17825\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/db7c53b1707856866e06cdeeef1aa4ae3598b1f2\"\u003e\u003ccode\u003edb7c53b\u003c/code\u003e\u003c/a\u003e chore(deps): replace \u0026quot;find-process\u0026quot; with a smaller, lighter alternative (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17786\"\u003e#17786\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/eface15c86b38d44e94b841c9d1e27394c470600\"\u003e\u003ccode\u003eeface15\u003c/code\u003e\u003c/a\u003e [ci] release (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17815\"\u003e#17815\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/633855b0cabd55cc7b913eb556a739a6a2d93dd2\"\u003e\u003ccode\u003e633855b\u003c/code\u003e\u003c/a\u003e Use workerd's compatibility date for Cloudflare defaults (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17819\"\u003e#17819\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/55d38c868b7cbf2266649929c60ddf442abe674f\"\u003e\u003ccode\u003e55d38c8\u003c/code\u003e\u003c/a\u003e Deserialize each route once when loading the manifest (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17415\"\u003e#17415\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/a0d2fe3af25a25bc9b808070f25886c37d5be6fc\"\u003e\u003ccode\u003ea0d2fe3\u003c/code\u003e\u003c/a\u003e Pass file path to SVGO so \u003ccode\u003eprefixIds\u003c/code\u003e generates unique per-file prefixes (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17\"\u003e#17\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/ae26d18c71515c47ecbd7e1ffe5c5dfc29fbd613\"\u003e\u003ccode\u003eae26d18\u003c/code\u003e\u003c/a\u003e Handle GET and HEAD request bodies during rewrites (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17813\"\u003e#17813\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/023b48b139a2c40420b340f61b53a62b47a557e5\"\u003e\u003ccode\u003e023b48b\u003c/code\u003e\u003c/a\u003e Normalize request paths before route matching (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17772\"\u003e#17772\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/withastro/astro/commits/astro@7.2.8/packages/astro\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@babel/core` from 7.29.0 to 7.29.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/babel/babel/releases\"\u003e@​babel/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.7 (2026-05-25)\u003c/h2\u003e\n\u003cp\u003eRe-release all packages with npm provenance attestations\u003c/p\u003e\n\u003ch2\u003ev7.29.6 (2026-05-25)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18014\"\u003e#18014\u003c/a\u003e Catchup source map position in preserveFormat (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18001\"\u003e#18001\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e, \u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17998\"\u003e#17998\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 3\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMateusz Burzyński (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.5 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:house:  Internal\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@babel/*\u003c/code\u003e dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.4 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17974\"\u003e#17974\u003c/a\u003e [7.x backport]fix(systemjs): improve module string name support (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 1\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.3 (2026-04-30)\u003c/h2\u003e\n\u003ch4\u003e:eyeglasses: Spec Compliance\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17923\"\u003e#17923\u003c/a\u003e Support flow extends bound (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-helper-create-class-features-plugin\u003c/code\u003e, \u003ccode\u003ebabel-plugin-proposal-decorators\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17931\"\u003e#17931\u003c/a\u003e fix(decorators): replace super within all removed static elements (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-register\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17915\"\u003e#17915\u003c/a\u003e Fix thread synchronization issues in \u003ccode\u003e@babel/register\u003c/code\u003e (\u003ca href=\"https://github.com/liuxingbaoyu\"\u003e\u003ccode\u003e@​liuxingbaoyu\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-compat-data\u003c/code\u003e, \u003ccode\u003ebabel-plugin-bugfix-safari-rest-destructuring-rhs-array\u003c/code\u003e, \u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17788\"\u003e#17788\u003c/a\u003e Add bugfix plugin for Safari array rest destructuring bug (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:nail_care: Polish\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/4fba7541180bf5f58256d8e358b544e3831ad090\"\u003e\u003ccode\u003e4fba754\u003c/code\u003e\u003c/a\u003e v7.29.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/04ea6b27fdac8f40c3481aec2080ac9678779509\"\u003e\u003ccode\u003e04ea6b2\u003c/code\u003e\u003c/a\u003e v7.29.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/99f498a9b9fa0b900d603fbe8f6601bb3b9e42bb\"\u003e\u003ccode\u003e99f498a\u003c/code\u003e\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/18001\"\u003e#18001\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/feba0a3654c596bd369d1ef1231f5d56666d56dc\"\u003e\u003ccode\u003efeba0a3\u003c/code\u003e\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17998\"\u003e#17998\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/babel/babel/commits/v7.29.7/packages/babel-core\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@babel/plugin-transform-modules-systemjs` from 7.29.0 to 7.29.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/babel/babel/releases\"\u003e@​babel/plugin-transform-modules-systemjs's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.8 (2026-07-31)\u003c/h2\u003e\n\u003ch4\u003e:eyeglasses: Spec Compliance\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e, \u003ccode\u003ebabel-parser\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-spread\u003c/code\u003e, \u003ccode\u003ebabel-traverse\u003c/code\u003e, \u003ccode\u003ebabel-types\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17871\"\u003e#17871\u003c/a\u003e Disallow super call after new (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18046\"\u003e#18046\u003c/a\u003e fix(generator): improve new callee parens check (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-node\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18044\"\u003e#18044\u003c/a\u003e fix(systemjs): support \u003ccode\u003e__proto__\u003c/code\u003e as an export name (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 2\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.7 (2026-05-25)\u003c/h2\u003e\n\u003cp\u003eRe-release all packages with npm provenance attestations\u003c/p\u003e\n\u003ch2\u003ev7.29.6 (2026-05-25)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18014\"\u003e#18014\u003c/a\u003e Catchup source map position in preserveFormat (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18001\"\u003e#18001\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e, \u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17998\"\u003e#17998\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 3\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMateusz Burzyński (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.5 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:house:  Internal\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@babel/*\u003c/code\u003e dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.4 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17974\"\u003e#17974\u003c/a\u003e [7.x backport]fix(systemjs): improve module string name support (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 1\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/5de11ca9234379b78ef95df72aebbec93f28bf45\"\u003e\u003ccode\u003e5de11ca\u003c/code\u003e\u003c/a\u003e v7.29.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/f08d4342e1f189a56e7cee46e60a1817af96219e\"\u003e\u003ccode\u003ef08d434\u003c/code\u003e\u003c/a\u003e fix(systemjs): support \u003cstrong\u003eproto\u003c/strong\u003e as an export name (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs/issues/18044\"\u003e#18044\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/4fba7541180bf5f58256d8e358b544e3831ad090\"\u003e\u003ccode\u003e4fba754\u003c/code\u003e\u003c/a\u003e v7.29.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/a458f66074b97d54773db8159af673d23b26079b\"\u003e\u003ccode\u003ea458f66\u003c/code\u003e\u003c/a\u003e v7.29.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/32ebd5aaf2526ddd176fd6a3d1e3dc594abdc8d9\"\u003e\u003ccode\u003e32ebd5a\u003c/code\u003e\u003c/a\u003e [7.x backport]fix(systemjs): improve module string name support (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs/issues/17974\"\u003e#17974\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/babel/babel/commits/v7.29.8/packages/babel-plugin-transform-modules-systemjs\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.14 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24\"\u003e\u003ccode\u003e2203f4f\u003c/code\u003e\u003c/a\u003e 1.1.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd\"\u003e\u003ccode\u003e0b09384\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@opentelemetry/core` from 1.30.1 to 2.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/releases\"\u003e@​opentelemetry/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.8.0\u003c/h2\u003e\n\u003ch2\u003e2.8.0\u003c/h2\u003e\n\u003ch3\u003e:rocket: Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(sdk-trace-base): pretty-print \u003ccode\u003eSpanImpl\u003c/code\u003e, \u003ccode\u003eTracer\u003c/code\u003e, and \u003ccode\u003eBasicTracerProvider\u003c/code\u003e via \u003ccode\u003eutil.inspect\u003c/code\u003e so they render through \u003ccode\u003ediag\u003c/code\u003e and \u003ccode\u003econsole.log\u003c/code\u003e \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6690\"\u003e#6690\u003c/a\u003e \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(sdk-metrics): implement metric reader self-observability metrics \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6449\"\u003e#6449\u003c/a\u003e \u003ca href=\"https://github.com/anuraaga\"\u003e\u003ccode\u003e@​anuraaga\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(core): add \u003ccode\u003ehrTimeToSeconds\u003c/code\u003e \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6449\"\u003e#6449\u003c/a\u003e \u003ca href=\"https://github.com/anuraaga\"\u003e\u003ccode\u003e@​anuraaga\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(core): limit processing of incoming \u0026quot;baggage\u0026quot; header to 8192 bytes \u003ca href=\"https://github.com/pichlermarc\"\u003e\u003ccode\u003e@​pichlermarc\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.7.1\u003c/h2\u003e\n\u003ch2\u003e2.7.1\u003c/h2\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(core, api): defer trace state validation. Deprecate trace state implementation in api \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6459\"\u003e#6459\u003c/a\u003e \u003ca href=\"https://github.com/david-luna\"\u003e\u003ccode\u003e@​david-luna\u003c/code\u003e\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eimportant:\u003c/strong\u003e this bug fix may be breaking for certain uses of \u003ccode\u003eTraceState\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eset\u003c/code\u003e now returns the same \u003ccode\u003eTraceState\u003c/code\u003e instance if key/value are invalid or makes the while trace state invalid.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eunset\u003c/code\u003e now returns the same \u003ccode\u003eTraceState\u003c/code\u003e instance if key is not present.\u003c/li\u003e\n\u003cli\u003ebest-effort parsing of invalid \u003ccode\u003eTraceState\u003c/code\u003es has changed: when multiple keys with the same name are present, the most recent one will win.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:house: Internal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eperf(sdk-trace-base): optimize TraceIdRatioBasedSampler performance \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6284\"\u003e#6284\u003c/a\u003e \u003ca href=\"https://github.com/AbhiPrasad\"\u003e\u003ccode\u003e@​AbhiPrasad\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf(sdk-metrics): reduce loop overhead in sdk hot paths \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6593\"\u003e#6593\u003c/a\u003e \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.7.0\u003c/h2\u003e\n\u003ch2\u003e2.7.0\u003c/h2\u003e\n\u003ch3\u003e:rocket: Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(sdk-logs): implement log creation metrics \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6433\"\u003e#6433\u003c/a\u003e \u003ca href=\"https://github.com/anuraaga\"\u003e\u003ccode\u003e@​anuraaga\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(sdk-metrics): add the cardinalitySelector argument to PeriodicExportingMetricReaders\n\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6460\"\u003e#6460\u003c/a\u003e \u003ca href=\"https://github.com/starzlocker\"\u003e\u003ccode\u003e@​starzlocker\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(opentelemetry-core): add extra checks on internal merge function for safety \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6587\"\u003e#6587\u003c/a\u003e \u003ca href=\"https://github.com/maryliag\"\u003e\u003ccode\u003e@​maryliag\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(opentelemetry-resources): do not discard OTEL_RESOURCE_ATTRIBUTES when it contains empty kv pairs\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:house: Internal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003etest(exporter-zipkin): fix broken browser test assertions and add missing coverage \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6566\"\u003e#6566\u003c/a\u003e \u003ca href=\"https://github.com/overbalance\"\u003e\u003ccode\u003e@​overbalance\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(sdk-metrics): repair ExponentialHistogram tests \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6565\"\u003e#6565\u003c/a\u003e \u003ca href=\"https://github.com/overbalance\"\u003e\u003ccode\u003e@​overbalance\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md\"\u003e@​opentelemetry/core's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.8.0\u003c/h2\u003e\n\u003ch3\u003e:rocket: Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(sdk-trace-base): pretty-print \u003ccode\u003eSpanImpl\u003c/code\u003e, \u003ccode\u003eTracer\u003c/code\u003e, and \u003ccode\u003eBasicTracerProvider\u003c/code\u003e via \u003ccode\u003eutil.inspect\u003c/code\u003e so they render through \u003ccode\u003ediag\u003c/code\u003e and \u003ccode\u003econsole.log\u003c/code\u003e \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6690\"\u003e#6690\u003c/a\u003e \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(sdk-metrics): implement metric reader self-observability metrics \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6449\"\u003e#6449\u003c/a\u003e \u003ca href=\"https://github.com/anuraaga\"\u003e\u003ccode\u003e@​anuraaga\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(core): add \u003ccode\u003ehrTimeToSeconds\u003c/code\u003e \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6449\"\u003e#6449\u003c/a\u003e \u003ca href=\"https://github.com/anuraaga\"\u003e\u003ccode\u003e@​anuraaga\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(core): limit processing of incoming \u0026quot;baggage\u0026quot; header to 8192 bytes \u003ca href=\"https://github.com/pichlermarc\"\u003e\u003ccode\u003e@​pichlermarc\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.7.1\u003c/h2\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(core, api): defer trace state validation. Deprecate trace state implementation in api \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6459\"\u003e#6459\u003c/a\u003e \u003ca href=\"https://github.com/david-luna\"\u003e\u003ccode\u003e@​david-luna\u003c/code\u003e\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eimportant:\u003c/strong\u003e this bug fix may be breaking for certain uses of \u003ccode\u003eTraceState\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eset\u003c/code\u003e now returns the same \u003ccode\u003eTraceState\u003c/code\u003e instance if key/value are invalid or makes the while trace state invalid.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eunset\u003c/code\u003e now returns the same \u003ccode\u003eTraceState\u003c/code\u003e instance if key is not present.\u003c/li\u003e\n\u003cli\u003ebest-effort parsing of invalid \u003ccode\u003eTraceState\u003c/code\u003es has changed: when multiple keys with the same name are present, the most recent one will win.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:house: Internal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eperf(sdk-trace-base): optimize TraceIdRatioBasedSampler performance \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6284\"\u003e#6284\u003c/a\u003e \u003ca href=\"https://github.com/AbhiPrasad\"\u003e\u003ccode\u003e@​AbhiPrasad\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: test Node.js 26 in CI \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6671\"\u003e#6671\u003c/a\u003e \u003ca href=\"https://github.com/cjihrig\"\u003e\u003ccode\u003e@​cjihrig\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.7.0\u003c/h2\u003e\n\u003ch3\u003e:rocket: Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(sdk-logs): implement log creation metrics \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6433\"\u003e#6433\u003c/a\u003e \u003ca href=\"https://github.com/anuraaga\"\u003e\u003ccode\u003e@​anuraaga\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(sdk-metrics): add the cardinalitySelector argument to PeriodicExportingMetricReaders\n\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6460\"\u003e#6460\u003c/a\u003e \u003ca href=\"https://github.com/starzlocker\"\u003e\u003ccode\u003e@​starzlocker\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(opentelemetry-core): add extra checks on internal merge function for safety \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6587\"\u003e#6587\u003c/a\u003e \u003ca href=\"https://github.com/maryliag\"\u003e\u003ccode\u003e@​maryliag\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(opentelemetry-resources): do not discard OTEL_RESOURCE_ATTRIBUTES when it contains empty kv pairs\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e:house: Internal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003etest(exporter-zipkin): fix broken browser test assertions and add missing coverage \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6566\"\u003e#6566\u003c/a\u003e \u003ca href=\"https://github.com/overbalance\"\u003e\u003ccode\u003e@​overbalance\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(sdk-metrics): repair ExponentialHistogram tests \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6565\"\u003e#6565\u003c/a\u003e \u003ca href=\"https://github.com/overbalance\"\u003e\u003ccode\u003e@​overbalance\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf(sdk-metrics): reduce loop overhead in sdk hot paths \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/pull/6593\"\u003e#6593\u003c/a\u003e \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.6.1\u003c/h2\u003e\n\u003ch3\u003e:bug: Bug Fixes\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/13a035bc695996cf4aec885fef7b9866f48bc555\"\u003e\u003ccode\u003e13a035b\u003c/code\u003e\u003c/a\u003e chore: prepare next release (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6756\"\u003e#6756\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/4b13587d1e08b47baf153e5312ccd08a3240d074\"\u003e\u003ccode\u003e4b13587\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/71d195c508320295f1892aaed1ee2f1971ffb470\"\u003e\u003ccode\u003e71d195c\u003c/code\u003e\u003c/a\u003e chore(renovate): set minimumReleaseAge to 3 days (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6792\"\u003e#6792\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/555fca6ce94fb8d40a5f869dbd28e43143b4e730\"\u003e\u003ccode\u003e555fca6\u003c/code\u003e\u003c/a\u003e Update renovate.json to use matchManagers (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6141\"\u003e#6141\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/b711a81d5262904245d70f1857b6f3bc811b22cd\"\u003e\u003ccode\u003eb711a81\u003c/code\u003e\u003c/a\u003e docs(otlp-exporter-base): add typedoc entry points so public API is indexed a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/da704029ccd291d65402f3d1c469bd3f25aec047\"\u003e\u003ccode\u003eda70402\u003c/code\u003e\u003c/a\u003e fix(ci): supply-chain sec: disable caching in release-related workflow (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6790\"\u003e#6790\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/002267b1c639aac1d2f1d6e5c7ac3ed023109ea0\"\u003e\u003ccode\u003e002267b\u003c/code\u003e\u003c/a\u003e chore: complete the move to the smaller SPDX license header (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6791\"\u003e#6791\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/056ef9c4e1ddf9306477b7ce26acc7be489f9c6c\"\u003e\u003ccode\u003e056ef9c\u003c/code\u003e\u003c/a\u003e feat(sdk-metrics): implement metric reader metrics (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-js/issues/6449\"\u003e#6449\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/3bd69ce18011f9a16a7231489d9c3acc8294e8d9\"\u003e\u003ccode\u003e3bd69ce\u003c/code\u003e\u003c/a\u003e fix(configuration): improve environment variable substitution to handle all t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/commit/bfbda7c2d90e1686f51cd0fc4d02d785ab9a9cc0\"\u003e\u003ccode\u003ebfbda7c\u003c/code\u003e\u003c/a\u003e docs(exporter-trace-otlp-grpc): import CompressionAlgorithm from otlp-exporte...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/open-telemetry/opentelemetry-js/compare/v1.30.1...v2.8.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​opentelemetry/core\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `esbuild` from 0.25.12 to 0.28.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/evanw/esbuild/releases\"\u003eesbuild's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.28.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix tree shaking bug due to TypeScript import alias (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4507\"\u003e#4507\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific \u003ccode\u003eimport\u003c/code\u003e assignment and looks something like this:\u003c/p\u003e\n\u003cpre lang=\"ts\"\u003e\u003ccode\u003eimport Base from './dep.js';\r\nimport Alias = Base.SomeType;\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix CSS minification bug involving \u003ccode\u003e\u0026amp;\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4497\"\u003e#4497\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug where esbuild's CSS minifier incorrectly removed a \u003ccode\u003e\u0026amp;\u003c/code\u003e when it was unsafe to do so. Here is an example:\u003c/p\u003e\n\u003cpre lang=\"css\"\u003e\u003ccode\u003e/* Original code */\r\n.a .b {\r\n  \u0026amp; .b:not(\u0026amp; .c) {\r\n    color: red;\r\n  }\r\n}\r\n\u003cp\u003e/* Old output (with --minify) */\u003cbr /\u003e\n.a .b{.b:not(\u0026amp; .c){color:red}}\u003c/p\u003e\n\u003cp\u003e/* New output (with --minify) */\u003cbr /\u003e\n.a .b{\u0026amp; .b:not(\u0026amp; .c){color:red}}\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eThis should match \u003ccode\u003e\u0026lt;span class=\u0026quot;a\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;yes\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u003c/code\u003e but not \u003ccode\u003e\u0026lt;span class=\u0026quot;a\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;no\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u003c/code\u003e. The old output incorrectly matched both.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAvoid overwriting input files without \u003ccode\u003e--allow-overwrite\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4484\"\u003e#4484\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eFor example: \u003ccode\u003eesbuild input.js --outfile=input.js\u003c/code\u003e tells esbuild to overwrite \u003ccode\u003einput.js\u003c/code\u003e with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.\u003c/p\u003e\n\u003cp\u003eThis release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless \u003ccode\u003e--allow-overwrite\u003c/code\u003e is explicitly present. This is done by not writing out any files when a build error is encountered.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix incorrect code generated when using top-level await (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4498\"\u003e#4498\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003ePreviously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing \u003ccode\u003easync\u003c/code\u003e on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an \u003ccode\u003easync\u003c/code\u003e module wrapper.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix a minification bug with lowered logical assignment operators (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4508\"\u003e#4508\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Original code\r\nfunction foo() {\r\n  let x\r\n  bar(x ||= {})\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/evanw/esbuild/blob/main/CHANGELOG-2025.md\"\u003eesbuild's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog: 2025\u003c/h1\u003e\n\u003cp\u003eThis changelog documents all esbuild versions published in the year 2025 (versions 0.25.0 through 0.27.2).\u003c/p\u003e\n\u003ch2\u003e0.27.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eAllow import path specifiers starting with \u003ccode\u003e#/\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/evanw/esbuild/pull/4361\"\u003e#4361\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003ePreviously the specification for \u003ccode\u003epackage.json\u003c/code\u003e disallowed import path specifiers starting with \u003ccode\u003e#/\u003c/code\u003e, but this restriction \u003ca href=\"https://redirect.github.com/nodejs/node/pull/60864\"\u003ehas recently been relaxed\u003c/a\u003e and support for it is being added across the JavaScript ecosystem. One use case is using it for a wildcard pattern such as mapping \u003ccode\u003e#/*\u003c/code\u003e to \u003ccode\u003e./src/*\u003c/code\u003e (previously you had to use another character such as \u003ccode\u003e#_*\u003c/code\u003e instead, which was more confusing). There is some more context in \u003ca href=\"https://redirect.github.com/nodejs/node/issues/49182\"\u003enodejs/node#49182\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eThis change was contributed by \u003ca href=\"https://github.com/hybrist\"\u003e\u003ccode\u003e@​hybrist\u003c/code\u003e\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAutomatically add the \u003ccode\u003e-webkit-mask\u003c/code\u003e prefix (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4357\"\u003e#4357\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4358\"\u003e#4358\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release automatically adds the \u003ccode\u003e-webkit-\u003c/code\u003e vendor prefix for the \u003ca href=\"https://developer.mozilla.org/en-US/docs/Web/CSS/Reference/Properties/mask\"\u003e\u003ccode\u003emask\u003c/code\u003e\u003c/a\u003e CSS shorthand property:\u003c/p\u003e\n\u003cpre lang=\"css\"\u003e\u003ccode\u003e/* Original code */\nmain {\n  mask: url(x.png) center/5rem no-repeat\n}\n\u003cp\u003e/* Old output (with --target=chrome110) */\u003cbr /\u003e\nmain {\u003cbr /\u003e\nmask: url(x.png) center/5rem no-repeat;\u003cbr /\u003e\n}\u003c/p\u003e\n\u003cp\u003e/* New output (with --target=chrome110) */\u003cbr /\u003e\nmain {\u003cbr /\u003e\n-webkit-mask: url(x.png) center/5rem no-repeat;\u003cbr /\u003e\nmask: url(x.png) center/5rem no-repeat;\u003cbr /\u003e\n}\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eThis change was contributed by \u003ca href=\"https://github.com/BPJEnnova\"\u003e\u003ccode\u003e@​BPJEnnova\u003c/code\u003e\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdditional minification of \u003ccode\u003eswitch\u003c/code\u003e statements (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4176\"\u003e#4176\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4359\"\u003e#4359\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release contains additional minification patterns for reducing \u003ccode\u003eswitch\u003c/code\u003e statements. Here is an example:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Original code\nswitch (x) {\n  case 0:\n    foo()\n    break\n  case 1:\n  default:\n    bar()\n}\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/609683d892977362a0f99026cb74b96263d728a9\"\u003e\u003ccode\u003e609683d\u003c/code\u003e\u003c/a\u003e publish 0.28.2 to npm\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/11b1fe48df6859393d9469f323b5ebd17baaf989\"\u003e\u003ccode\u003e11b1fe4\u003c/code\u003e\u003c/a\u003e add to release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/ab50d91559a27e54cd0a27a403389130ea10d97d\"\u003e\u003ccode\u003eab50d91\u003c/code\u003e\u003c/a\u003e css: fix green/blue channel swap in oklch gamut mapping (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4488\"\u003e#4488\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/04627b6cf99b4a7491bebb0268173a7c77a85030\"\u003e\u003ccode\u003e04627b6\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4498\"\u003e#4498\u003c/a\u003e: \u003ccode\u003easync\u003c/code\u003e TLA checks need a worklist\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/5c15177a308c7224604058a769c4abf0a66b0a36\"\u003e\u003ccode\u003e5c15177\u003c/code\u003e\u003c/a\u003e disable \u003ccode\u003egopls\u003c/code\u003e in the \u003ccode\u003ego\u003c/code\u003e folder\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/fc2ee9babc5a2e8ea7ec7c10dd5850b71f7cec7e\"\u003e\u003ccode\u003efc2ee9b\u003c/code\u003e\u003c/a\u003e css: adjust parser to allow \u003ccode\u003e--foo: {...}\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/209db54371e62ad1c50e12e56bb93c74c53b0408\"\u003e\u003ccode\u003e209db54\u003c/code\u003e\u003c/a\u003e release notes for css nesting bugfix\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/c625d31bf08a0647ec724bf76c7115f7aec55971\"\u003e\u003ccode\u003ec625d31\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4497\"\u003e#4497\u003c/a\u003e: preserve nested ampersands during minification (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4500\"\u003e#4500\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/34474e278528a60f58c959c0f422d2bfa6f6886d\"\u003e\u003ccode\u003e34474e2\u003c/code\u003e\u003c/a\u003e better isolation of current part in js parser\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/07f6e8c50677e0b41e5ed726c08b0ea200b14e5b\"\u003e\u003ccode\u003e07f6e8c\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4507\"\u003e#4507\u003c/a\u003e: \u003ccode\u003eimport\u003c/code\u003e assignment tree-shaking bug\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/evanw/esbuild/compare/v0.25.12...v0.28.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for esbuild since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `vite` from 6.4.2 to 7.3.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/releases\"\u003evite's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.3.6\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.6/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.3.5\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.5/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.3.3\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.3/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.3.2\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.2/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.3.1\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.1/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.3.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.0/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.2.7\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.2.7/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.2.6\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.2.6/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.2.5\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.2.5/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eNote: 7.2.5 failed to publish so it is skipped on npm\u003c/em\u003e\u003c/p\u003e\n\u003ch2\u003ev7.2.4\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.2.4/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.2.3\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.2.3/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.2.2\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.2.2/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.2.1\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.2.1/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.2.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.2.0/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.2.0-beta.1\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.2.0-beta.1/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.2.0-beta.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.2.0-beta.0/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.6/packages/vite/CHANGELOG.md\"\u003evite's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.5...v7.3.6\"\u003e7.3.6\u003c/a\u003e (2026-06-25)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eallow esbuild 0.28 (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22743\"\u003e#22743\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/a24931e7934e80eff5895b89d9e612ad3ad3e1f4\"\u003ea24931e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.3...v7.3.5\"\u003e7.3.5\u003c/a\u003e (2026-06-01)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ebackport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22572\"\u003e#22572\u003c/a\u003e, reject windows alternate paths (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22574\"\u003e#22574\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8c1855607b7c9884c4565d897ee98899a008a2d0\"\u003e8c18556\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e backport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22571\"\u003e#22571\u003c/a\u003e, reject UNC paths for launch-editor-middleware (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22573\"\u003e#22573\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/f20d64bef6e0ef1e4fa7a9783281c7bba0ce5292\"\u003ef20d64b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMiscellaneous Chores\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eskip v7.3.4 release (\u003ca href=\"https://github.com/vitejs/vite/commit/8a6a0c9fc734dbfe293ac33a4954506ee50430e1\"\u003e8a6a0c9\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.3...v7.3.4\"\u003e7.3.4\u003c/a\u003e (2026-06-01)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ebackport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22572\"\u003e#22572\u003c/a\u003e, reject windows alternate paths (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22574\"\u003e#22574\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8c1855607b7c9884c4565d897ee98899a008a2d0\"\u003e8c18556\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e backport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22571\"\u003e#22571\u003c/a\u003e, reject UNC paths for launch-editor-middleware (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22573\"\u003e#22573\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/f20d64bef6e0ef1e4fa7a9783281c7bba0ce5292\"\u003ef20d64b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.2...v7.3.3\"\u003e7.3.3\u003c/a\u003e (2026-05-07)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eavoid destructure lowering for newer safari (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22346\"\u003e#22346\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/5ab51c0f76f0896175e02ad797c1f5fe116d02f4\"\u003e5ab51c0\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.1...v7.3.2\"\u003e7.3.2\u003c/a\u003e (2026-04-06)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eavoid...\n\n_Description has been truncated_","html_url":"https://github.com/milliorn/portfolio/pull/310","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/milliorn%2Fportfolio/issues/310","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/310/packages"}},{"old_version":"3.1.4","new_version":"3.1.7","update_type":"patch","path":null,"pr_created_at":"2026-09-13T07:42:39.000Z","version_change":"3.1.4 → 3.1.7","issue":{"uuid":"5438857810","node_id":"PR_kwDOSmyDHM8AAAABDUdj-Q","number":12,"state":"open","title":"build(deps): bump the npm_and_yarn group across 1 directory with 9 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-13T07:42:39.000Z","updated_at":"2026-09-13T07:43:01.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"npm_and_yarn","update_count":9,"packages":[{"name":"next","old_version":"16.2.9","new_version":"16.3.5","repository_url":"https://github.com/vercel/next.js"},{"name":"baseline-browser-mapping","old_version":"2.10.32","new_version":"2.11.23","repository_url":"https://github.com/web-platform-dx/baseline-browser-mapping"},{"name":"browserslist","old_version":"4.28.2","new_version":"4.28.9","repository_url":"https://github.com/browserslist/browserslist"},{"name":"fast-uri","old_version":"3.1.4","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"find-my-way","old_version":"9.6.0","new_version":"9.7.0","repository_url":"https://github.com/delvedor/find-my-way"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 5 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [next](https://github.com/vercel/next.js) | `16.2.9` | `16.3.5` |\n| [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) | `2.10.32` | `2.11.23` |\n| [browserslist](https://github.com/browserslist/browserslist) | `4.28.2` | `4.28.9` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.4` | `3.1.7` |\n| [find-my-way](https://github.com/delvedor/find-my-way) | `9.6.0` | `9.7.0` |\n\n\nUpdates `next` from 16.2.9 to 16.3.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003enext's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.5\u003c/h2\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does not include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003enext/image: Skip 0-byte entries when initializing disk LRU cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98185\"\u003e#98185\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enext/image: Reject empty images when reading/writing to the disk cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98186\"\u003e#98186\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEmit whole-app server NFTs when \u003ccode\u003eoutput: 'standalone'\u003c/code\u003e is used with an adapter (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98167\"\u003e#98167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd CSP nonce to script tags of loading and template files (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98403\"\u003e#98403\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003euse cache\u003c/code\u003e prerender signal retention (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98448\"\u003e#98448\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.4\u003c/h2\u003e\n\u003cp\u003eFollow-up release to \u003ca href=\"https://github.com/vercel/next.js/releases/tag/v16.3.3\"\u003ev16.3.3\u003c/a\u003e re-enabling AVIF Image Optimization (\u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97949\"\u003e#97949\u003c/a\u003e).\u003c/p\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003etestmode: Fix infinite recursion in testmode passthrough fetch (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97691\"\u003e#97691\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix build error when aliasing typescript to \u003ccode\u003e@​typescript/typescript6\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97997\"\u003e#97997\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix unset crossOrigin in Turbopack manifests (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97930\"\u003e#97930\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.3\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eCritical:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36\"\u003eUnauthenticated Remote Code Execution on windows-hosted servers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4\"\u003eUnauthenticated Remote Code Execution in Image Optimization API when AVIF files are used\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.2\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Scope app-entry export validation to files inside the app directory (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97357\"\u003e#97357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[backport] Fix catch-all index page being served for every other slug (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97416\"\u003e#97416\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: don't trace embedded WASM loader helpers (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97353\"\u003e#97353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97463\"\u003e#97463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: retain conditions when replacing resolve request keys (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97453\"\u003e#97453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Fix Turbopack worker chunk loading with asset prefix (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97419\"\u003e#97419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97603\"\u003e#97603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/lubieowoce\"\u003e\u003ccode\u003e@​lubieowoce\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[16.x] Turbopack: don't strip async-module runtime from shared runtime chunks by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96653\"\u003evercel/next.js#96653\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/ca2c75eb7f8d9dd012a8bb83c06132149fe221f9\"\u003e\u003ccode\u003eca2c75e\u003c/code\u003e\u003c/a\u003e v16.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/14fb290de65077e9f1e22ef56d8de6cc1e63d436\"\u003e\u003ccode\u003e14fb290\u003c/code\u003e\u003c/a\u003e [backport] Fix use cache prerender signal retention (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98448\"\u003e#98448\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/2b1f28dbe1de344807ec0946a85171bc890a6047\"\u003e\u003ccode\u003e2b1f28d\u003c/code\u003e\u003c/a\u003e [16.3.x] Add CSP nonce to script tags of loading and template files (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98403\"\u003e#98403\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/4b56cee3f01d3b249edcd798b51895d5126a4170\"\u003e\u003ccode\u003e4b56cee\u003c/code\u003e\u003c/a\u003e [16.3.x] Backport docs fixes (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98317\"\u003e#98317\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/5568a02a7d47f9cb088e58350f2c2e68d9e93a00\"\u003e\u003ccode\u003e5568a02\u003c/code\u003e\u003c/a\u003e [backport] docs: local development: Rewrite docker section, add Windows Dev D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/93249ab2144132abfd4a8d611dad5b5978107ee2\"\u003e\u003ccode\u003e93249ab\u003c/code\u003e\u003c/a\u003e [16.3.X] Emit whole-app server NFTs when \u003ccode\u003eoutput: 'standalone'\u003c/code\u003e is used with ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/6549fd7c4e15a8883b0ad1c2ef67dec287a44f12\"\u003e\u003ccode\u003e6549fd7\u003c/code\u003e\u003c/a\u003e [16.3.x] next/image: reject empty image on read/write to disk cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98186\"\u003e#98186\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/d9eac96e7526ff0b9cb51db9801f06e741fe1960\"\u003e\u003ccode\u003ed9eac96\u003c/code\u003e\u003c/a\u003e [16.3.x] next/image: skip 0-byte entries when initializing disk LRU cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/9\"\u003e#9\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/84b35feccb2b53a563e41ad2dfe7a5fe08c58d3f\"\u003e\u003ccode\u003e84b35fe\u003c/code\u003e\u003c/a\u003e [test] Fix 16.3 deploy test assertions (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98133\"\u003e#98133\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/14f9c1ac4e084a44633c354476ddeaf70969cd90\"\u003e\u003ccode\u003e14f9c1a\u003c/code\u003e\u003c/a\u003e [16.3.x][ci] Run flake detection and new deploy tests when merged and on back...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/compare/v16.2.9...v16.3.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.16 to 8.5.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8\"\u003e\u003ccode\u003e7beca13\u003c/code\u003e\u003c/a\u003e Does no load source map file without opts.from\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/decea51421682341401575b3740709fda0e12930\"\u003e\u003ccode\u003edecea51\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/c18e30d126395d42a0726aa00e03a8f1088985ae\"\u003e\u003ccode\u003ec18e30d\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/98a39ad73d163a90be924d5126c771262110f1fc\"\u003e\u003ccode\u003e98a39ad\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/a3e48c492ddec0e4879d513b8b995fee887af352\"\u003e\u003ccode\u003ea3e48c4\u003c/code\u003e\u003c/a\u003e Release 8.5.22 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f49d6911795f53b2cfe023bb686bf1144ec30618\"\u003e\u003ccode\u003ef49d691\u003c/code\u003e\u003c/a\u003e Fix custom property losing its semicolon before a comment (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2117\"\u003e#2117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/28e0daf8f2fe5ba9e19ea3f8c27c8fe176f9419e\"\u003e\u003ccode\u003e28e0daf\u003c/code\u003e\u003c/a\u003e Release 8.5.21 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3d2b4e43e38274f233b5609d09687cadad8215d9\"\u003e\u003ccode\u003e3d2b4e4\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.16...8.5.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `baseline-browser-mapping` from 2.10.32 to 2.11.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/releases\"\u003ebaseline-browser-mapping's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.11.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed in 2.11.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: Adds a new \u003ccode\u003egetTimeline()\u003c/code\u003e method for getting the series of minimum browser changes, either grouped by date or by browser.\u003c/li\u003e\n\u003cli\u003erefactor: Substantial refactoring of the data compression process that replaces the full list of browsers from \u003ccode\u003e@mdn/browser-compat-data\u003c/code\u003e and \u003ccode\u003edownstream-browsers.json\u003c/code\u003e and features from \u003ccode\u003eweb-features\u003c/code\u003e (in their very pared down form) with a change-list timeline that reflects which versions supported Baseline (newly available) on a given date.  Thanks to \u003ca href=\"https://github.com/swwind\"\u003e\u003ccode\u003e@​swwind\u003c/code\u003e\u003c/a\u003e for the idea!\u003c/li\u003e\n\u003cli\u003erefactor: Some common functions have been moved to a \u003ccode\u003eutil.ts\u003c/code\u003e module for use in other scripts.\u003c/li\u003e\n\u003cli\u003efix: Removes \u003ccode\u003eprocess.exit()\u003c/code\u003e calls when unsupported option combinations are passed to getCompatibleVersions() and \u003ccode\u003egetAllVersions()\u003c/code\u003e in favour of throwing an \u003ccode\u003eError\u003c/code\u003e.  There is a small security risk with \u003ccode\u003eprocess.exit()\u003c/code\u003e calls that sites accepting unsanitised inputs could be the subject of attacks.  Unsupported config options now throw and Error which should allow for more graceful handling.  Thanks to \u003ca href=\"https://github.com/bnbdr\"\u003e\u003ccode\u003e@​bnbdr\u003c/code\u003e\u003c/a\u003e for flagging this as vulnerability CVE-2026-45819 .\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFixes \u003ca href=\"https://redirect.github.com/web-platform-dx/baseline-browser-mapping/issues/134\"\u003e#134\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.10.44...v2.11.0\"\u003ehttps://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.10.44...v2.11.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/ebdc72f5637922808cfe1fbf9e67897ba9f89677\"\u003e\u003ccode\u003eebdc72f\u003c/code\u003e\u003c/a\u003e Patch to 2.11.23 because browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/55fa3a1503097faad7a9806d6c08029a36cb19e3\"\u003e\u003ccode\u003e55fa3a1\u003c/code\u003e\u003c/a\u003e Browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/5ac60db1f4eedbd9b61dfa6db0cab10cccc19c2a\"\u003e\u003ccode\u003e5ac60db\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/af7c3c4ebc2692844e521fada6c8d49250795f10\"\u003e\u003ccode\u003eaf7c3c4\u003c/code\u003e\u003c/a\u003e Patch to 2.11.22 because browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/7e10cadb03c00cb5eab538d62b6d16511cd93841\"\u003e\u003ccode\u003e7e10cad\u003c/code\u003e\u003c/a\u003e Browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/ebb97027ff15d916e66b02feb9e019d8c7bab081\"\u003e\u003ccode\u003eebb9702\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/ecc57a365d502e0c85574e45751c1b7475689936\"\u003e\u003ccode\u003eecc57a3\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/0e5ed80e21dda23cac3dc1f6ec37e6b5fc4ea734\"\u003e\u003ccode\u003e0e5ed80\u003c/code\u003e\u003c/a\u003e Patch to 2.11.21 because browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/11da0b699d6d03a1e30b37a8fe7a4f8d96e06f4d\"\u003e\u003ccode\u003e11da0b6\u003c/code\u003e\u003c/a\u003e Browser or feature data changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/commit/69fcc81987ecc7dbbf4d21e17be8c4adf642aa2b\"\u003e\u003ccode\u003e69fcc81\u003c/code\u003e\u003c/a\u003e Updating static site\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.10.32...v2.11.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `browserslist` from 4.28.2 to 4.28.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/releases\"\u003ebrowserslist's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eincluding kaios\u003c/code\u003e in baseline queries (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved parsing performance.\u003c/li\u003e\n\u003cli\u003eFixed unbounded memory growth (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed prototype write issue (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Electron version queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003e\u0026gt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;=\u003c/code\u003e queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eSyntaxError\u003c/code\u003e regression of 4.28.3.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed baseline query case-insensitivity (by \u003ca href=\"https://github.com/swwind\"\u003e\u003ccode\u003e@​swwind\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md\"\u003ebrowserslist's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eincluding kaios\u003c/code\u003e in baseline queries (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved parsing performance.\u003c/li\u003e\n\u003cli\u003eFixed unbounded memory growth (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed prototype write issue (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Electron version queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003e\u0026gt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;=\u003c/code\u003e queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eSyntaxError\u003c/code\u003e regression of 4.28.3.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed baseline query case-insensitivity (by \u003ca href=\"https://github.com/swwind\"\u003e\u003ccode\u003e@​swwind\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/12ed5252dabc14fee4e97b465894b2f90910ca62\"\u003e\u003ccode\u003e12ed525\u003c/code\u003e\u003c/a\u003e Release 4.28.9 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/b1d8cf9d7a7dc76f6585425a8360218289194297\"\u003e\u003ccode\u003eb1d8cf9\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/21517b651c915cdbbfb8c122268bc36f5cabb7ef\"\u003e\u003ccode\u003e21517b6\u003c/code\u003e\u003c/a\u003e Improve \u003ccode\u003eor\u003c/code\u003e parsing performance\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/f2f2e6cfb01bb4942941d328737546f4e2ae41ad\"\u003e\u003ccode\u003ef2f2e6c\u003c/code\u003e\u003c/a\u003e Release 4.28.8 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/d0787c88fa29ba895fea51cfe921232c7b5d1377\"\u003e\u003ccode\u003ed0787c8\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/fcf8fa9857b30ccdf801a548f5d09d3c4ff0d43f\"\u003e\u003ccode\u003efcf8fa9\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/browserslist/browserslist/issues/939\"\u003e#939\u003c/a\u003e from Jaybhade/fix/baseline-kaios-without-downstream\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/57ecd64454e9252afdd6a7e76926e13dda48a38c\"\u003e\u003ccode\u003e57ecd64\u003c/code\u003e\u003c/a\u003e fix: support \u0026quot;including kaios\u0026quot; without downstream\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/093a0f67bb0becda55235d767b134df3197c54a1\"\u003e\u003ccode\u003e093a0f6\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/b637868045806d2fba4c24eb0060e4cc8b1db276\"\u003e\u003ccode\u003eb637868\u003c/code\u003e\u003c/a\u003e Release 4.28.7 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/313f4659b9f985ade89d1d6a54a860371c41cc46\"\u003e\u003ccode\u003e313f465\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/browserslist/browserslist/compare/4.28.2...4.28.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for browserslist since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-uri` from 3.1.4 to 3.1.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `find-my-way` from 9.6.0 to 9.7.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/delvedor/find-my-way/releases\"\u003efind-my-way's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev9.7.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: backtrack on regex param mismatch by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/427\"\u003edelvedor/find-my-way#427\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: apply root path fallback for optional params in off() by \u003ca href=\"https://github.com/aquie00t\"\u003e\u003ccode\u003e@​aquie00t\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/428\"\u003edelvedor/find-my-way#428\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: add node v26 to test matrix by \u003ca href=\"https://github.com/aquie00t\"\u003e\u003ccode\u003e@​aquie00t\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/435\"\u003edelvedor/find-my-way#435\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf(host): cache regex lookup results in HostStorage by \u003ca href=\"https://github.com/aquie00t\"\u003e\u003ccode\u003e@​aquie00t\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/436\"\u003edelvedor/find-my-way#436\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump inquirer from 13.4.3 to 14.0.2 in the dev-dependencies group by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/437\"\u003edelvedor/find-my-way#437\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump fastify/github-action-merge-dependabot from 3.12.0 to 3.15.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/438\"\u003edelvedor/find-my-way#438\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump \u003ccode\u003e@​types/node\u003c/code\u003e from 25.9.4 to 26.1.0 in the dev-dependencies group by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/440\"\u003edelvedor/find-my-way#440\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: prevent done from being called multiple times on async constraint errors by \u003ca href=\"https://github.com/deepview-autofix\"\u003e\u003ccode\u003e@​deepview-autofix\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/425\"\u003edelvedor/find-my-way#425\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: align isParamSafe state in findRoute with _on by \u003ca href=\"https://github.com/deepview-autofix\"\u003e\u003ccode\u003e@​deepview-autofix\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/424\"\u003edelvedor/find-my-way#424\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump actions/checkout from 6 to 7 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/439\"\u003edelvedor/find-my-way#439\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid crash on undefined regex capture during route lookup by \u003ca href=\"https://github.com/bianyifan\"\u003e\u003ccode\u003e@​bianyifan\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/441\"\u003edelvedor/find-my-way#441\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aquie00t\"\u003e\u003ccode\u003e@​aquie00t\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/428\"\u003edelvedor/find-my-way#428\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/deepview-autofix\"\u003e\u003ccode\u003e@​deepview-autofix\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/425\"\u003edelvedor/find-my-way#425\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bianyifan\"\u003e\u003ccode\u003e@​bianyifan\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/delvedor/find-my-way/pull/441\"\u003edelvedor/find-my-way#441\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/delvedor/find-my-way/compare/v9.6.0...v9.7.0\"\u003ehttps://github.com/delvedor/find-my-way/compare/v9.6.0...v9.7.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/delvedor/find-my-way/commit/827248e64fe17e44cbd9690e4eb0121e51256385\"\u003e\u003ccode\u003e827248e\u003c/code\u003e\u003c/a\u003e Bumped v9.7.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/delvedor/find-my-way/commit/b9d7bf17cd1dbc01590010ef66f66f14ee76cbb2\"\u003e\u003ccode\u003eb9d7bf1\u003c/code\u003e\u003c/a\u003e Merge branch 'main' of github.com:delvedor/find-my-way\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/delvedor/find-my-way/commit/b7b5657bd44517a20204c2c6432e0c19528412b3\"\u003e\u003ccode\u003eb7b5657\u003c/code\u003e\u003c/a\u003e fix: avoid crash on undefined regex capture during route lookup (\u003ca href=\"https://redirect.github.com/delvedor/find-my-way/issues/441\"\u003e#441\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/delvedor/find-my-way/commit/4263d82315bc09d1e6f3b2d3fa3e2be28a6efebf\"\u003e\u003ccode\u003e4263d82\u003c/code\u003e\u003c/a\u003e chore: bump actions/checkout from 6 to 7 (\u003ca href=\"https://redirect.github.com/delvedor/find-my-way/issues/439\"\u003e#439\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/delvedor/find-my-way/commit/66d30150c6eeebf9499fa9d0cd7b0425a4f91c10\"\u003e\u003ccode\u003e66d3015\u003c/code\u003e\u003c/a\u003e fix: align isParamSafe state in findRoute with _on (\u003ca href=\"https://redirect.github.com/delvedor/find-my-way/issues/424\"\u003e#424\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/delvedor/find-my-way/commit/75e47287c19247d172291e4713220310dfcf4877\"\u003e\u003ccode\u003e75e4728\u003c/code\u003e\u003c/a\u003e fix: prevent done from being called multiple times on async constraint errors...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/delvedor/find-my-way/commit/902a02dd09613e0ed08bbc9d911d3e1123470fc2\"\u003e\u003ccode\u003e902a02d\u003c/code\u003e\u003c/a\u003e chore: bump \u003ccode\u003e@​types/node\u003c/code\u003e in the dev-dependencies group (\u003ca href=\"https://redirect.github.com/delvedor/find-my-way/issues/440\"\u003e#440\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/delvedor/find-my-way/commit/b803e4ee59092d31d6e06c714552da9c086400f0\"\u003e\u003ccode\u003eb803e4e\u003c/code\u003e\u003c/a\u003e chore: bump fastify/github-action-merge-dependabot from 3.12.0 to 3.15.0 (\u003ca href=\"https://redirect.github.com/delvedor/find-my-way/issues/438\"\u003e#438\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/delvedor/find-my-way/commit/e63cb77c4f318780557305d757f90a5ebe1914dd\"\u003e\u003ccode\u003ee63cb77\u003c/code\u003e\u003c/a\u003e chore: bump inquirer from 13.4.3 to 14.0.2 in the dev-dependencies group (\u003ca href=\"https://redirect.github.com/delvedor/find-my-way/issues/437\"\u003e#437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/delvedor/find-my-way/commit/992c1df719f06292048cf6764f91deeaead30214\"\u003e\u003ccode\u003e992c1df\u003c/code\u003e\u003c/a\u003e perf(host): cache regex lookup results in HostStorage (\u003ca href=\"https://redirect.github.com/delvedor/find-my-way/issues/436\"\u003e#436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/delvedor/find-my-way/compare/v9.6.0...v9.7.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nanoid` from 3.3.12 to 3.3.19\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/releases\"\u003enanoid's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/blob/main/CHANGELOG.md\"\u003enanoid's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID (by \u003ca href=\"https://github.com/geoffrey-diederichs\"\u003e\u003ccode\u003e@​geoffrey-diederichs\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/eb63bd6775188dc35d143bf24868be094f19b5ee\"\u003e\u003ccode\u003eeb63bd6\u003c/code\u003e\u003c/a\u003e Release 3.3.19 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9067e0361a643ab2c94ddd67606efbf275f6c0dd\"\u003e\u003ccode\u003e9067e03\u003c/code\u003e\u003c/a\u003e Sync CJS and ESM\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9ad98052b316c5e707f8098ace509d2ae165e54d\"\u003e\u003ccode\u003e9ad9805\u003c/code\u003e\u003c/a\u003e Release 3.3.18 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/55e50a0621ec084b4bb4000ea4e86e1191bd3da8\"\u003e\u003ccode\u003e55e50a0\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e10f8d40ce9d1ab47f66d65a16b48086432730d0\"\u003e\u003ccode\u003ee10f8d4\u003c/code\u003e\u003c/a\u003e Update index.native.js (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/606\"\u003e#606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/73d67168136b36fd3b644159b0cff149da4905d9\"\u003e\u003ccode\u003e73d6716\u003c/code\u003e\u003c/a\u003e Release 3.3.17 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/f9d13f150847d117877adee3460a46eceb0cf49b\"\u003e\u003ccode\u003ef9d13f1\u003c/code\u003e\u003c/a\u003e Sync 0 size behaviour with PostCSS 5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9760e112757cf7d46a79abd7a133bc4958757bb8\"\u003e\u003ccode\u003e9760e11\u003c/code\u003e\u003c/a\u003e Release 3.3.16 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66d\"\u003e\u003ccode\u003ee835c9b\u003c/code\u003e\u003c/a\u003e fix(non-secure): clamp negative size to prevent infinite loop (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/601\"\u003e#601\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/96dd086eb24396a275fa93ee78d73b2fece35809\"\u003e\u003ccode\u003e96dd086\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ai/nanoid/compare/3.3.12...3.3.19\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for nanoid since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `sharp` from 0.34.5 to 0.35.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lovell/sharp/releases\"\u003esharp's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.35.4\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\"\u003ehttps://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.35.4-rc.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpgrade to libvips v8.18.6 for upstream bug fixes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7f1a0a22cc285fe180766f4935d50b55af6e8432\"\u003e\u003ccode\u003e7f1a0a2\u003c/code\u003e\u003c/a\u003e Release v0.35.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/f927818924bc5a9493d822a4e8b23ec5857c52e1\"\u003e\u003ccode\u003ef927818\u003c/code\u003e\u003c/a\u003e Upgrade to sharp-libvips v1.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e80209240d005c71e1173a50dd9cd4db4ce2a9e6\"\u003e\u003ccode\u003ee802092\u003c/code\u003e\u003c/a\u003e Prerelease v0.35.4-rc.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e13eb2f97a0a22f1ef726e8d0cd33f7c56835945\"\u003e\u003ccode\u003ee13eb2f\u003c/code\u003e\u003c/a\u003e CI: Fix wasm32 build (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4589\"\u003e#4589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/a82a0b3d58bc25854ad1e925e6eb0a50725d1489\"\u003e\u003ccode\u003ea82a0b3\u003c/code\u003e\u003c/a\u003e Upgrade to libvips v8.18.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/8044fe43e36d0ea7f8beb89f79a37bb0f3342e84\"\u003e\u003ccode\u003e8044fe4\u003c/code\u003e\u003c/a\u003e Bound resize dimensions to coordinate limit\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/147f8591a153bc4a1e199c3fe3150fac2931b30c\"\u003e\u003ccode\u003e147f859\u003c/code\u003e\u003c/a\u003e Docs: changelog entries for \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4578\"\u003e#4578\u003c/a\u003e \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ee5bfb853de75a611c64381783b04032a3a897d8\"\u003e\u003ccode\u003eee5bfb8\u003c/code\u003e\u003c/a\u003e Tests: use yauzl directly rather than via extract-zip wrapper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7a7788928f8a2a429f45039010a87cee35401694\"\u003e\u003ccode\u003e7a77889\u003c/code\u003e\u003c/a\u003e Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4588\"\u003e#4588\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ea5bef24c187b2c7ee3fe3cad3b45c8cb67a46fd\"\u003e\u003ccode\u003eea5bef2\u003c/code\u003e\u003c/a\u003e Improve support for input Streams finishing before output is requested (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/lovell/sharp/compare/v0.34.5...v0.35.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `valibot` from 1.2.0 to 1.4.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-circle/valibot/releases\"\u003evalibot's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.4.2\u003c/h2\u003e\n\u003cp\u003eMany thanks to \u003ca href=\"https://github.com/Faze-up\"\u003e\u003ccode\u003e@​Faze-up\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e for contributing to this release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix word count actions to cache the \u003ccode\u003eIntl.Segmenter\u003c/code\u003e for non-primitive locales, preventing it from being recreated on every \u003ccode\u003ewords\u003c/code\u003e, \u003ccode\u003eminWords\u003c/code\u003e, \u003ccode\u003emaxWords\u003c/code\u003e and \u003ccode\u003enotWords\u003c/code\u003e validation (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1521\"\u003e#1521\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eflatten\u003c/code\u003e method to handle issue path keys that collide with \u003ccode\u003eObject.prototype\u003c/code\u003e members like \u003ccode\u003etoString\u003c/code\u003e instead of throwing a \u003ccode\u003eTypeError\u003c/code\u003e (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1522\"\u003e#1522\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eintersect\u003c/code\u003e schema to merge object keys that collide with \u003ccode\u003eObject.prototype\u003c/code\u003e members like \u003ccode\u003etoString\u003c/code\u003e instead of failing to merge them (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1522\"\u003e#1522\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.4.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eintersect\u003c/code\u003e schema to infer correct input and output types for non-tuple array options instead of \u003ccode\u003enever\u003c/code\u003e (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1478\"\u003e#1478\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.4.0\u003c/h2\u003e\n\u003cp\u003eMany thanks to \u003ca href=\"https://github.com/ksaurav24\"\u003e\u003ccode\u003e@​ksaurav24\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/heiwen\"\u003e\u003ccode\u003e@​heiwen\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/compulim\"\u003e\u003ccode\u003e@​compulim\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/ysknsid25\"\u003e\u003ccode\u003e@​ysknsid25\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/alaycock-stripe\"\u003e\u003ccode\u003e@​alaycock-stripe\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/IlyaSemenov\"\u003e\u003ccode\u003e@​IlyaSemenov\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/wszgrcy\"\u003e\u003ccode\u003e@​wszgrcy\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/LMGO\"\u003e\u003ccode\u003e@​LMGO\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/yslpn\"\u003e\u003ccode\u003e@​yslpn\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/EltonLobo07\"\u003e\u003ccode\u003e@​EltonLobo07\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/Eronmmer\"\u003e\u003ccode\u003e@​Eronmmer\u003c/code\u003e\u003c/a\u003e for contributing to this release.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eRead the \u003ca href=\"https://valibot.dev/blog/valibot-v1.4-release-notes/\"\u003erelease notes\u003c/a\u003e on our website for a quick overview of the most exciting new features in this release.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003eisoDateTimeSecond\u003c/code\u003e validation action to validate ISO date times with seconds (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1418\"\u003e#1418\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003etoCamelCase\u003c/code\u003e, \u003ccode\u003etoKebabCase\u003c/code\u003e, \u003ccode\u003etoPascalCase\u003c/code\u003e and \u003ccode\u003etoSnakeCase\u003c/code\u003e transformation actions to convert strings between common naming conventions (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1457\"\u003e#1457\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChange internal \u003ccode\u003eReadonlyOutputKeys\u003c/code\u003e and \u003ccode\u003eOutputWithReadonly\u003c/code\u003e types of \u003ccode\u003eobject\u003c/code\u003e schemas and \u003ccode\u003eWithReadonly\u003c/code\u003e type of \u003ccode\u003erecord\u003c/code\u003e schemas to improve TypeScript type performance (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1442\"\u003e#1442\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChange hot paths to reduce object allocations and improve runtime performance (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1437\"\u003e#1437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChange build target to ES2020 so distributed output stays compatible with environments that lack support for newer syntax (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1455\"\u003e#1455\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChange internal \u003ccode\u003e_LruCache\u003c/code\u003e to use a TypeScript \u003ccode\u003eprivate\u003c/code\u003e method instead of a \u003ccode\u003e#private\u003c/code\u003e class field to avoid runtime helpers in the transpiled output (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1455\"\u003e#1455\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChange internal \u003ccode\u003e_isValidObjectKey\u003c/code\u003e to use \u003ccode\u003eObject.prototype.hasOwnProperty.call\u003c/code\u003e instead of \u003ccode\u003eObject.hasOwn\u003c/code\u003e so the distributed output stays compatible with runtimes that lack the ES2022 \u003ccode\u003eObject.hasOwn\u003c/code\u003e builtin (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1421\"\u003e#1421\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChange \u003ccode\u003eflatten\u003c/code\u003e method to accept readonly issue arrays (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1269\"\u003e#1269\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix potential \u003ccode\u003eRangeError\u003c/code\u003e caused by spreading large issue arrays (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1437\"\u003e#1437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003ecreditCard\u003c/code\u003e validation action to reject Mastercard numbers with invalid lengths (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1462\"\u003e#1462\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eintersect\u003c/code\u003e schema to no longer mutate input values, allowing frozen objects and arrays to be merged (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1463\"\u003e#1463\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.4.0 (to-json-schema)\u003c/h2\u003e\n\u003cp\u003eMany thanks to \u003ca href=\"https://github.com/stefanprobst\"\u003e\u003ccode\u003e@​stefanprobst\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/sruenwg\"\u003e\u003ccode\u003e@​sruenwg\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/cruzdanilo\"\u003e\u003ccode\u003e@​cruzdanilo\u003c/code\u003e\u003c/a\u003e for contributing to this release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for \u003ccode\u003eexamples\u003c/code\u003e action\u003c/li\u003e\n\u003cli\u003eAdd support for \u003ccode\u003einteger\u003c/code\u003e when used with \u003ccode\u003eminValue\u003c/code\u003e and \u003ccode\u003emaxValue\u003c/code\u003e actions (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1367\"\u003e#1367\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChange Valibot peer dependency to v1.2.0\u003c/li\u003e\n\u003cli\u003eFix conversion of \u003ccode\u003eexactOptional\u003c/code\u003e object properties (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1220\"\u003e#1220\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix conversion of \u003ccode\u003evariant\u003c/code\u003e to use \u003ccode\u003eoneOf\u003c/code\u003e instead of \u003ccode\u003eanyOf\u003c/code\u003e (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1193\"\u003e#1193\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.3.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChange \u003ccode\u003eMAC48_REGEX\u003c/code\u003e, \u003ccode\u003eMAC64_REGEX\u003c/code\u003e and \u003ccode\u003eMAC_REGEX\u003c/code\u003e to drop the \u003ccode\u003ei\u003c/code\u003e flag for better JSON Schema compatibility (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1430\"\u003e#1430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChange \u003ccode\u003ehash\u003c/code\u003e action to use case-expanded character classes instead of the \u003ccode\u003ei\u003c/code\u003e flag (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1430\"\u003e#1430\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.3.0\u003c/h2\u003e\n\u003cp\u003eMany thanks to \u003ca href=\"https://github.com/EskiMojo14\"\u003e\u003ccode\u003e@​EskiMojo14\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/yslpn\"\u003e\u003ccode\u003e@​yslpn\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/alexilyaev\"\u003e\u003ccode\u003e@​alexilyaev\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/idleberg\"\u003e\u003ccode\u003e@​idleberg\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/BerkliumBirb\"\u003e\u003ccode\u003e@​BerkliumBirb\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/frenzzy\"\u003e\u003ccode\u003e@​frenzzy\u003c/code\u003e\u003c/a\u003e for contributing to this release.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eRead the \u003ca href=\"https://valibot.dev/blog/valibot-v1.3-release-notes/\"\u003erelease notes\u003c/a\u003e on our website for a quick overview of the most exciting new features in this release.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003eguard\u003c/code\u003e transformation action to narrow types using type predicates (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1204\"\u003e#1204\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eparseBoolean\u003c/code\u003e transformation action to parse boolean values from strings and other types (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1251\"\u003e#1251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eisrc\u003c/code\u003e validation action to validate ISRC codes (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1373\"\u003e#1373\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003ecache\u003c/code\u003e method for caching schema output by input (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1170\"\u003e#1170\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003edomain\u003c/code\u003e validation action to validate domain names (pull request \u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1284\"\u003e#1284\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-circle/valibot/commit/0dc26ea88cf07a414653375f0da43f97e0eed607\"\u003e\u003ccode\u003e0dc26ea\u003c/code\u003e\u003c/a\u003e Bump library version to 1.4.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-circle/valibot/commit/1bd01c304657cd0809cc92694360b6cc60f700bf\"\u003e\u003ccode\u003e1bd01c3\u003c/code\u003e\u003c/a\u003e fix: handle keys that collide with Object.prototype in flatten and merge (\u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1522\"\u003e#1522\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-circle/valibot/commit/752c6369bbd05904bab22149bf79f716a274c99d\"\u003e\u003ccode\u003e752c636\u003c/code\u003e\u003c/a\u003e docs: clarify string length semantics (\u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1505\"\u003e#1505\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-circle/valibot/commit/a3beff96ad65e5409cb9202c9d2b30f670b3cde3\"\u003e\u003ccode\u003ea3beff9\u003c/code\u003e\u003c/a\u003e fix: cache word-count segmenter for non-primitive locales (\u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1521\"\u003e#1521\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-circle/valibot/commit/1f9b18338ad5530f1f6c63c2cf241962bd82d6f8\"\u003e\u003ccode\u003e1f9b183\u003c/code\u003e\u003c/a\u003e Update FUNDING.yml in fabvor of Open Collective\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-circle/valibot/commit/2c63b2a0c8ad23ace4e52f6e4a93524d39c25947\"\u003e\u003ccode\u003e2c63b2a\u003c/code\u003e\u003c/a\u003e Update logos of partners in README\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-circle/valibot/commit/09616b20c8772aeb2e6203b58f1254fae27cb071\"\u003e\u003ccode\u003e09616b2\u003c/code\u003e\u003c/a\u003e Add CodeRabbit as partner and remove Stainless\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-circle/valibot/commit/92bcf55fff4347f7d43327a0224565699df6602c\"\u003e\u003ccode\u003e92bcf55\u003c/code\u003e\u003c/a\u003e Add Cloudflare to privacy policy page\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-circle/valibot/commit/9bb6617f2f04e735cc815d771eb15f6b7ad0feb6\"\u003e\u003ccode\u003e9bb6617\u003c/code\u003e\u003c/a\u003e Add Cloudflare as a deploy target to our website (\u003ca href=\"https://redirect.github.com/open-circle/valibot/issues/1508\"\u003e#1508\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-circle/valibot/commit/c05bf954ada47d5ff953cdfad905cc701b25719c\"\u003e\u003ccode\u003ec05bf95\u003c/code\u003e\u003c/a\u003e Bump to-json-schema version to 1.7.1\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/open-circle/valibot/compare/v1.2.0...v1.4.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for valibot since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/executiveusa/pauli-glot/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/executiveusa/pauli-glot/pull/12","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/executiveusa%2Fpauli-glot/issues/12","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/12/packages"}},{"old_version":"3.1.7","new_version":"4.1.4","update_type":"major","path":null,"pr_created_at":"2026-09-13T06:06:05.000Z","version_change":"3.1.7 → 4.1.4","issue":{"uuid":"5438402679","node_id":"PR_kwDOSAxHtc8AAAABDUGkkQ","number":157,"state":"closed","title":"build(deps-dev): Bump the cadence-npm-development group across 1 directory with 15 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":"2026-09-13T07:37:51.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-13T06:06:05.000Z","updated_at":"2026-09-13T07:38:00.000Z","time_to_close":5506,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps-dev): Bump","group_name":"cadence-npm-development","update_count":15,"packages":[{"name":"@playwright/test","old_version":"1.61.1","new_version":"1.63.0","repository_url":"https://github.com/microsoft/playwright"},{"name":"@testing-library/jest-dom","old_version":"6.9.1","new_version":"7.0.1","repository_url":"https://github.com/testing-library/jest-dom"},{"name":"@testing-library/react","old_version":"16.3.2","new_version":"16.3.3","repository_url":"https://github.com/testing-library/react-testing-library"},{"name":"@types/node","old_version":"26.1.1","new_version":"26.5.1","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"@typescript-eslint/eslint-plugin","old_version":"8.63.0","new_version":"8.70.0","repository_url":"https://github.com/typescript-eslint/typescript-eslint"},{"name":"@vitejs/plugin-react","old_version":"6.0.3","new_version":"6.1.1","repository_url":"https://github.com/vitejs/vite-plugin-react"},{"name":"@vitest/coverage-v8","old_version":"4.1.10","new_version":"5.0.0","repository_url":"https://github.com/vitest-dev/vitest"},{"name":"browserslist","old_version":"4.28.8","new_version":"4.28.9","repository_url":"https://github.com/browserslist/browserslist"},{"name":"eslint","old_version":"10.6.0","new_version":"10.10.0","repository_url":"https://github.com/eslint/eslint"},{"name":"fast-uri","old_version":"3.1.7","new_version":"4.1.4","repository_url":"https://github.com/fastify/fast-uri"},{"name":"jsdom","old_version":"29.1.1","new_version":"30.0.1","repository_url":"https://github.com/jsdom/jsdom"},{"name":"prettier","old_version":"3.9.4","new_version":"3.9.6","repository_url":"https://github.com/prettier/prettier"},{"name":"vite","old_version":"8.1.3","new_version":"8.2.2","repository_url":"https://github.com/vitejs/vite"},{"name":"vitest","old_version":"4.1.10","new_version":"5.0.0","repository_url":"https://github.com/vitest-dev/vitest"}],"path":null,"ecosystem":"npm"},"body":"Bumps the cadence-npm-development group with 14 updates in the /Cadence/web directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@playwright/test](https://github.com/microsoft/playwright) | `1.61.1` | `1.63.0` |\n| [@testing-library/jest-dom](https://github.com/testing-library/jest-dom) | `6.9.1` | `7.0.1` |\n| [@testing-library/react](https://github.com/testing-library/react-testing-library) | `16.3.2` | `16.3.3` |\n| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.1.1` | `26.5.1` |\n| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.63.0` | `8.70.0` |\n| [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) | `6.0.3` | `6.1.1` |\n| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `4.1.10` | `5.0.0` |\n| [browserslist](https://github.com/browserslist/browserslist) | `4.28.8` | `4.28.9` |\n| [eslint](https://github.com/eslint/eslint) | `10.6.0` | `10.10.0` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.7` | `4.1.4` |\n| [jsdom](https://github.com/jsdom/jsdom) | `29.1.1` | `30.0.1` |\n| [prettier](https://github.com/prettier/prettier) | `3.9.4` | `3.9.6` |\n| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.1.3` | `8.2.2` |\n| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.10` | `5.0.0` |\n\n\nUpdates `@playwright/test` from 1.61.1 to 1.63.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/microsoft/playwright/releases\"\u003e@​playwright/test's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.63.0\u003c/h2\u003e\n\u003ch2\u003e🔒 Test locks\u003c/h2\u003e\n\u003cp\u003eTests that access a shared resource — an external service, a global account setting — can now declare a named \u003ccode\u003elock\u003c/code\u003e.\nTests that share a lock name never run concurrently, across files, workers and \u003ca href=\"https://playwright.dev/docs/test-projects\"\u003eprojects\u003c/a\u003e, while\neverything else keeps running in parallel:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003etest('update user settings', { lock: 'user-settings' }, async ({ page }) =\u0026gt; {\r\n  // never runs at the same time as other tests holding 'user-settings'\r\n});\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eA test can hold multiple locks, and \u003ca href=\"https://playwright.dev/docs/api/class-test#test-describe\"\u003etest.describe()\u003c/a\u003e accepts a \u003ccode\u003elock\u003c/code\u003e for the whole group.\nLearn more about \u003ca href=\"https://playwright.dev/docs/test-parallel#test-locks\"\u003etest locks\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003e🪟 Locate across frames\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://playwright.dev/docs/api/class-page#page-frame-locator\"\u003epage.frameLocator()\u003c/a\u003e and \u003ca href=\"https://playwright.dev/docs/api/class-frame#frame-frame-locator\"\u003eframe.frameLocator()\u003c/a\u003e called without a selector search in any frame of the\nsubtree, so you no longer need to locate the iframe first:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Finds the button in any frame on the page.\r\nawait page.frameLocator().getByRole('button').click();\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eThe rest of the locator resolves inside a single frame, just like a regular locator, and an error is thrown when it\nmatches elements in several frames.\u003c/p\u003e\n\u003ch2\u003e👁️ Visible-only locators\u003c/h2\u003e\n\u003cp\u003eNew \u003ca href=\"https://playwright.dev/docs/api/class-locator#locator-visible\"\u003elocator.visible()\u003c/a\u003e returns a locator that matches only visible elements. It is the recommended\nreplacement for the \u003ccode\u003e:visible\u003c/code\u003e CSS pseudo-class:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003eawait page.locator('button').visible().click();\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003ch2\u003e🧾 Step params and subtitles\u003c/h2\u003e\n\u003cp\u003eSteps now carry structured data for reporters. Playwright API steps report the target locator and call arguments,\nand \u003ca href=\"https://playwright.dev/docs/api/class-test#test-step\"\u003etest.step()\u003c/a\u003e accepts \u003ccode\u003esubtitle\u003c/code\u003e and \u003ccode\u003eparams\u003c/code\u003e options for your own steps:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003eawait test.step('Login', async () =\u0026gt; {\r\n  // ...\r\n}, { subtitle: 'as admin', params: { user: 'admin' } });\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eReporters receive them via \u003ca href=\"https://playwright.dev/docs/api/class-teststep#test-step-subtitle\"\u003etestStep.subtitle\u003c/a\u003e and \u003ca href=\"https://playwright.dev/docs/api/class-teststep#test-step-params\"\u003etestStep.params\u003c/a\u003e. For Playwright API\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/1b025d7e20a026371cd5f98ba0cdce48892737c8\"\u003e\u003ccode\u003e1b025d7\u003c/code\u003e\u003c/a\u003e chore: mark v1.63.0 (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42569\"\u003e#42569\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/0b9956d2247ce88399c3c46a22c1cc0526acb340\"\u003e\u003ccode\u003e0b9956d\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42568\"\u003e#42568\u003c/a\u003e): docs(test): mark test.step subtitle option as since v1.63\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/13dbf102b88305ed96b7791a7843246cd75d4dae\"\u003e\u003ccode\u003e13dbf10\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42552\"\u003e#42552\u003c/a\u003e): docs: release notes for v1.63\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/e93b64ed6f9cf6ac2cc8cb13ad01514b406a7142\"\u003e\u003ccode\u003ee93b64e\u003c/code\u003e\u003c/a\u003e cherry-pick(\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42566\"\u003e#42566\u003c/a\u003e): feat(test): add subtitle option to test.step (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42567\"\u003e#42567\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/2b7a5f2ea1cea04b549c5378498c1b16b6bc6a6f\"\u003e\u003ccode\u003e2b7a5f2\u003c/code\u003e\u003c/a\u003e test: response.body() for content-encoding:identity (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42537\"\u003e#42537\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/648a67c7c1261eefe4113cba2d586417d5e3f2f2\"\u003e\u003ccode\u003e648a67c\u003c/code\u003e\u003c/a\u003e fix(mcp): create parent directories for explicitly named files (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42540\"\u003e#42540\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/7894f5653e7f253c17aa1638c19f63e0d54d5e0e\"\u003e\u003ccode\u003e7894f56\u003c/code\u003e\u003c/a\u003e docs(mcp): clarify how tool file names are resolved (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42538\"\u003e#42538\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/52900a1b99ca51011526afcaf8981970cc1a521a\"\u003e\u003ccode\u003e52900a1\u003c/code\u003e\u003c/a\u003e devops: restore npm publishing from GitHub Actions (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42550\"\u003e#42550\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/8c47f596edebd2460895a5953f2ea67f8b884001\"\u003e\u003ccode\u003e8c47f59\u003c/code\u003e\u003c/a\u003e docs(csharp): fix nonexistent method names in guide examples (\u003ca href=\"https://redirect.github.com/microsoft/playwright/issues/42507\"\u003e#42507\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/playwright/commit/bd6e552a63f8cf9b0da0216f392b8e63a08bf1d2\"\u003e\u003ccode\u003ebd6e552\u003c/code\u003e\u003c/a\u003e chore(video): emit frames with real timestamps, drop frame number quantizatio...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/microsoft/playwright/compare/v1.61.1...v1.63.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@testing-library/jest-dom` from 6.9.1 to 7.0.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/testing-library/jest-dom/releases\"\u003e@​testing-library/jest-dom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/testing-library/jest-dom/compare/v7.0.0...v7.0.1\"\u003e7.0.1\u003c/a\u003e (2026-08-09)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003edeclare vitest as an optional peer dependency (\u003ca href=\"https://redirect.github.com/testing-library/jest-dom/issues/733\"\u003e#733\u003c/a\u003e) (\u003ca href=\"https://github.com/testing-library/jest-dom/commit/3782c78b3dc9824675afe0cb8f1722f8c96f494d\"\u003e3782c78\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/testing-library/jest-dom/compare/v6.10.0...v7.0.0\"\u003e7.0.0\u003c/a\u003e (2026-07-20)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eadd toContainAnyBy* and toContainOneBy* query matchers (\u003ca href=\"https://github.com/testing-library/jest-dom/commit/1e39089d850408a583c83495d00d8aa27078933f\"\u003e1e39089\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBREAKING CHANGES\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​testing-library/dom\u003c/code\u003e is now a required peer dependency. The minimum supported\nNode.js version is now 22.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eRepaired release for \u003ca href=\"https://redirect.github.com/testing-library/jest-dom/pull/731\"\u003etesting-library/jest-dom#731\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.10.0\u003c/h2\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/testing-library/jest-dom/compare/v6.9.1...v6.10.0\"\u003e6.10.0\u003c/a\u003e (2026-07-20)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eadd toContainAnyBy* and toContainOneBy* query matchers (\u003ca href=\"https://redirect.github.com/testing-library/jest-dom/issues/731\"\u003e#731\u003c/a\u003e) (\u003ca href=\"https://github.com/testing-library/jest-dom/commit/cae44df901cf8e92e3febc0af6fa667b10be6d6a\"\u003ecae44df\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/jest-dom/commit/3782c78b3dc9824675afe0cb8f1722f8c96f494d\"\u003e\u003ccode\u003e3782c78\u003c/code\u003e\u003c/a\u003e fix: declare vitest as an optional peer dependency (\u003ca href=\"https://redirect.github.com/testing-library/jest-dom/issues/733\"\u003e#733\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/jest-dom/commit/1e39089d850408a583c83495d00d8aa27078933f\"\u003e\u003ccode\u003e1e39089\u003c/code\u003e\u003c/a\u003e feat: add toContainAnyBy* and toContainOneBy* query matchers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/jest-dom/commit/cae44df901cf8e92e3febc0af6fa667b10be6d6a\"\u003e\u003ccode\u003ecae44df\u003c/code\u003e\u003c/a\u003e feat: add toContainAnyBy* and toContainOneBy* query matchers (\u003ca href=\"https://redirect.github.com/testing-library/jest-dom/issues/731\"\u003e#731\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/jest-dom/commit/55c07ce5f1c489b5b9dc31a770a84d83a1178072\"\u003e\u003ccode\u003e55c07ce\u003c/code\u003e\u003c/a\u003e ci: switch release to npm trusted publishing (\u003ca href=\"https://redirect.github.com/testing-library/jest-dom/issues/726\"\u003e#726\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/jest-dom/commit/213256fa8e0aff45e47920a0bc564f708d1f67de\"\u003e\u003ccode\u003e213256f\u003c/code\u003e\u003c/a\u003e docs: move toHaveSelection from the deprecated section (\u003ca href=\"https://redirect.github.com/testing-library/jest-dom/issues/717\"\u003e#717\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/testing-library/jest-dom/compare/v6.9.1...v7.0.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​testing-library/jest-dom\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@testing-library/react` from 16.3.2 to 16.3.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/testing-library/react-testing-library/releases\"\u003e@​testing-library/react's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.3\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/testing-library/react-testing-library/compare/v16.3.2...v16.3.3\"\u003e16.3.3\u003c/a\u003e (2026-08-27)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid act() re-entrant when dispatching events (\u003ca href=\"https://redirect.github.com/testing-library/react-testing-library/issues/1468\"\u003e#1468\u003c/a\u003e) (\u003ca href=\"https://github.com/testing-library/react-testing-library/commit/20ce75f2907ca0e5c5a8ae595c0e9a4e368c7800\"\u003e20ce75f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/react-testing-library/commit/20ce75f2907ca0e5c5a8ae595c0e9a4e368c7800\"\u003e\u003ccode\u003e20ce75f\u003c/code\u003e\u003c/a\u003e fix: Avoid act() re-entrant when dispatching events (\u003ca href=\"https://redirect.github.com/testing-library/react-testing-library/issues/1468\"\u003e#1468\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/testing-library/react-testing-library/commit/be9d81d91314c9f0bafaa363f70b409b4b31989c\"\u003e\u003ccode\u003ebe9d81d\u003c/code\u003e\u003c/a\u003e docs: fix typos in comments and types (\u003ca href=\"https://redirect.github.com/testing-library/react-testing-library/issues/1446\"\u003e#1446\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/testing-library/react-testing-library/compare/v16.3.2...v16.3.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@types/node` from 26.1.1 to 26.5.1\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@typescript-eslint/eslint-plugin` from 8.63.0 to 8.70.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases\"\u003e@​typescript-eslint/eslint-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.70.0\u003c/h2\u003e\n\u003ch2\u003e8.70.0 (2026-09-07)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-generated-empty-object-type] add rule (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12730\"\u003e#12730\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ewebsite:\u003c/strong\u003e generate per-page social preview cards (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12734\"\u003e#12734\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003euse stable release of pnpm 12 (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12808\"\u003e#12808\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate pnpm to 12.3.4 and dedupe Docusaurus packages (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12829\"\u003e#12829\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [member-ordering] don't report fields that read fields declared before them (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12729\"\u003e#12729\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-unnecessary-condition] no false positive on RHS of a nested logical expression (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12728\"\u003e#12728\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-deprecated] report deprecated imported values used in object shorthand properties (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12780\"\u003e#12780\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eproject-service:\u003c/strong\u003e avoid discarded tsserver logs (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12748\"\u003e#12748\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypescript-estree:\u003c/strong\u003e clarify the parserOptions.project error message (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12817\"\u003e#12817\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBarry \u003ca href=\"https://github.com/barry166\"\u003e\u003ccode\u003e@​barry166\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEvyatar Daud \u003ca href=\"https://github.com/StyleShit\"\u003e\u003ccode\u003e@​StyleShit\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJosh Goldberg\u003c/li\u003e\n\u003cli\u003eJosh Goldberg ✨ \u003ca href=\"https://github.com/JoshuaKGoldberg\"\u003e\u003ccode\u003e@​JoshuaKGoldberg\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eKirk Waiblinger \u003ca href=\"https://github.com/kirkwaiblinger\"\u003e\u003ccode\u003e@​kirkwaiblinger\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUlrich Stark \u003ca href=\"https://github.com/ulrichstark\"\u003e\u003ccode\u003e@​ulrichstark\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e송재욱\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003ev8.69.0\u003c/h2\u003e\n\u003ch2\u003e8.69.0 (2026-08-31)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-misused-promises] add flagUnions option for checkConditionals (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12603\"\u003e#12603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-mixed-enums] use scope analysis instead of type checking for merged namespaces (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12731\"\u003e#12731\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [unified-signatures] compare type parameters by constraint instead of name (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12741\"\u003e#12741\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-meaningless-void-operator] report void on non-call expressions (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12727\"\u003e#12727\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ewebsite:\u003c/strong\u003e respect allowJs playground config (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12744\"\u003e#12744\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAbdu Alim Arlikhozhaev \u003ca href=\"https://github.com/Arlikhozhaev\"\u003e\u003ccode\u003e@​Arlikhozhaev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEvyatar Daud \u003ca href=\"https://github.com/StyleShit\"\u003e\u003ccode\u003e@​StyleShit\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md\"\u003e@​typescript-eslint/eslint-plugin's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.70.0 (2026-09-07)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-generated-empty-object-type] add rule (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12730\"\u003e#12730\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-deprecated] report deprecated imported values used in object shorthand properties (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12780\"\u003e#12780\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-unnecessary-condition] no false positive on RHS of a nested logical expression (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12728\"\u003e#12728\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [member-ordering] don't report fields that read fields declared before them (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12729\"\u003e#12729\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eJosh Goldberg ✨ \u003ca href=\"https://github.com/JoshuaKGoldberg\"\u003e\u003ccode\u003e@​JoshuaKGoldberg\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUlrich Stark \u003ca href=\"https://github.com/ulrichstark\"\u003e\u003ccode\u003e@​ulrichstark\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003e8.69.0 (2026-08-31)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-misused-promises] add flagUnions option for checkConditionals (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12603\"\u003e#12603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-meaningless-void-operator] report void on non-call expressions (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12727\"\u003e#12727\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [unified-signatures] compare type parameters by constraint instead of name (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12741\"\u003e#12741\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-mixed-enums] use scope analysis instead of type checking for merged namespaces (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12731\"\u003e#12731\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAbdu Alim Arlikhozhaev \u003ca href=\"https://github.com/Arlikhozhaev\"\u003e\u003ccode\u003e@​Arlikhozhaev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEvyatar Daud \u003ca href=\"https://github.com/StyleShit\"\u003e\u003ccode\u003e@​StyleShit\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJosh Goldberg ✨\u003c/li\u003e\n\u003cli\u003ewonbeanie \u003ca href=\"https://github.com/wonbeanie\"\u003e\u003ccode\u003e@​wonbeanie\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.69.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003e8.68.0 (2026-08-24)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [strict-void-return] add fix suggestions (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12086\"\u003e#12086\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/7ee76085c22e923c0036b8e0733a3ca7dfd82b60\"\u003e\u003ccode\u003e7ee7608\u003c/code\u003e\u003c/a\u003e chore(release): publish 8.70.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/f66bdcac30c13c7ca8932667494550fd13fde5fc\"\u003e\u003ccode\u003ef66bdca\u003c/code\u003e\u003c/a\u003e test(eslint-plugin): [member-ordering] use \u003ccode\u003eRuleTester\u003c/code\u003e directly in `optional...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/4586535ab24d7d5e9b3ba87e4adb8636f9314aca\"\u003e\u003ccode\u003e4586535\u003c/code\u003e\u003c/a\u003e fix(eslint-plugin): [no-deprecated] report deprecated imported values used in...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/f8e1e4e2f7454ab2ba680cb523f9e3abe6582f81\"\u003e\u003ccode\u003ef8e1e4e\u003c/code\u003e\u003c/a\u003e fix(eslint-plugin): [no-unnecessary-condition] no false positive on RHS of a ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/889cece8bba520fc8c342dade4adf42b5d7f671e\"\u003e\u003ccode\u003e889cece\u003c/code\u003e\u003c/a\u003e fix(eslint-plugin): [member-ordering] don't report fields that read fields de...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/1a5a8b124b905c81a76ba1104a6396e65ad407dd\"\u003e\u003ccode\u003e1a5a8b1\u003c/code\u003e\u003c/a\u003e feat(eslint-plugin): [no-generated-empty-object-type] add rule (\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin/issues/12730\"\u003e#12730\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/9a6e546823e5d8f2dc015df2aa66c0230615e209\"\u003e\u003ccode\u003e9a6e546\u003c/code\u003e\u003c/a\u003e chore(release): publish 8.69.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/513638effe9e7b78566cc153d4d809a1435153f3\"\u003e\u003ccode\u003e513638e\u003c/code\u003e\u003c/a\u003e fix(eslint-plugin): [no-meaningless-void-operator] report void on non-call ex...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/1dba4c50f0599cc212e9d1eca9ec0f21a818f0b5\"\u003e\u003ccode\u003e1dba4c5\u003c/code\u003e\u003c/a\u003e chore(eslint-plugin): fix \u003ccode\u003eeslint-plugin/require-test-error-positions\u003c/code\u003e report...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/a2fccae39c7cb1e516a29b1c746b7767bffa03e2\"\u003e\u003ccode\u003ea2fccae\u003c/code\u003e\u003c/a\u003e fix(eslint-plugin): [unified-signatures] compare type parameters by constrain...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.0/packages/eslint-plugin\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@typescript-eslint/parser` from 8.63.0 to 8.70.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases\"\u003e@​typescript-eslint/parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.70.0\u003c/h2\u003e\n\u003ch2\u003e8.70.0 (2026-09-07)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-generated-empty-object-type] add rule (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12730\"\u003e#12730\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ewebsite:\u003c/strong\u003e generate per-page social preview cards (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12734\"\u003e#12734\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003euse stable release of pnpm 12 (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12808\"\u003e#12808\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate pnpm to 12.3.4 and dedupe Docusaurus packages (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12829\"\u003e#12829\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [member-ordering] don't report fields that read fields declared before them (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12729\"\u003e#12729\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-unnecessary-condition] no false positive on RHS of a nested logical expression (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12728\"\u003e#12728\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-deprecated] report deprecated imported values used in object shorthand properties (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12780\"\u003e#12780\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eproject-service:\u003c/strong\u003e avoid discarded tsserver logs (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12748\"\u003e#12748\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypescript-estree:\u003c/strong\u003e clarify the parserOptions.project error message (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12817\"\u003e#12817\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBarry \u003ca href=\"https://github.com/barry166\"\u003e\u003ccode\u003e@​barry166\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEvyatar Daud \u003ca href=\"https://github.com/StyleShit\"\u003e\u003ccode\u003e@​StyleShit\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJosh Goldberg\u003c/li\u003e\n\u003cli\u003eJosh Goldberg ✨ \u003ca href=\"https://github.com/JoshuaKGoldberg\"\u003e\u003ccode\u003e@​JoshuaKGoldberg\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eKirk Waiblinger \u003ca href=\"https://github.com/kirkwaiblinger\"\u003e\u003ccode\u003e@​kirkwaiblinger\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUlrich Stark \u003ca href=\"https://github.com/ulrichstark\"\u003e\u003ccode\u003e@​ulrichstark\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e송재욱\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003ev8.69.0\u003c/h2\u003e\n\u003ch2\u003e8.69.0 (2026-08-31)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-misused-promises] add flagUnions option for checkConditionals (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12603\"\u003e#12603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-mixed-enums] use scope analysis instead of type checking for merged namespaces (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12731\"\u003e#12731\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [unified-signatures] compare type parameters by constraint instead of name (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12741\"\u003e#12741\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-meaningless-void-operator] report void on non-call expressions (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12727\"\u003e#12727\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ewebsite:\u003c/strong\u003e respect allowJs playground config (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12744\"\u003e#12744\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAbdu Alim Arlikhozhaev \u003ca href=\"https://github.com/Arlikhozhaev\"\u003e\u003ccode\u003e@​Arlikhozhaev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEvyatar Daud \u003ca href=\"https://github.com/StyleShit\"\u003e\u003ccode\u003e@​StyleShit\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md\"\u003e@​typescript-eslint/parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.70.0 (2026-09-07)\u003c/h2\u003e\n\u003cp\u003eThis was a version bump only for parser to align it with other projects, there were no code changes.\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003e8.69.0 (2026-08-31)\u003c/h2\u003e\n\u003cp\u003eThis was a version bump only for parser to align it with other projects, there were no code changes.\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.69.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003e8.68.0 (2026-08-24)\u003c/h2\u003e\n\u003cp\u003eThis was a version bump only for parser to align it with other projects, there were no code changes.\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.68.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003e8.67.0 (2026-08-10)\u003c/h2\u003e\n\u003cp\u003eThis was a version bump only for parser to align it with other projects, there were no code changes.\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.67.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003e8.66.0 (2026-08-03)\u003c/h2\u003e\n\u003cp\u003eThis was a version bump only for parser to align it with other projects, there were no code changes.\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.66.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003e8.65.0 (2026-07-20)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eadd warning when TS 7 is detected (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12529\"\u003e#12529\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eparser:\u003c/strong\u003e add onUnsupportedTypeScriptVersion option to error on unsupported TypeScript versions (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12465\"\u003e#12465\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEvyatar Daud \u003ca href=\"https://github.com/StyleShit\"\u003e\u003ccode\u003e@​StyleShit\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/7ee76085c22e923c0036b8e0733a3ca7dfd82b60\"\u003e\u003ccode\u003e7ee7608\u003c/code\u003e\u003c/a\u003e chore(release): publish 8.70.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/9a6e546823e5d8f2dc015df2aa66c0230615e209\"\u003e\u003ccode\u003e9a6e546\u003c/code\u003e\u003c/a\u003e chore(release): publish 8.69.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/8f4e00a4e8f3bdf93a5e5e8bc568ba1c15a4f896\"\u003e\u003ccode\u003e8f4e00a\u003c/code\u003e\u003c/a\u003e chore(release): publish 8.68.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/55f6d5d4ca39d2fab93db97ced497b956017878d\"\u003e\u003ccode\u003e55f6d5d\u003c/code\u003e\u003c/a\u003e chore: enable source maps (\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser/issues/12677\"\u003e#12677\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/20a261fb8e62351e88176b075090dc9276d26072\"\u003e\u003ccode\u003e20a261f\u003c/code\u003e\u003c/a\u003e chore(release): publish 8.67.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/3b155bb1344fd7ce83086cf2f864a7e8f3b4a217\"\u003e\u003ccode\u003e3b155bb\u003c/code\u003e\u003c/a\u003e chore: use typescript 7 for typechecking (\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser/issues/12601\"\u003e#12601\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/e51b11ba3ab31837762c675f62f0d4dcb1abc4fb\"\u003e\u003ccode\u003ee51b11b\u003c/code\u003e\u003c/a\u003e chore(release): publish 8.66.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/63ba81b6acfa0d663c29aa0013d4672bf3b0426c\"\u003e\u003ccode\u003e63ba81b\u003c/code\u003e\u003c/a\u003e chore(release): publish 8.65.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/eaf457631ac381aadfee747c2d098c8ac4df9d63\"\u003e\u003ccode\u003eeaf4576\u003c/code\u003e\u003c/a\u003e feat: add warning when TS 7 is detected (\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser/issues/12529\"\u003e#12529\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/d8f1044702e3257ee92c0af6681c1455563009db\"\u003e\u003ccode\u003ed8f1044\u003c/code\u003e\u003c/a\u003e feat(parser): add onUnsupportedTypeScriptVersion option to error on unsupport...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.0/packages/parser\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@vitejs/plugin-react` from 6.0.3 to 6.1.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite-plugin-react/releases\"\u003e@​vitejs/plugin-react's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eplugin-react@6.1.1\u003c/h2\u003e\n\u003ch3\u003eAdd \u003ccode\u003ecompiler.logDiagnostics\u003c/code\u003e option\u003c/h3\u003e\n\u003cp\u003eRecoverable React Compiler diagnostics are no longer logged by default. Set \u003ccode\u003ecompiler.logDiagnostics\u003c/code\u003e to \u003ccode\u003etrue\u003c/code\u003e to log them through Vite. Fatal diagnostics are always logged and fail the transform.\u003c/p\u003e\n\u003ch3\u003eRespect environment sourcemap option for React Compiler transform when \u003ccode\u003ebuilder.sharedPlugins\u003c/code\u003e is enabled (\u003ca href=\"https://redirect.github.com/vitejs/vite-plugin-react/pull/1439\"\u003e#1439\u003c/a\u003e)\u003c/h3\u003e\n\u003cp\u003eThe React Compiler transform was using the top-level sourcemap option instead of the environment sourcemap option. This caused a problem when the experimental \u003ccode\u003ebuilder.sharedPlugins\u003c/code\u003e was enabled.\u003c/p\u003e\n\u003ch2\u003eplugin-react@6.1.0\u003c/h2\u003e\n\u003ch3\u003eAdd experimental native React Compiler support (\u003ca href=\"https://redirect.github.com/vitejs/vite-plugin-react/pull/1419\"\u003e#1419\u003c/a\u003e)\u003c/h3\u003e\n\u003cp\u003eAdd experimental native React Compiler support.\u003c/p\u003e\n\u003cp\u003eYou can use it by installing \u003ccode\u003eoxc-transform-react\u003c/code\u003e and enabling it via the \u003ccode\u003ecompiler\u003c/code\u003e option:\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install -D oxc-transform-react\n\u003c/code\u003e\u003c/pre\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003eimport { defineConfig } from 'vite'\nimport react from '@vitejs/plugin-react'\n\u003cp\u003eexport default defineConfig({\u003cbr /\u003e\nplugins: [\u003cbr /\u003e\nreact({ compiler: true })\u003cbr /\u003e\n]\u003cbr /\u003e\n})\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003ch2\u003eplugin-react@6.0.5\u003c/h2\u003e\n\u003ch3\u003eFixed the react compiler preset filter to be linear (\u003ca href=\"https://redirect.github.com/vitejs/vite-plugin-react/pull/1353\"\u003e#1353\u003c/a\u003e)\u003c/h3\u003e\n\u003cp\u003eThe improved filter in v6.0.3 was non-linear and caused a performance regression (\u003ca href=\"https://redirect.github.com/vitejs/vite-plugin-react/issues/1349\"\u003e#1349\u003c/a\u003e). The filter was changed to be linear to avoid that.\u003c/p\u003e\n\u003ch2\u003eplugin-react@6.0.4\u003c/h2\u003e\n\u003ch3\u003eFixed \u003ccode\u003e$RefreshSig$ is not defined\u003c/code\u003e error when running \u003ccode\u003evite dev\u003c/code\u003e with \u003ccode\u003eNODE_ENV=production\u003c/code\u003e\u003c/h3\u003e\n\u003cp\u003eWhen running \u003ccode\u003evite dev\u003c/code\u003e with \u003ccode\u003eNODE_ENV=production\u003c/code\u003e, the app errored with \u003ccode\u003e$RefreshSig$ is not defined\u003c/code\u003e.\nThis error is now fixed.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md\"\u003e@​vitejs/plugin-react's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e6.1.1 (2026-08-28)\u003c/h2\u003e\n\u003ch3\u003eAdd \u003ccode\u003ecompiler.logDiagnostics\u003c/code\u003e option\u003c/h3\u003e\n\u003cp\u003eRecoverable React Compiler diagnostics are no longer logged by default. Set \u003ccode\u003ecompiler.logDiagnostics\u003c/code\u003e to \u003ccode\u003etrue\u003c/code\u003e to log them through Vite. Fatal diagnostics are always logged and fail the transform.\u003c/p\u003e\n\u003ch3\u003eRespect environment sourcemap option for React Compiler transform when \u003ccode\u003ebuilder.sharedPlugins\u003c/code\u003e is enabled (\u003ca href=\"https://redirect.github.com/vitejs/vite-plugin-react/pull/1439\"\u003e#1439\u003c/a\u003e)\u003c/h3\u003e\n\u003cp\u003eThe React Compiler transform was using the top-level sourcemap option instead of the environment sourcemap option. This caused a problem when the experimental \u003ccode\u003ebuilder.sharedPlugins\u003c/code\u003e was enabled.\u003c/p\u003e\n\u003ch2\u003e6.1.0 (2026-08-19)\u003c/h2\u003e\n\u003ch3\u003eAdd experimental native React Compiler support (\u003ca href=\"https://redirect.github.com/vitejs/vite-plugin-react/pull/1419\"\u003e#1419\u003c/a\u003e)\u003c/h3\u003e\n\u003cp\u003eAdd experimental native React Compiler support.\u003c/p\u003e\n\u003cp\u003eYou can use it by installing \u003ccode\u003eoxc-transform-react\u003c/code\u003e and enabling it via the \u003ccode\u003ecompiler\u003c/code\u003e option:\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install -D oxc-transform-react\n\u003c/code\u003e\u003c/pre\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003eimport { defineConfig } from 'vite'\nimport react from '@vitejs/plugin-react'\n\u003cp\u003eexport default defineConfig({\u003cbr /\u003e\nplugins: [\u003cbr /\u003e\nreact({ compiler: true })\u003cbr /\u003e\n]\u003cbr /\u003e\n})\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003ch2\u003e6.0.5 (2026-07-30)\u003c/h2\u003e\n\u003ch3\u003eFixed the react compiler preset filter to be linear (\u003ca href=\"https://redirect.github.com/vitejs/vite-plugin-react/pull/1353\"\u003e#1353\u003c/a\u003e)\u003c/h3\u003e\n\u003cp\u003eThe improved filter in v6.0.3 was non-linear and caused a performance regression (\u003ca href=\"https://redirect.github.com/vitejs/vite-plugin-react/issues/1349\"\u003e#1349\u003c/a\u003e). The filter was changed to be linear to avoid that.\u003c/p\u003e\n\u003ch2\u003e6.0.4 (2026-07-22)\u003c/h2\u003e\n\u003ch3\u003eFixed \u003ccode\u003e$RefreshSig$ is not defined\u003c/code\u003e error when running \u003ccode\u003evite dev\u003c/code\u003e with \u003ccode\u003eNODE_ENV=production\u003c/code\u003e\u003c/h3\u003e\n\u003cp\u003eWhen running \u003ccode\u003evite dev\u003c/code\u003e with \u003ccode\u003eNODE_ENV=production\u003c/code\u003e, the app errored with \u003ccode\u003e$RefreshSig$ is not defined\u003c/code\u003e.\nThis error is now fixed.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite-plugin-react/commit/04cac5020e349f452d76c5a4f6d788ad4b38930a\"\u003e\u003ccode\u003e04cac50\u003c/code\u003e\u003c/a\u003e release: plugin-react@6.1.1 (\u003ca href=\"https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1440\"\u003e#1440\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite-plugin-react/commit/82d35abe4946eddd4e6456802bf2b53444e264f2\"\u003e\u003ccode\u003e82d35ab\u003c/code\u003e\u003c/a\u003e fix(react): respect environment sourcemap option when \u003ccode\u003ebuilder.sharedPlugins\u003c/code\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite-plugin-react/commit/397e8471a559f18a16dd21bd797ac01a369dabdc\"\u003e\u003ccode\u003e397e847\u003c/code\u003e\u003c/a\u003e fix(react): make logging diagnostics an opt-in for React Compiler (\u003ca href=\"https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1431\"\u003e#1431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite-plugin-react/commit/61006e6f52124821c24121a78712f7162ae36f5b\"\u003e\u003ccode\u003e61006e6\u003c/code\u003e\u003c/a\u003e fix(deps): update all non-major dependencies (\u003ca href=\"https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1433\"\u003e#1433\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite-plugin-react/commit/e2a649cbaa7334d6991f843563683975667e1be1\"\u003e\u003ccode\u003ee2a649c\u003c/code\u003e\u003c/a\u003e chore: use \u003ccode\u003edeps.neverBundle\u003c/code\u003e instead of \u003ccode\u003eexternal\u003c/code\u003e in tsdown config (\u003ca href=\"https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1430\"\u003e#1430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite-plugin-react/commit/fb2d6f3635acbb0f3acbd0e9a914f6c620460957\"\u003e\u003ccode\u003efb2d6f3\u003c/code\u003e\u003c/a\u003e fix(deps): update all non-major dependencies (\u003ca href=\"https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1427\"\u003e#1427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite-plugin-react/commit/39b31735bf79c2dd380eedaba7ed849256f92a29\"\u003e\u003ccode\u003e39b3173\u003c/code\u003e\u003c/a\u003e release: plugin-react@6.1.0 (\u003ca href=\"https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1428\"\u003e#1428\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite-plugin-react/commit/f1340b0c760b1c16e1b780eeba46fd933ddd52eb\"\u003e\u003ccode\u003ef1340b0\u003c/code\u003e\u003c/a\u003e feat(react): add native React Compiler support (\u003ca href=\"https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1419\"\u003e#1419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite-plugin-react/commit/9ab698eafc38ffa14861db450291ed2f6f557557\"\u003e\u003ccode\u003e9ab698e\u003c/code\u003e\u003c/a\u003e fix(deps): update all non-major dependencies (\u003ca href=\"https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1375\"\u003e#1375\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite-plugin-react/commit/68c0cb8796ce18bd049c3d05c5210eaf0617eac0\"\u003e\u003ccode\u003e68c0cb8\u003c/code\u003e\u003c/a\u003e release: plugin-react@6.0.5 (\u003ca href=\"https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1362\"\u003e#1362\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.1.1/packages/plugin-react\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@vitest/coverage-v8` from 4.1.10 to 5.0.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitest-dev/vitest/releases\"\u003e@​vitest/coverage-v8's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.0.0\u003c/h2\u003e\n\u003cp\u003eVitest 5 is officially out! This release focuses on performance and brings a lot of new features while fixing long-standing bugs. See our \u003ca href=\"https://vitest.dev/blog/vitest-5.html\"\u003eblog post\u003c/a\u003e for the official announcement.\u003c/p\u003e\n\u003ch3\u003e   🚨 Breaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReplace \u003ccode\u003eloupe.inspect\u003c/code\u003e with pretty-format  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eClaude Opus 5 (1M context)\u003c/strong\u003e and \u003cstrong\u003eOpenAI Codex\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9609\"\u003evitest-dev/vitest#9609\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/3f802da4b\"\u003e\u003c!-- raw HTML omitted --\u003e(3f802)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove quotes from string values in \u003ccode\u003etest.for/each\u003c/code\u003e title \u003ccode\u003e$\u003c/code\u003e variable (take 2)  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10170\"\u003evitest-dev/vitest#10170\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/04d37e9d7\"\u003e\u003c!-- raw HTML omitted --\u003e(04d37)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDefault \u003ccode\u003eattachmentsDir\u003c/code\u003e from \u003ccode\u003e.vitest-attachements/\u003c/code\u003e to \u003ccode\u003e.vitest/attachments/\u003c/code\u003e  -  by \u003ca href=\"https://github.com/MdSadiqMd\"\u003e\u003ccode\u003e@​MdSadiqMd\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10186\"\u003evitest-dev/vitest#10186\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/1ba7338c3\"\u003e\u003c!-- raw HTML omitted --\u003e(1ba73)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove \u003ccode\u003esequential\u003c/code\u003e test/suite options in favor of \u003ccode\u003econcurrent\u003c/code\u003e  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e and \u003cstrong\u003eOpenAI Codex\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10198\"\u003evitest-dev/vitest#10198\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/9229f2edc\"\u003e\u003c!-- raw HTML omitted --\u003e(9229f)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRepresent locator as an object instead of a string  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10212\"\u003evitest-dev/vitest#10212\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/80f07edf6\"\u003e\u003c!-- raw HTML omitted --\u003e(80f07)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eInline \u003ccode\u003eexpect\u003c/code\u003e package  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10221\"\u003evitest-dev/vitest#10221\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/ad16223e7\"\u003e\u003c!-- raw HTML omitted --\u003e(ad162)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove deprecated entry points  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10222\"\u003evitest-dev/vitest#10222\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/994c6ddb9\"\u003e\u003c!-- raw HTML omitted --\u003e(994c6)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRequire Node.js 22 and Vite 6.4  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10178\"\u003evitest-dev/vitest#10178\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/3876283e8\"\u003e\u003c!-- raw HTML omitted --\u003e(38762)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail \u003ccode\u003eexpect.poll\u003c/code\u003e when function didn't resolve in time  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e and \u003cstrong\u003eOpenAI Codex\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10233\"\u003evitest-dev/vitest#10233\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/4df048c11\"\u003e\u003c!-- raw HTML omitted --\u003e(4df04)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThrow an error if hoistable methods are outside the top level scope  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10460\"\u003evitest-dev/vitest#10460\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/d0b4fddcb\"\u003e\u003c!-- raw HTML omitted --\u003e(d0b4f)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etoHaveTextContent\u003c/code\u003e is strict, add \u003ccode\u003etoMatchTextContent\u003c/code\u003e as alternative  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10473\"\u003evitest-dev/vitest#10473\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/18f303079\"\u003e\u003c!-- raw HTML omitted --\u003e(18f30)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDon't lookup config file from ancestor directories  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eOpenAI Codex\u003c/strong\u003e and \u003cstrong\u003eHiroshi Ogawa\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10428\"\u003evitest-dev/vitest#10428\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/945d9090e\"\u003e\u003c!-- raw HTML omitted --\u003e(945d9)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eInline \u003ccode\u003e@vitest/runner\u003c/code\u003e package, do not publish it anymore  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10511\"\u003evitest-dev/vitest#10511\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/6d6e46b1e\"\u003e\u003c!-- raw HTML omitted --\u003e(6d6e4)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAllow mutating happy-dom/jsdom window object  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eHiroshi Ogawa\u003c/strong\u003e and \u003cstrong\u003eOpenAI Codex\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10373\"\u003evitest-dev/vitest#10373\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/206e8cff8\"\u003e\u003c!-- raw HTML omitted --\u003e(206e8)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExpose \u003ccode\u003econcurrencyId\u003c/code\u003e/\u003ccode\u003eworkerId\u003c/code\u003e on TestModule's diagnostics, make id 1-based  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10516\"\u003evitest-dev/vitest#10516\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/bdd985433\"\u003e\u003c!-- raw HTML omitted --\u003e(bdd98)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003escreenshotDirectory\u003c/code\u003e config to \u003ccode\u003ebrowser.expect.toMatchScreenshot\u003c/code\u003e  -  by \u003ca href=\"https://github.com/macarie\"\u003e\u003ccode\u003e@​macarie\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10592\"\u003evitest-dev/vitest#10592\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/a60ded0fb\"\u003e\u003c!-- raw HTML omitted --\u003e(a60de)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@sinonjs/fake-timers\u003c/code\u003e and support mocking \u003ccode\u003eTemporal\u003c/code\u003e  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eHiroshi Ogawa\u003c/strong\u003e and \u003cstrong\u003eOpenCode (gpt-5.6-sol)\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10654\"\u003evitest-dev/vitest#10654\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/f8b1532fe\"\u003e\u003c!-- raw HTML omitted --\u003e(f8b15)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove webdriverio package  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10675\"\u003evitest-dev/vitest#10675\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/5fed68f72\"\u003e\u003c!-- raw HTML omitted --\u003e(5fed6)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eClear mocks by default before each test  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10613\"\u003evitest-dev/vitest#10613\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/0f6463bf2\"\u003e\u003c!-- raw HTML omitted --\u003e(0f646)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDon't emit localStorage warnings on Node 26, fail gracefully when worker fails to start  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10293\"\u003evitest-dev/vitest#10293\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/334edef92\"\u003e\u003c!-- raw HTML omitted --\u003e(334ed)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSeparate config resolution from the server creation  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10554\"\u003evitest-dev/vitest#10554\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/1c0ec3444\"\u003e\u003c!-- raw HTML omitted --\u003e(1c0ec)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eInline projects extend the root config by default  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10750\"\u003evitest-dev/vitest#10750\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/fec001ad3\"\u003e\u003c!-- raw HTML omitted --\u003e(fec00)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEnable mocking Temporal without fake timers  -  by \u003ca href=\"https://github.com/fabon-f\"\u003e\u003ccode\u003e@​fabon-f\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eHiroshi Ogawa\u003c/strong\u003e and \u003cstrong\u003eOpenCode (gpt-5.6-sol)\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10757\"\u003evitest-dev/vitest#10757\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/ac2d46b42\"\u003e\u003c!-- raw HTML omitted --\u003e(ac2d4)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport nested projects  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10846\"\u003evitest-dev/vitest#10846\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/ec367cf2a\"\u003e\u003c!-- raw HTML omitted --\u003e(ec367)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse \u003ccode\u003e\u0026gt;\u003c/code\u003e as separator in \u003ccode\u003e-t\u003c/code\u003e, calculate \u003ccode\u003eonly\u003c/code\u003e once  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10686\"\u003evitest-dev/vitest#10686\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/a0b20bc86\"\u003e\u003c!-- raw HTML omitted --\u003e(a0b20)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFail the test when an asynchronous assertion is not awaited  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10868\"\u003evitest-dev/vitest#10868\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/86d4a9da9\"\u003e\u003c!-- raw HTML omitted --\u003e(86d4a)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eShare the Vite server between inline projects  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10848\"\u003evitest-dev/vitest#10848\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/d87c96ee4\"\u003e\u003c!-- raw HTML omitted --\u003e(d87c9)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eParse files statically in vitest list by default  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/11088\"\u003evitest-dev/vitest#11088\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/51e949416\"\u003e\u003c!-- raw HTML omitted --\u003e(51e94)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebenchmark\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eRewrite the public API  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10113\"\u003evitest-dev/vitest#10113\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/19f6e8947\"\u003e\u003c!-- raw HTML omitted --\u003e(19f6e)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebrowser\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eIframe scale  -  by \u003ca href=\"https://github.com/macarie\"\u003e\u003ccode\u003e@​macarie\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9745\"\u003evitest-dev/vitest#9745\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/b639852cc\"\u003e\u003c!-- raw HTML omitted --\u003e(b6398)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEnable \u003ccode\u003elocators.exact\u003c/code\u003e by default  -  by \u003ca href=\"https://github.com/sheremet-va\"\u003e\u003ccode\u003e@​sheremet-va\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10430\"\u003evitest-dev/vitest#10430\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/e203202f9\"\u003e\u003c!-- raw HTML omitted --\u003e(e2032)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRequire \u003ccode\u003esessionId\u003c/code\u003e for orchestrator html request  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eHiroshi Ogawa\u003c/strong\u003e and \u003cstrong\u003eOpenAI Codex\u003c/strong\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10522\"\u003evitest-dev/vitest#10522\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/79b7d8fcc\"\u003e\u003c!-- raw HTML omitted --\u003e(79b7d)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSave failure screenshots in \u003ccode\u003eattachmentsDir\u003c/code\u003e  -  by \u003ca href=\"https://github.com/macarie\"\u003e\u003ccode\u003e@​macarie\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10917\"\u003evitest-dev/vitest#10917\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/3b5bbd8b4\"\u003e\u003c!-- raw HTML omitted --\u003e(3b5bb)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecoverage\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003einclude/exclude\u003c/code\u003e globs too eager  -  by \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9818\"\u003evitest-dev/vitest#9818\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/edacb0fd4\"\u003e\u003c!-- raw HTML omitted --\u003e(edacb)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAllow \u003ccode\u003ethresholds.perFile\u003c/code\u003e to accept an object  -  by \u003ca href=\"https://github.com/vladlenskiy\"\u003e\u003ccode\u003e@​vladlenskiy\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10190\"\u003evitest-dev/vitest#10190\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/13b78d98b\"\u003e\u003c!-- raw HTML omitted --\u003e(13b78)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eexpect\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003etoThrow(\u0026quot;\u0026quot;)\u003c/code\u003e behavior by reverting \u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/6710\"\u003e#6710\u003c/a\u003e  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/9643\"\u003evitest-dev/vitest#9643\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/6710\"\u003evitest-dev/vitest#6710\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/6c3e4bdbf\"\u003e\u003c!-- raw HTML omitted --\u003e(6c3e4)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emocker\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003eDeserialize automock as automock  -  by \u003ca href=\"https://github.com/nami8824\"\u003e\u003ccode\u003e@​nami8824\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10192\"\u003evitest-dev/vitest#10192\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/2f892712d\"\u003e\u003c!-- raw HTML omitted --\u003e(2f892)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ereporters\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eblob\u003c/code\u003e reporter and \u003ccode\u003e--merge-reports\u003c/code\u003e default to \u003ccode\u003e.vitest/blob/\u003c/code\u003e  -  by \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10232\"\u003evitest-dev/vitest#10232\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/d22b029ae\"\u003e\u003c!-- raw HTML omitted --\u003e(d22b0)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWrite json and junit reporter output files to \u003ccode\u003e.vitest\u003c/code\u003e by default  -  by \u003ca href=\"https://github.com/hi-ogawa\"\u003e\u003ccode\u003e@​hi-ogawa\u003c/code\u003e\u003c/a\u003e, \u003cstrong\u003eHiroshi Ogawa\u003c/strong\u003e, \u003cstrong\u003eOpenCode (gpt-5.6-sol)\u003c/strong\u003e and \u003ca href=\"https://github.com/AriPerkkio\"\u003e\u003ccode\u003e@​AriPerkkio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vitest-dev/vitest/issues/10621\"\u003evitest-dev/vitest#10621\u003c/a\u003e \u003ca href=\"https://github.com/vitest-dev/vitest/commit/58577290a\"\u003e\u003c!-- raw HTML omitted --\u003e(58577)\u003c!-- raw HTML omitted --\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/f441c6fab25e579c5b7dd3dd50538416f415fbae\"\u003e\u003ccode\u003ef441c6f\u003c/code\u003e\u003c/a\u003e chore: release v5.0.0 (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/11130\"\u003e#11130\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/c4473e48ee046938a9ab6784fe2735257c2c0f72\"\u003e\u003ccode\u003ec4473e4\u003c/code\u003e\u003c/a\u003e fix(coverage): prevent crash on \u003ccode\u003e/@fs/\u003c/code\u003e prepended virtual files (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/11119\"\u003e#11119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/897f51fd2493046c52ec9539b7d02fe3763bd63e\"\u003e\u003ccode\u003e897f51f\u003c/code\u003e\u003c/a\u003e chore: release v5.0.0-rc.4 (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/11107\"\u003e#11107\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/7db80dc27e5948010c00160ed0b86570baad6ce8\"\u003e\u003ccode\u003e7db80dc\u003c/code\u003e\u003c/a\u003e chore: release v5.0.0-rc.3 (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/11089\"\u003e#11089\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/5f6a5e84a5e8cef301e15ac2e8f8e9837b002ec6\"\u003e\u003ccode\u003e5f6a5e8\u003c/code\u003e\u003c/a\u003e feat(coverage): switch to \u003ccode\u003e@vitest/istanbuljs\u003c/code\u003e packages (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/11053\"\u003e#11053\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/c6174a6cf2847b23075ee35ba5151c2184a70594\"\u003e\u003ccode\u003ec6174a6\u003c/code\u003e\u003c/a\u003e fix(coverage): v8 to ignore Vite SSR's generated import bindings (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/11023\"\u003e#11023\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/af83d1b1933b5d74c421d30849717369b828de0b\"\u003e\u003ccode\u003eaf83d1b\u003c/code\u003e\u003c/a\u003e chore: release v5.0.0-rc.2 (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/10976\"\u003e#10976\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/a7fa111fef94bdc80ca9614c4e20b56f3393c920\"\u003e\u003ccode\u003ea7fa111\u003c/code\u003e\u003c/a\u003e chore: release v5.0.0-rc.1 (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/10920\"\u003e#10920\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/0553851f9f299233fbd2e797a76152e98f593ac7\"\u003e\u003ccode\u003e0553851\u003c/code\u003e\u003c/a\u003e chore: add Knip checks (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/10847\"\u003e#10847\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitest-dev/vitest/commit/b7be731900e913c5aae905af03a50fb55f23eac0\"\u003e\u003ccode\u003eb7be731\u003c/code\u003e\u003c/a\u003e chore: release v5.0.0-beta.7 (\u003ca href=\"https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8/issues/10825\"\u003e#10825\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vitest-dev/vitest/commits/v5.0.0/packages/coverage-v8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `browserslist` from 4.28.8 to 4.28.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/releases\"\u003ebrowserslist's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md\"\u003ebrowserslist's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/12ed5252dabc14fee4e97b465894b2f90910ca62\"\u003e\u003ccode\u003e12ed525\u003c/code\u003e\u003c/a\u003e Release 4.28.9 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/b1d8cf9d7a7dc76f6585425a8360218289194297\"\u003e\u003ccode\u003eb1d8cf9\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/21517b651c915cdbbfb8c122268bc36f5cabb7ef\"\u003e\u003ccode\u003e21517b6\u003c/code\u003e\u003c/a\u003e Improve \u003ccode\u003eor\u003c/code\u003e parsing performance\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/browserslist/browserslist/compare/4.28.8...4.28.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `eslint` from 10.6.0 to 10.10.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/eslint/eslint/releases\"\u003eeslint's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev10.10.0\u003c/h2\u003e\n\u003ch2\u003eFeatures\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/264b4346d1963701df0c398b4aeb2f6e8b2af93e\"\u003e\u003ccode\u003e264b434\u003c/code\u003e\u003c/a\u003e feat: add \u003ccode\u003ed\u003c/code\u003e and \u003ccode\u003ev\u003c/code\u003e flags to \u003ccode\u003eno-unexpected-multiline\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21305\"\u003e#21305\u003c/a\u003e) (Gihyeon Jeong / 정기현)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/c6cc6c592f30901345d94ef75e0d42c1894fae6c\"\u003e\u003ccode\u003ec6cc6c5\u003c/code\u003e\u003c/a\u003e feat: check \u003ccode\u003eObject.prototype\u003c/code\u003e property names in \u003ccode\u003enew-cap\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21269\"\u003e#21269\u003c/a\u003e) (crimsonjay0)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/5661fa65fde9fd4c14f0b730e3cee6a42fc657c1\"\u003e\u003ccode\u003e5661fa6\u003c/code\u003e\u003c/a\u003e feat: no-extra-bind false negatives with class fields and static blocks (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21260\"\u003e#21260\u003c/a\u003e) (synthex-byte)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/bb47dc6da2399a8f76c0c0c3273e6bc314c480e5\"\u003e\u003ccode\u003ebb47dc6\u003c/code\u003e\u003c/a\u003e fix: update dependency file-entry-cache to v11 (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/20801\"\u003e#20801\u003c/a\u003e) (Milos Djermanovic)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/427ac0a014066c36aa57fa8fa9af20fd9fb591e1\"\u003e\u003ccode\u003e427ac0a\u003c/code\u003e\u003c/a\u003e fix: use format strings in debug calls (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21247\"\u003e#21247\u003c/a\u003e) (Francesco Trotta)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/9d8153223dbf47b9aecdc1474202aaee4845f146\"\u003e\u003ccode\u003e9d81532\u003c/code\u003e\u003c/a\u003e fix: support \u003ccode\u003e__proto__\u003c/code\u003e in \u003ccode\u003e/* exported */\u003c/code\u003e comments (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21261\"\u003e#21261\u003c/a\u003e) (sethamus)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/87e0a082438264ad90b87fd74165ab4fd90f63ef\"\u003e\u003ccode\u003e87e0a08\u003c/code\u003e\u003c/a\u003e fix: prefer-object-has-own autofix breaks when Object is shadowed (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21282\"\u003e#21282\u003c/a\u003e) (김채영)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/8e2cb142217f2efee1d10dcc02bfb75145ae775d\"\u003e\u003ccode\u003e8e2cb14\u003c/code\u003e\u003c/a\u003e fix: \u003ccode\u003enew-cap\u003c/code\u003e false positive for \u003ccode\u003eUTC\u003c/code\u003e calls with \u003ccode\u003eproperties: false\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21275\"\u003e#21275\u003c/a\u003e) (Pixel)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/9f4a364ab0ade048dfce1f37792b1d461d866e55\"\u003e\u003ccode\u003e9f4a364\u003c/code\u003e\u003c/a\u003e fix: Ignore static imports in no-unreachable (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21276\"\u003e#21276\u003c/a\u003e) (Taha Kotil)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/2417cad57d7d1bc4cf3ecf0f0575cfb10ff2011c\"\u003e\u003ccode\u003e2417cad\u003c/code\u003e\u003c/a\u003e docs: Update README (GitHub Actions Bot)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/9cecb8a0a2348070abf72321965d41919c7cc626\"\u003e\u003ccode\u003e9cecb8a\u003c/code\u003e\u003c/a\u003e docs: document \u003ccode\u003e\\c\u003c/code\u003e control letter escapes in no-control-regex (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21286\"\u003e#21286\u003c/a\u003e) (한국)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/8724829f69f8ed80c876e3a5a017da199ce78739\"\u003e\u003ccode\u003e8724829\u003c/code\u003e\u003c/a\u003e docs: update compat table links (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21263\"\u003e#21263\u003c/a\u003e) (fnx)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/5634542be580750ffb1a5766470f9e9c72719696\"\u003e\u003ccode\u003e5634542\u003c/code\u003e\u003c/a\u003e docs: Clarify eqeqeq suggestion behavior (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21256\"\u003e#21256\u003c/a\u003e) (Müslüm Yılmaz)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eChores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/b3d876b46083d67899eb1d9613118c1c583632a2\"\u003e\u003ccode\u003eb3d876b\u003c/code\u003e\u003c/a\u003e chore: disable npm au...\n\n_Description has been truncated_","html_url":"https://github.com/Brooklyn20i/rodney-brain/pull/157","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Brooklyn20i%2Frodney-brain/issues/157","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/157/packages"}},{"old_version":"3.1.0","new_version":"3.1.7","update_type":"patch","path":null,"pr_created_at":"2026-09-12T23:34:53.000Z","version_change":"3.1.0 → 3.1.7","issue":{"uuid":"5436754351","node_id":"PR_kwDORRCW3s8AAAABDS0yww","number":6,"state":"open","title":"Bump fast-uri from 3.1.0 to 3.1.7","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-12T23:34:53.000Z","updated_at":"2026-09-12T23:36:53.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"fast-uri","old_version":"3.1.0","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"}],"path":null,"ecosystem":"npm"},"body":"Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.0 to 3.1.7.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.0...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=fast-uri\u0026package-manager=npm_and_yarn\u0026previous-version=3.1.0\u0026new-version=3.1.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/CallingCrow/btt-app/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/CallingCrow/btt-app/pull/6","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/CallingCrow%2Fbtt-app/issues/6","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/6/packages"}},{"old_version":"3.1.2","new_version":"3.1.7","update_type":"patch","path":null,"pr_created_at":"2026-09-12T23:24:02.000Z","version_change":"3.1.2 → 3.1.7","issue":{"uuid":"5436705271","node_id":"PR_kwDOUYYxZs8AAAABDSySQQ","number":1,"state":"closed","title":"build(deps): bump the npm_and_yarn group across 1 directory with 11 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-12T23:24:46.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-12T23:24:02.000Z","updated_at":"2026-09-12T23:24:48.000Z","time_to_close":44,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"npm_and_yarn","update_count":11,"packages":[{"name":"next","old_version":"16.2.6","new_version":"16.3.5","repository_url":"https://github.com/vercel/next.js"},{"name":"vite","old_version":"8.0.13","new_version":"8.3.0","repository_url":"https://github.com/vitejs/vite"},{"name":"@babel/core","old_version":"7.29.0","new_version":"7.29.7","repository_url":"https://github.com/babel/babel"},{"name":"brace-expansion","old_version":"1.1.14","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"fast-uri","old_version":"3.1.2","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"js-yaml","old_version":"4.1.1","new_version":"4.3.2","repository_url":"https://github.com/nodeca/js-yaml"},{"name":"sharp","old_version":"0.34.5","new_version":"0.35.4","repository_url":"https://github.com/lovell/sharp"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 7 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [next](https://github.com/vercel/next.js) | `16.2.6` | `16.3.5` |\n| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.0.13` | `8.3.0` |\n| [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) | `7.29.0` | `7.29.7` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.14` | `1.1.18` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.2` | `3.1.7` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.1` | `4.3.2` |\n| [sharp](https://github.com/lovell/sharp) | `0.34.5` | `0.35.4` |\n\n\nUpdates `next` from 16.2.6 to 16.3.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003enext's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.5\u003c/h2\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does not include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003enext/image: Skip 0-byte entries when initializing disk LRU cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98185\"\u003e#98185\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enext/image: Reject empty images when reading/writing to the disk cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98186\"\u003e#98186\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEmit whole-app server NFTs when \u003ccode\u003eoutput: 'standalone'\u003c/code\u003e is used with an adapter (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98167\"\u003e#98167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd CSP nonce to script tags of loading and template files (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98403\"\u003e#98403\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003euse cache\u003c/code\u003e prerender signal retention (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98448\"\u003e#98448\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.4\u003c/h2\u003e\n\u003cp\u003eFollow-up release to \u003ca href=\"https://github.com/vercel/next.js/releases/tag/v16.3.3\"\u003ev16.3.3\u003c/a\u003e re-enabling AVIF Image Optimization (\u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97949\"\u003e#97949\u003c/a\u003e).\u003c/p\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003etestmode: Fix infinite recursion in testmode passthrough fetch (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97691\"\u003e#97691\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix build error when aliasing typescript to \u003ccode\u003e@​typescript/typescript6\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97997\"\u003e#97997\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix unset crossOrigin in Turbopack manifests (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97930\"\u003e#97930\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.3\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eCritical:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36\"\u003eUnauthenticated Remote Code Execution on windows-hosted servers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4\"\u003eUnauthenticated Remote Code Execution in Image Optimization API when AVIF files are used\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.2\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Scope app-entry export validation to files inside the app directory (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97357\"\u003e#97357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[backport] Fix catch-all index page being served for every other slug (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97416\"\u003e#97416\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: don't trace embedded WASM loader helpers (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97353\"\u003e#97353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97463\"\u003e#97463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: retain conditions when replacing resolve request keys (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97453\"\u003e#97453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Fix Turbopack worker chunk loading with asset prefix (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97419\"\u003e#97419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97603\"\u003e#97603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/lubieowoce\"\u003e\u003ccode\u003e@​lubieowoce\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[16.x] Turbopack: don't strip async-module runtime from shared runtime chunks by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96653\"\u003evercel/next.js#96653\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/ca2c75eb7f8d9dd012a8bb83c06132149fe221f9\"\u003e\u003ccode\u003eca2c75e\u003c/code\u003e\u003c/a\u003e v16.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/14fb290de65077e9f1e22ef56d8de6cc1e63d436\"\u003e\u003ccode\u003e14fb290\u003c/code\u003e\u003c/a\u003e [backport] Fix use cache prerender signal retention (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98448\"\u003e#98448\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/2b1f28dbe1de344807ec0946a85171bc890a6047\"\u003e\u003ccode\u003e2b1f28d\u003c/code\u003e\u003c/a\u003e [16.3.x] Add CSP nonce to script tags of loading and template files (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98403\"\u003e#98403\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/4b56cee3f01d3b249edcd798b51895d5126a4170\"\u003e\u003ccode\u003e4b56cee\u003c/code\u003e\u003c/a\u003e [16.3.x] Backport docs fixes (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98317\"\u003e#98317\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/5568a02a7d47f9cb088e58350f2c2e68d9e93a00\"\u003e\u003ccode\u003e5568a02\u003c/code\u003e\u003c/a\u003e [backport] docs: local development: Rewrite docker section, add Windows Dev D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/93249ab2144132abfd4a8d611dad5b5978107ee2\"\u003e\u003ccode\u003e93249ab\u003c/code\u003e\u003c/a\u003e [16.3.X] Emit whole-app server NFTs when \u003ccode\u003eoutput: 'standalone'\u003c/code\u003e is used with ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/6549fd7c4e15a8883b0ad1c2ef67dec287a44f12\"\u003e\u003ccode\u003e6549fd7\u003c/code\u003e\u003c/a\u003e [16.3.x] next/image: reject empty image on read/write to disk cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98186\"\u003e#98186\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/d9eac96e7526ff0b9cb51db9801f06e741fe1960\"\u003e\u003ccode\u003ed9eac96\u003c/code\u003e\u003c/a\u003e [16.3.x] next/image: skip 0-byte entries when initializing disk LRU cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/9\"\u003e#9\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/84b35feccb2b53a563e41ad2dfe7a5fe08c58d3f\"\u003e\u003ccode\u003e84b35fe\u003c/code\u003e\u003c/a\u003e [test] Fix 16.3 deploy test assertions (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98133\"\u003e#98133\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/14f9c1ac4e084a44633c354476ddeaf70969cd90\"\u003e\u003ccode\u003e14f9c1a\u003c/code\u003e\u003c/a\u003e [16.3.x][ci] Run flake detection and new deploy tests when merged and on back...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/compare/v16.2.6...v16.3.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `vite` from 8.0.13 to 8.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/releases\"\u003evite's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ecreate-vite@8.3.0\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/create-vite@8.3.0/packages/create-vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev8.3.0\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e avoid settling seen preload dependencies for performance (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23446\"\u003e#23446\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/e6f6b3e3119256daa837b2dc399058c8aa45b470\"\u003ee6f6b3e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ehandle CRLF line endings in code frame positions (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23219\"\u003e#23219\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/9913672bee9c34a2df7fff4c2538783cd4f43b4e\"\u003e9913672\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eonly treat whole \u003ccode\u003enode_modules\u003c/code\u003e path segments as dependencies (fix \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/17467\"\u003e#17467\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23437\"\u003e#23437\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/ef0dc17ada53d1169ae5a89cb8f6482831466755\"\u003eef0dc17\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance Improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eproxy:\u003c/strong\u003e pre-compile context matchers at server creation (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23263\"\u003e#23263\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8abf700eeb2411d8402d08f8e2696effafdbe774\"\u003e8abf700\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev8.3.0-beta.1\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003edevtools:\u003c/strong\u003e enable dev server integration (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23333\"\u003e#23333\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/68aeb8a3b5a5a2ccd505288999bae1a5e6942ee1\"\u003e68aeb8a\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e keep hash placeholders as-is in \u003ccode\u003eresolveFileUrl\u003c/code\u003e hook (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23422\"\u003e#23422\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/e8d6a4d3399c739772080d70c7f3c4d548a637c9\"\u003ee8d6a4d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebundled-dev:\u003c/strong\u003e mark payload delivered on client report (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23373\"\u003e#23373\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/a6d43bc9e3464faa4d49f090e75e1ab334ffb7b0\"\u003ea6d43bc\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update all non-major dependencies (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23445\"\u003e#23445\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/fc7c104e74d35a97fa313d5dd6f1b5e7d5b26159\"\u003efc7c104\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ehtml:\u003c/strong\u003e don't inline preload link targets (fix \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/13355\"\u003e#13355\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23387\"\u003e#23387\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/12e709ca4df1059747db1cb7c5d1cd71aba79a24\"\u003e12e709c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eresolve the actual package root in findNearestMainPackageData for nested package.json (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23356\"\u003e#23356\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8492422b8f110625a90c702f42f30784e8cf19dc\"\u003e8492422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eshortcuts extend error (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23447\"\u003e#23447\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/4ec58d159df4a1b4799356a1fda62db88ed14752\"\u003e4ec58d1\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMiscellaneous Chores\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eintroducing \u003ccode\u003e@e18e/eslint-plugin\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23357\"\u003e#23357\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/f79413353995a2344879014410a9128b1b9f8e9a\"\u003ef794133\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eremove unnecessary comment (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23448\"\u003e#23448\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/b919a1a8b5a7c694667f993d677973f42d349458\"\u003eb919a1a\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev8.3.0-beta.0\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eaccept Rolldown watch options in \u003ccode\u003eserver.watch\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23133\"\u003e#23133\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/1b5cfe3d3777d4ceb7f35fcee9d3c4279316a084\"\u003e1b5cfe3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd closeServer and closePreviewServer hooks (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23110\"\u003e#23110\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/e17d2d565b0288f169c7995adb2b192f917548e7\"\u003ee17d2d5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd top-level \u003ccode\u003etsconfig\u003c/code\u003e option (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23310\"\u003e#23310\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/93164c3530a7b4fc7bbedfb986d6afa9546cdef3\"\u003e93164c3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd warning for unsupported hooks in plugin returned from \u003ccode\u003eapplyToEnvironment\u003c/code\u003e hook (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23191\"\u003e#23191\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/fdef04f112aadfea40ad3c448d96a49a04c168bd\"\u003efdef04f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecli:\u003c/strong\u003e support naming the CPU profile via --profile [name] (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23042\"\u003e#23042\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/a500deeb6f52d93ca501a0fc612a5392b939f2f5\"\u003ea500dee\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003econfig:\u003c/strong\u003e warn on named imports from JSON modules (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23378\"\u003e#23378\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/472385e6ec4b21e3167c7abf9769883d1c9675f8\"\u003e472385e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecss:\u003c/strong\u003e minify style tag (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23183\"\u003e#23183\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8156684572bdcf73e9d8568ed67971f0467fab60\"\u003e8156684\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esearched params attached to workers are now preserved (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22280\"\u003e#22280\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/517b97f57ab9473e7417da856eb641d76870a56e\"\u003e517b97f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport subpath imports in dynamic import statements (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23185\"\u003e#23185\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/b78e2f1bc1cba404c4bd9faf518d26ec85e89fc7\"\u003eb78e2f1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003eimport.meta.ROLLDOWN_FILE_URL_*\u003c/code\u003e for assets in JS (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22888\"\u003e#22888\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/4366ac468343252df6d5706361a6348afa66f9cc\"\u003e4366ac4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003eimport.meta.ROLLDOWN_FILE_URL_*\u003c/code\u003e for other plugins (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22894\"\u003e#22894\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/e38f29ee48bea5ea3178faec5b78708e86f38afb\"\u003ee38f29e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md\"\u003evite's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v8.2.2...v8.3.0\"\u003e8.3.0\u003c/a\u003e (2026-09-10)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e avoid settling seen preload dependencies for performance (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23446\"\u003e#23446\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/e6f6b3e3119256daa837b2dc399058c8aa45b470\"\u003ee6f6b3e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edevtools:\u003c/strong\u003e enable dev server integration (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23333\"\u003e#23333\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/68aeb8a3b5a5a2ccd505288999bae1a5e6942ee1\"\u003e68aeb8a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eaccept Rolldown watch options in \u003ccode\u003eserver.watch\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23133\"\u003e#23133\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/1b5cfe3d3777d4ceb7f35fcee9d3c4279316a084\"\u003e1b5cfe3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd closeServer and closePreviewServer hooks (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23110\"\u003e#23110\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/e17d2d565b0288f169c7995adb2b192f917548e7\"\u003ee17d2d5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd top-level \u003ccode\u003etsconfig\u003c/code\u003e option (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23310\"\u003e#23310\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/93164c3530a7b4fc7bbedfb986d6afa9546cdef3\"\u003e93164c3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd warning for unsupported hooks in plugin returned from \u003ccode\u003eapplyToEnvironment\u003c/code\u003e hook (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23191\"\u003e#23191\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/fdef04f112aadfea40ad3c448d96a49a04c168bd\"\u003efdef04f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecli:\u003c/strong\u003e support naming the CPU profile via --profile [name] (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23042\"\u003e#23042\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/a500deeb6f52d93ca501a0fc612a5392b939f2f5\"\u003ea500dee\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003econfig:\u003c/strong\u003e warn on named imports from JSON modules (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23378\"\u003e#23378\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/472385e6ec4b21e3167c7abf9769883d1c9675f8\"\u003e472385e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecss:\u003c/strong\u003e minify style tag (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23183\"\u003e#23183\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8156684572bdcf73e9d8568ed67971f0467fab60\"\u003e8156684\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esearched params attached to workers are now preserved (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22280\"\u003e#22280\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/517b97f57ab9473e7417da856eb641d76870a56e\"\u003e517b97f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport subpath imports in dynamic import statements (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23185\"\u003e#23185\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/b78e2f1bc1cba404c4bd9faf518d26ec85e89fc7\"\u003eb78e2f1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003eimport.meta.ROLLDOWN_FILE_URL_*\u003c/code\u003e for assets in JS (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22888\"\u003e#22888\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/4366ac468343252df6d5706361a6348afa66f9cc\"\u003e4366ac4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003eimport.meta.ROLLDOWN_FILE_URL_*\u003c/code\u003e for other plugins (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22894\"\u003e#22894\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/e38f29ee48bea5ea3178faec5b78708e86f38afb\"\u003ee38f29e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eworker:\u003c/strong\u003e remove worker chunk if it's detected that it's not referenced (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22473\"\u003e#22473\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/924997a4bdda9115faee9bdb622fcec4fc8357f0\"\u003e924997a\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ehandle CRLF line endings in code frame positions (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23219\"\u003e#23219\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/9913672bee9c34a2df7fff4c2538783cd4f43b4e\"\u003e9913672\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eonly treat whole \u003ccode\u003enode_modules\u003c/code\u003e path segments as dependencies (fix \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/17467\"\u003e#17467\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23437\"\u003e#23437\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/ef0dc17ada53d1169ae5a89cb8f6482831466755\"\u003eef0dc17\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebuild:\u003c/strong\u003e keep hash placeholders as-is in \u003ccode\u003eresolveFileUrl\u003c/code\u003e hook (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23422\"\u003e#23422\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/e8d6a4d3399c739772080d70c7f3c4d548a637c9\"\u003ee8d6a4d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebundled-dev:\u003c/strong\u003e mark payload delivered on client report (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23373\"\u003e#23373\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/a6d43bc9e3464faa4d49f090e75e1ab334ffb7b0\"\u003ea6d43bc\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update all non-major dependencies (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23445\"\u003e#23445\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/fc7c104e74d35a97fa313d5dd6f1b5e7d5b26159\"\u003efc7c104\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ehtml:\u003c/strong\u003e don't inline preload link targets (fix \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/13355\"\u003e#13355\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23387\"\u003e#23387\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/12e709ca4df1059747db1cb7c5d1cd71aba79a24\"\u003e12e709c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eresolve the actual package root in findNearestMainPackageData for nested package.json (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23356\"\u003e#23356\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8492422b8f110625a90c702f42f30784e8cf19dc\"\u003e8492422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eshortcuts extend error (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23447\"\u003e#23447\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/4ec58d159df4a1b4799356a1fda62db88ed14752\"\u003e4ec58d1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003econfig:\u003c/strong\u003e close bundles when generation fails (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23256\"\u003e#23256\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/6bacc956df5a76cc5653b9de4493453b953439fd\"\u003e6bacc95\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ecss:\u003c/strong\u003e keep newline-separated srcset candidates intact (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23265\"\u003e#23265\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/4f9d2f4dadc83191200de7d2154c957a711e8c3d\"\u003e4f9d2f4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update all non-major dependencies (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23337\"\u003e#23337\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/d55081581ddd4d55667fef38e85d02ab7f879f15\"\u003ed550815\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update all non-major dependencies (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23404\"\u003e#23404\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/238ad811c7fb9e4730cbd317d0657867ed3447b3\"\u003e238ad81\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update rolldown-related dependencies (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23338\"\u003e#23338\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/76e8082c56a2872dc8017c5672bc36cba8dcf75d\"\u003e76e8082\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e update rolldown-related dependencies (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23405\"\u003e#23405\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/b88256607e3a051b7bcb0b338b3c4665926b55a8\"\u003eb882566\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edev:\u003c/strong\u003e run closeBundle after buildEnd failure (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23165\"\u003e#23165\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8cb872e7fb65b03f6068923c6aa7fcf3e71baf21\"\u003e8cb872e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ehmr:\u003c/strong\u003e handle \u003ccode\u003eimport.meta.hot.invalidate\u003c/code\u003e in virtual module (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23171\"\u003e#23171\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/616296895bd135386d35069a479a5f188c7de298\"\u003e6162968\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eutils:\u003c/strong\u003e handle dot in srcset density descriptor (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23346\"\u003e#23346\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/b50e1b4a3d66128a4076e19769b2e29657985516\"\u003eb50e1b4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eutils:\u003c/strong\u003e match timestamp query parameter with proper delimiters (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23364\"\u003e#23364\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/41f3c6fff88ade015669cac5c42db946e0b6f5c9\"\u003e41f3c6f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance Improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eproxy:\u003c/strong\u003e pre-compile context matchers at server creation (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23263\"\u003e#23263\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8abf700eeb2411d8402d08f8e2696effafdbe774\"\u003e8abf700\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMiscellaneous Chores\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eintroducing \u003ccode\u003e@e18e/eslint-plugin\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23357\"\u003e#23357\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/f79413353995a2344879014410a9128b1b9f8e9a\"\u003ef794133\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eremove unnecessary comment (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23448\"\u003e#23448\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/b919a1a8b5a7c694667f993d677973f42d349458\"\u003eb919a1a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edelete unused \u003ccode\u003ePluginContainerOptions\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23382\"\u003e#23382\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/ee644014aab61e546742b862a7d7b0d6c7d67a7b\"\u003eee64401\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse oxfmt \u003ccode\u003esortImports\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/23319\"\u003e#23319\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/97ad042170f4c71b518239723b733dd98e8e3e76\"\u003e97ad042\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/95e8923f35d0252c9f6eb2d5e358c084542706f1\"\u003e\u003ccode\u003e95e8923\u003c/code\u003e\u003c/a\u003e release: v7.3.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/9d39d373a7b4e0a93322b70b9dbeb202af06af3e\"\u003e\u003ccode\u003e9d39d37\u003c/code\u003e\u003c/a\u003e feat: add \u003ccode\u003eignoreOutdatedRequests\u003c/code\u003e option to \u003ccode\u003eoptimizeDeps\u003c/code\u003e (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/21364\"\u003e#21364\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/acf7e05eaeb18e98f5e19e2d3e648950726f20d1\"\u003e\u003ccode\u003eacf7e05\u003c/code\u003e\u003c/a\u003e release: v7.3.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/cff26ec0fc13373d7125a5eac6cb01fe63fee4b1\"\u003e\u003ccode\u003ecff26ec\u003c/code\u003e\u003c/a\u003e feat(deps): update esbuild from ^0.25.0 to ^0.27.0 (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/21183\"\u003e#21183\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/317b3b272f9ef6faa647a51ab3b0768fecc1071d\"\u003e\u003ccode\u003e317b3b2\u003c/code\u003e\u003c/a\u003e release: v7.2.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/721f16343d9555ae8fc71a2e5354b22e12ff0dc3\"\u003e\u003ccode\u003e721f163\u003c/code\u003e\u003c/a\u003e fix: plugin shortcut support (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/21211\"\u003e#21211\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/bda5dbb648fa7cf877ea9c76ba8a7da226b65cce\"\u003e\u003ccode\u003ebda5dbb\u003c/code\u003e\u003c/a\u003e release: v7.2.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/3aa7527fb4fc7dafe3ab57c41d637d2985c7bb6e\"\u003e\u003ccode\u003e3aa7527\u003c/code\u003e\u003c/a\u003e release: v7.2.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/72e398a46d8d2f54fbcbeb9ff0dceab346aeb642\"\u003e\u003ccode\u003e72e398a\u003c/code\u003e\u003c/a\u003e fix(deps): update all non-major dependencies (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/21175\"\u003e#21175\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/3765f7baea36234bf3816eeed38776d27bfd3649\"\u003e\u003ccode\u003e3765f7b\u003c/code\u003e\u003c/a\u003e fix: shortcuts not rebound after server restart (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/21166\"\u003e#21166\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vitejs/vite/commits/create-vite@8.3.0/packages/vite\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@babel/core` from 7.29.0 to 7.29.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/babel/babel/releases\"\u003e@​babel/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.7 (2026-05-25)\u003c/h2\u003e\n\u003cp\u003eRe-release all packages with npm provenance attestations\u003c/p\u003e\n\u003ch2\u003ev7.29.6 (2026-05-25)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18014\"\u003e#18014\u003c/a\u003e Catchup source map position in preserveFormat (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18001\"\u003e#18001\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e, \u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17998\"\u003e#17998\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 3\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMateusz Burzyński (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.5 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:house:  Internal\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@babel/*\u003c/code\u003e dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.4 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17974\"\u003e#17974\u003c/a\u003e [7.x backport]fix(systemjs): improve module string name support (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 1\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.3 (2026-04-30)\u003c/h2\u003e\n\u003ch4\u003e:eyeglasses: Spec Compliance\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17923\"\u003e#17923\u003c/a\u003e Support flow extends bound (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-helper-create-class-features-plugin\u003c/code\u003e, \u003ccode\u003ebabel-plugin-proposal-decorators\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17931\"\u003e#17931\u003c/a\u003e fix(decorators): replace super within all removed static elements (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-register\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17915\"\u003e#17915\u003c/a\u003e Fix thread synchronization issues in \u003ccode\u003e@babel/register\u003c/code\u003e (\u003ca href=\"https://github.com/liuxingbaoyu\"\u003e\u003ccode\u003e@​liuxingbaoyu\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-compat-data\u003c/code\u003e, \u003ccode\u003ebabel-plugin-bugfix-safari-rest-destructuring-rhs-array\u003c/code\u003e, \u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17788\"\u003e#17788\u003c/a\u003e Add bugfix plugin for Safari array rest destructuring bug (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:nail_care: Polish\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/4fba7541180bf5f58256d8e358b544e3831ad090\"\u003e\u003ccode\u003e4fba754\u003c/code\u003e\u003c/a\u003e v7.29.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/04ea6b27fdac8f40c3481aec2080ac9678779509\"\u003e\u003ccode\u003e04ea6b2\u003c/code\u003e\u003c/a\u003e v7.29.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/99f498a9b9fa0b900d603fbe8f6601bb3b9e42bb\"\u003e\u003ccode\u003e99f498a\u003c/code\u003e\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/18001\"\u003e#18001\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/feba0a3654c596bd369d1ef1231f5d56666d56dc\"\u003e\u003ccode\u003efeba0a3\u003c/code\u003e\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17998\"\u003e#17998\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/babel/babel/commits/v7.29.7/packages/babel-core\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.14 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24\"\u003e\u003ccode\u003e2203f4f\u003c/code\u003e\u003c/a\u003e 1.1.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd\"\u003e\u003ccode\u003e0b09384\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-uri` from 3.1.2 to 3.1.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `js-yaml` from 4.1.1 to 4.3.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md\"\u003ejs-yaml's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.3.2 - 2026-08-26\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Hard-limit merge sequence size to 100.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Count empty mappings in merge sequences toward \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e\nto limit CPU usage, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/797\"\u003e#797\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.3.1 - 2026-07-31\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Remove quadratic complexity from \u003ccode\u003e!!omap\u003c/code\u003e duplicate key detection.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.3.0 - 2026-06-27\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Added \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e (10000) loader option to limit the total number of\nkeys processed by YAML merge (\u003ccode\u003e\u0026lt;\u0026lt;\u003c/code\u003e) across one \u003ccode\u003eload()\u003c/code\u003e / \u003ccode\u003eloadAll()\u003c/code\u003e call.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRestore umd builds back to es5.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRemoved\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e replaced with \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e for limiting YAML merge\nprocessing.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[4.2.0] - 2026-06-01\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003edocs/safety.md\u003c/code\u003e with notes about processing untrusted YAML.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003emaxDepth\u003c/code\u003e (100) loader option. Not a problem, but gives a better\nexception instead of RangeError on stack overflow.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e (20) loader option. Not a problem after \u003ccode\u003emerge\u003c/code\u003e fix,\nbut an additional restriction for safety.\u003c/li\u003e\n\u003cli\u003eAdded sourcemaps to \u003ccode\u003edist/\u003c/code\u003e builds.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStop resolving numbers with underscores as numeric scalars, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/627\"\u003e#627\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eSwitched dev toolchains to Vite / neostandard.\u003c/li\u003e\n\u003cli\u003eUpdated demo.\u003c/li\u003e\n\u003cli\u003eReorganized tests.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edist/\u003c/code\u003e files are no longer kept in the repository.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix parsing of properties on the first implicit block mapping key, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/62\"\u003e#62\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix trailing whitespace handling when folding flow scalar lines, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/307\"\u003e#307\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eReject top-level block scalars without content indentation, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/280\"\u003e#280\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eEnsure numbers survive round-trip, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/737\"\u003e#737\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix test coverage for issue \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/221\"\u003e#221\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFix flow scalar trailing whitespace folding, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/307\"\u003e#307\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/79ca68d90f333fbe6d9e42827527e62636200191\"\u003e\u003ccode\u003e79ca68d\u003c/code\u003e\u003c/a\u003e 4.3.2 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/d90b6612a5a84385bdcb556c44578eac76dc0f6b\"\u003e\u003ccode\u003ed90b661\u003c/code\u003e\u003c/a\u003e Backport merge limits from v5.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/86e91b815b8794c3c73a179c1770871e37ec2df8\"\u003e\u003ccode\u003e86e91b8\u003c/code\u003e\u003c/a\u003e 4.3.1 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/c3cc4b0bb9ddb9af2dd9b61e0d56f5ce7983cd4a\"\u003e\u003ccode\u003ec3cc4b0\u003c/code\u003e\u003c/a\u003e Backport quadratic complexity fix for !!omap\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/33d05b5d29a8c21360f620f7e1c1706e24522eda\"\u003e\u003ccode\u003e33d05b5\u003c/code\u003e\u003c/a\u003e 4.3.0 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/663bfab6db2b4a146a9366fd685f069345be4ddb\"\u003e\u003ccode\u003e663bfab\u003c/code\u003e\u003c/a\u003e Drop demo publish, to not override new v5 one.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/1cb8c7b94bf75e15116869c1c0482dcb22785986\"\u003e\u003ccode\u003e1cb8c7b\u003c/code\u003e\u003c/a\u003e Add v4-legacy tag for publish\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/02f27afad532763263cd2b6be35c24ee8e1f6157\"\u003e\u003ccode\u003e02f27af\u003c/code\u003e\u003c/a\u003e Restore umd builds back to es5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/8be84edaf15e7c394fa3b813179d1bcc280e87fb\"\u003e\u003ccode\u003e8be84ed\u003c/code\u003e\u003c/a\u003e Fix es5 compatibility\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/59423c6f8cdc78742ac00e25a4dd39ef16b702e4\"\u003e\u003ccode\u003e59423c6\u003c/code\u003e\u003c/a\u003e Replace \u003ccode\u003emaxMergeSeqLength\u003c/code\u003e option with \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e (more robust). Ba...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodeca/js-yaml/compare/4.1.1...4.3.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.4.31 to 8.5.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003epostcss-scss\u003c/code\u003e commend regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed reading any file via user-generated CSS.\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eopts.unsafeMap\u003c/code\u003e to disable checks.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed nested brackets parsing performance (by \u003ca href=\"https://github.com/offset\"\u003e\u003ccode\u003e@​offset\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.10\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed XSS via unescaped \u003ccode\u003e\u0026lt;/style\u0026gt;\u003c/code\u003e in non-bundler cases (by \u003ca href=\"https://github.com/TharVid\"\u003e\u003ccode\u003e@​TharVid\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom syntax regression (by \u003ca href=\"https://github.com/43081j\"\u003e\u003ccode\u003e@​43081j\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.13\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8\"\u003e\u003ccode\u003e7beca13\u003c/code\u003e\u003c/a\u003e Does no load source map file without opts.from\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/decea51421682341401575b3740709fda0e12930\"\u003e\u003ccode\u003edecea51\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/c18e30d126395d42a0726aa00e03a8f1088985ae\"\u003e\u003ccode\u003ec18e30d\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/98a39ad73d163a90be924d5126c771262110f1fc\"\u003e\u003ccode\u003e98a39ad\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/a3e48c492ddec0e4879d513b8b995fee887af352\"\u003e\u003ccode\u003ea3e48c4\u003c/code\u003e\u003c/a\u003e Release 8.5.22 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f49d6911795f53b2cfe023bb686bf1144ec30618\"\u003e\u003ccode\u003ef49d691\u003c/code\u003e\u003c/a\u003e Fix custom property losing its semicolon before a comment (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2117\"\u003e#2117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/28e0daf8f2fe5ba9e19ea3f8c27c8fe176f9419e\"\u003e\u003ccode\u003e28e0daf\u003c/code\u003e\u003c/a\u003e Release 8.5.21 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3d2b4e43e38274f233b5609d09687cadad8215d9\"\u003e\u003ccode\u003e3d2b4e4\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.4.31...8.5.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `sharp` from 0.34.5 to 0.35.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lovell/sharp/releases\"\u003esharp's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.35.4\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\"\u003ehttps://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.35.4-rc.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpgrade to libvips v8.18.6 for upstream bug fixes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7f1a0a22cc285fe180766f4935d50b55af6e8432\"\u003e\u003ccode\u003e7f1a0a2\u003c/code\u003e\u003c/a\u003e Release v0.35.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/f927818924bc5a9493d822a4e8b23ec5857c52e1\"\u003e\u003ccode\u003ef927818\u003c/code\u003e\u003c/a\u003e Upgrade to sharp-libvips v1.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e80209240d005c71e1173a50dd9cd4db4ce2a9e6\"\u003e\u003ccode\u003ee802092\u003c/code\u003e\u003c/a\u003e Prerelease v0.35.4-rc.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e13eb2f97a0a22f1ef726e8d0cd33f7c56835945\"\u003e\u003ccode\u003ee13eb2f\u003c/code\u003e\u003c/a\u003e CI: Fix wasm32 build (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4589\"\u003e#4589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/a82a0b3d58bc25854ad1e925e6eb0a50725d1489\"\u003e\u003ccode\u003ea82a0b3\u003c/code\u003e\u003c/a\u003e Upgrade to libvips v8.18.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/8044fe43e36d0ea7f8beb89f79a37bb0f3342e84\"\u003e\u003ccode\u003e8044fe4\u003c/code\u003e\u003c/a\u003e Bound resize dimensions to coordinate limit\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/147f8591a153bc4a1e199c3fe3150fac2931b30c\"\u003e\u003ccode\u003e147f859\u003c/code\u003e\u003c/a\u003e Docs: changelog entries for \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4578\"\u003e#4578\u003c/a\u003e \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ee5bfb853de75a611c64381783b04032a3a897d8\"\u003e\u003ccode\u003eee5bfb8\u003c/code\u003e\u003c/a\u003e Tests: use yauzl directly rather than via extract-zip wrapper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7a7788928f8a2a429f45039010a87cee35401694\"\u003e\u003ccode\u003e7a77889\u003c/code\u003e\u003c/a\u003e Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4588\"\u003e#4588\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ea5bef24c187b2c7ee3fe3cad3b45c8cb67a46fd\"\u003e\u003ccode\u003eea5bef2\u003c/code\u003e\u003c/a\u003e Improve support for input Streams finishing before output is requested (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/lovell/sharp/compare/v0.34.5...v0.35.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.24.8 to 7.29.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.28.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e7 security advisories\u003c/strong\u003e, all shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 7.28.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^7.28.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe v7 line is \u003cstrong\u003enot\u003c/strong\u003e affected by GHSA-38rv-x7px-6hhq (CVE-2026-9675), which is\nan 8.x-only regression.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on GHSA-hm92-r4w5-c3mj:\u003c/strong\u003e this fix shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e, not the\nearlier 7.2x line — the vulnerable single-pool code was still present through\n\u003ccode\u003ev7.27.2\u003c/code\u003e. The per-origin pool fix is\n\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5041\"\u003e#5041\u003c/a\u003e).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAdvisory\u003c/th\u003e\n\u003cth\u003eCVE\u003c/th\u003e\n\u003cth\u003eSeverity (CVSS)\u003c/th\u003e\n\u003cth\u003eFixed in\u003c/th\u003e\n\u003cth\u003eFix commit\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-12151\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8cb10f98\"\u003e\u003ccode\u003e8cb10f98\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g\"\u003eGHSA-vmh5-mc38-953g\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9697\u003c/td\u003e\n\u003ctd\u003eHigh (7.4)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/04201f89\"\u003e\u003ccode\u003e04201f89\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj\"\u003eGHSA-hm92-r4w5-c3mj\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6734\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6\"\u003eGHSA-pr7r-676h-xcf6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9678\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/85a24055\"\u003e\u003ccode\u003e85a24055\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv\"\u003eGHSA-p88m-4jfj-68fv\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9679\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m\"\u003eGHSA-g8m3-5g58-fq7m\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-11525\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52\"\u003eGHSA-35p6-xmwp-9g52\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6733\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ea8930cf\"\u003e\u003ccode\u003eea8930cf\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493...\n\n_Description has been truncated_","html_url":"https://github.com/franklinburrus/thefileswithdub/pull/1","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/franklinburrus%2Fthefileswithdub/issues/1","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1/packages"}},{"old_version":"3.1.5","new_version":"3.1.7","update_type":"patch","path":null,"pr_created_at":"2026-09-12T20:33:51.000Z","version_change":"3.1.5 → 3.1.7","issue":{"uuid":"5435847057","node_id":"PR_kwDOQfaW688AAAABDSHh_Q","number":42,"state":"closed","title":"build(deps): bump the npm_and_yarn group across 2 directories with 7 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-12T21:06:17.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-12T20:33:51.000Z","updated_at":"2026-09-12T21:06:19.000Z","time_to_close":1946,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"npm_and_yarn","update_count":7,"packages":[{"name":"js-yaml","old_version":"3.15.1","new_version":"3.15.2","repository_url":"https://github.com/nodeca/js-yaml"},{"name":"adm-zip","old_version":"0.5.18","new_version":"0.6.1","repository_url":"https://github.com/cthackers/adm-zip"},{"name":"fast-uri","old_version":"3.1.5","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"postcss-selector-parser","old_version":"6.1.2","new_version":"6.1.4","repository_url":"https://github.com/postcss/postcss-selector-parser"},{"name":"postcss-selector-parser","old_version":"7.1.1","new_version":"7.1.6","repository_url":"https://github.com/postcss/postcss-selector-parser"},{"name":"svgo","old_version":"3.3.4","new_version":"3.3.5","repository_url":"https://github.com/svg/svgo"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 5 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `3.15.1` | `3.15.2` |\n| [adm-zip](https://github.com/cthackers/adm-zip) | `0.5.18` | `0.6.1` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.5` | `3.1.7` |\n| [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) | `6.1.2` | `6.1.4` |\n| [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) | `7.1.1` | `7.1.6` |\n| [svgo](https://github.com/svg/svgo) | `3.3.4` | `3.3.5` |\n\nBumps the npm_and_yarn group with 3 updates in the /docs directory: [js-yaml](https://github.com/nodeca/js-yaml), [svgo](https://github.com/svg/svgo) and [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro).\n\nUpdates `js-yaml` from 3.15.1 to 3.15.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md\"\u003ejs-yaml's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.15.2 - 2026-08-26\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Hard-limit merge sequence size to 100.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Count empty mappings in merge sequences toward \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e\nto limit CPU usage, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/797\"\u003e#797\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/5c45bd6e960603c13644f5cc8b572ca257723b36\"\u003e\u003ccode\u003e5c45bd6\u003c/code\u003e\u003c/a\u003e 3.15.2 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/5a708f9f4f22e78b87ebe363848cfa4fa4818c0d\"\u003e\u003ccode\u003e5a708f9\u003c/code\u003e\u003c/a\u003e dist rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/3485bc06ff8a0251505f44a00414d90df2466639\"\u003e\u003ccode\u003e3485bc0\u003c/code\u003e\u003c/a\u003e Backport merge limits from v5.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/f34812f1cea794f8c21e0a4e1f3a2584b720f305\"\u003e\u003ccode\u003ef34812f\u003c/code\u003e\u003c/a\u003e Update .gitignore\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodeca/js-yaml/compare/3.15.1...3.15.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `adm-zip` from 0.5.18 to 0.6.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cthackers/adm-zip/releases\"\u003eadm-zip's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.6.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cthackers/adm-zip/compare/v0.6.0...v0.6.1\"\u003ehttps://github.com/cthackers/adm-zip/compare/v0.6.0...v0.6.1\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dev dependencies\u003c/li\u003e\n\u003cli\u003eFixed uncaught crash in async decompression on malformed DEFLATE data\u003c/li\u003e\n\u003cli\u003eFixed addLocalFolder following symlinks out of the archived folder\u003c/li\u003e\n\u003cli\u003eStripped setuid/setgid/sticky bits from extracted file permissions\u003c/li\u003e\n\u003cli\u003eEnforced the decompression size cap on the async path and for size 0\u003c/li\u003e\n\u003cli\u003eRejected archives with duplicate entry names\u003c/li\u003e\n\u003cli\u003eBlocked extraction from writing through symlinks inside the target\u003c/li\u003e\n\u003cli\u003eRouted malformed-header parse errors through the async callback\u003c/li\u003e\n\u003cli\u003eRejected zip entries whose declared data extent runs past the buffer\u003c/li\u003e\n\u003cli\u003eFixed addLocalFolderPromise hanging on empty folders and swallowing errors\u003c/li\u003e\n\u003cli\u003eFixed addLocalFolderAsync2 mangling local paths on Windows\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.6.0\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cthackers/adm-zip/compare/v0.5.18...v0.6.0\"\u003ehttps://github.com/cthackers/adm-zip/compare/v0.5.18...v0.6.0\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eThis release fixes a security vulnerability (CVE-2026-39244), resolves several long-standing bugs, ships built-in TypeScript types, and includes two behavior changes worth reading before you upgrade.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eextractEntryTo(dirEntry, target, maintainEntryPath = false) now preserves subdirectories instead of flattening files into the target folder by basename (which also silently overwrote same-named files). (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/306\"\u003e#306\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eExtraction no longer fails when the modification time can't be set — utimes is now best-effort. (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/379\"\u003e#379\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMinimum Node.js is now 14 (the code already required it; engines was incorrectly \u0026gt;=12).\u003c/li\u003e\n\u003cli\u003eCVE-2026-39244 — a crafted archive declaring a huge uncompressed size could force an unbounded Buffer.alloc and OOM the process; allocation is now bounded by the data actually present. Reported by Daniel Púa (devploit), Anh Hong, and José Antonio Zamudio Amaya. (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/568\"\u003e#568\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHardened entry-name lookup against object injection (\u003cstrong\u003eproto\u003c/strong\u003e names). Prototype-less table.\u003c/li\u003e\n\u003cli\u003eData-descriptor regression rejecting valid archives (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/548\"\u003e#548\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/533\"\u003e#533\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/554\"\u003e#554\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDirectory permissions not restored on extract (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/530\"\u003e#530\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eInfinite recursion on symlink loops in addLocalFolder (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/541\"\u003e#541\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUncaught process crash in writeFileToAsync on write failure (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/470\"\u003e#470\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/459\"\u003e#459\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/402\"\u003e#402\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEmpty name on directory entries (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/466\"\u003e#466\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etest() always returned false for archives with files\u003c/li\u003e\n\u003cli\u003e~6× faster entry sorting for large archives\u003c/li\u003e\n\u003cli\u003eBuilt-in TypeScript definitions (types.d.ts) — you can drop \u003ccode\u003e@​types/adm-zip\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cthackers/adm-zip/blob/master/history.md\"\u003eadm-zip's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e0.6.0 / 2026-07-10\u003c/h1\u003e\n\u003cp\u003eSecurity\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed CVE-2026-39244: a crafted archive declaring a huge uncompressed size could force an unbounded \u003ccode\u003eBuffer.alloc\u003c/code\u003e (memory exhaustion / DoS) before any validation. Allocation is now bounded by the data actually present — STORED output is sized from the real bytes, DEFLATED output is grown by the inflater and capped at the declared size (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/568\"\u003e#568\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHardened the internal entry-name lookup table against object injection: entry names come from untrusted archives, and a name such as \u003ccode\u003e__proto__\u003c/code\u003e previously resolved to \u003ccode\u003eObject.prototype\u003c/code\u003e, crashing \u003ccode\u003eaddFile\u003c/code\u003e and hiding the entry from \u003ccode\u003egetEntry\u003c/code\u003e/\u003ccode\u003ereadFile\u003c/code\u003e. The table is now prototype-less\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eBug fixes\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a regression (0.5.15) that rejected valid archives using a data descriptor (general-purpose bit 3). The payload is now validated against the authoritative central-directory CRC instead of requiring/parsing the trailing descriptor (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/548\"\u003e#548\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/533\"\u003e#533\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/554\"\u003e#554\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eextractAllTo\u003c/code\u003e/\u003ccode\u003eextractAllToAsync\u003c/code\u003e not restoring directory permissions with \u003ccode\u003ekeepOriginalPermission\u003c/code\u003e; directory modes are applied after their contents are written, deepest path first, and no longer lock the extractor out of a restrictive directory (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/530\"\u003e#530\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed infinite recursion in \u003ccode\u003eaddLocalFolder\u003c/code\u003e when a folder contains a symlink pointing back to an ancestor (e.g. workspace \u003ccode\u003enode_modules\u003c/code\u003e); the walk now tracks resolved real paths and skips already-visited directories (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/541\"\u003e#541\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed an uncaught exception (\u003ccode\u003eERR_INVALID_ARG_TYPE\u003c/code\u003e) that crashed the process when \u003ccode\u003ewriteFileToAsync\u003c/code\u003e could not open the target file (bad permissions, invalid filename, exhausted file descriptors); write failures are now reported through the callback and write errors are no longer silently swallowed (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/470\"\u003e#470\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/459\"\u003e#459\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/402\"\u003e#402\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed directory entries reporting an empty \u003ccode\u003ename\u003c/code\u003e (e.g. \u003ccode\u003ea/b/c/\u003c/code\u003e now returns \u003ccode\u003ec\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/466\"\u003e#466\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eextractEntryTo\u003c/code\u003e flattening subdirectories when \u003ccode\u003emaintainEntryPath\u003c/code\u003e is false; the structure below the extracted directory is now preserved instead of collapsing (and overwriting) files by basename (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/306\"\u003e#306\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a failed \u003ccode\u003eutimes\u003c/code\u003e aborting extraction; setting the modification time is now best-effort and never fails extraction of already-written content (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/379\"\u003e#379\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003etest()\u003c/code\u003e always returning false for any archive containing a file (it indexed the entries array with an entry object instead of reading the entry); it now correctly verifies each entry's CRC\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003ePerformance\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFaster entry sorting when writing archives with many entries: names are decoded once instead of on every comparison (about 6× faster sort for large archives)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAdded\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eBundled TypeScript type definitions (\u003ccode\u003etypes.d.ts\u003c/code\u003e), so \u003ccode\u003e@types/adm-zip\u003c/code\u003e is no longer required\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNotes\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eBehavior change: \u003ccode\u003eextractEntryTo(dir, target, /* maintainEntryPath */ false)\u003c/code\u003e now preserves subdirectories beneath the extracted directory rather than flattening them\u003c/li\u003e\n\u003cli\u003eBehavior change: extraction no longer fails when the modification time cannot be set\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e0.5.4 / 2021-03-08\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eFixed relative paths\u003c/li\u003e\n\u003cli\u003eAdded zipcrypto encryption\u003c/li\u003e\n\u003cli\u003eLower verMade for macOS when generating zip file\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e0.5.3 / 2021-02-07\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eFixed filemode when unzipping\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e0.5.2 / 2021-01-27\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eFixed path traversal issue (GHSL-2020-198)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e0.5.1 / 2020-11-27\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eIncremented version (cthackers)\u003c/li\u003e\n\u003cli\u003eFixed outFileName (cthackers)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e0.5.0 / 2020-11-19\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eAdded extra parameter to extractEntryTo so target filename can be renamed (cthackers)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cthackers/adm-zip/commit/cb2cf9ba4c7c865db426e2de1997cb41194d9872\"\u003e\u003ccode\u003ecb2cf9b\u003c/code\u003e\u003c/a\u003e Fixed addLocalFolderAsync2 mangling local paths on Windows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cthackers/adm-zip/commit/54902b60f0f1d6d6e8157e81e0f18c5001941ccc\"\u003e\u003ccode\u003e54902b6\u003c/code\u003e\u003c/a\u003e Fixed addLocalFolderPromise hanging on empty folders and swallowing errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cthackers/adm-zip/commit/73131bdce50fa6ed201c48b468082ef456894f2e\"\u003e\u003ccode\u003e73131bd\u003c/code\u003e\u003c/a\u003e Fixed CI\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cthackers/adm-zip/commit/758898d71508e8a016691d5843b5f7ce2d1b208a\"\u003e\u003ccode\u003e758898d\u003c/code\u003e\u003c/a\u003e Rejected zip entries whose declared data extent runs past the buffer\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cthackers/adm-zip/commit/74b6e9f402c4c7cde4e33f3c87ff8f15ddcd6121\"\u003e\u003ccode\u003e74b6e9f\u003c/code\u003e\u003c/a\u003e Routed malformed-header parse errors through the async callback\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cthackers/adm-zip/commit/eaa35fa73df6108a3d6ebc9b9073371740735265\"\u003e\u003ccode\u003eeaa35fa\u003c/code\u003e\u003c/a\u003e Blocked extraction from writing through symlinks inside the target\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cthackers/adm-zip/commit/1e015e3e713aee426bf3d5c1bc1b555c90f4f3e6\"\u003e\u003ccode\u003e1e015e3\u003c/code\u003e\u003c/a\u003e Increment version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cthackers/adm-zip/commit/05101d47b3b983b705cc3e66fc34366118ba7b99\"\u003e\u003ccode\u003e05101d4\u003c/code\u003e\u003c/a\u003e Rejected archives with duplicate entry names\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cthackers/adm-zip/commit/491600683dacb6cb9fe0718a0eeb9cb5eb49afa6\"\u003e\u003ccode\u003e4916006\u003c/code\u003e\u003c/a\u003e Enforced the decompression size cap on the async path and for size 0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cthackers/adm-zip/commit/6a63c339b83c52915483efacda517660a7a7bf87\"\u003e\u003ccode\u003e6a63c33\u003c/code\u003e\u003c/a\u003e Stripped setuid/setgid/sticky bits from extracted file permissions\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/cthackers/adm-zip/compare/v0.5.18...v0.6.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-uri` from 3.1.5 to 3.1.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss-selector-parser` from 6.1.2 to 6.1.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss-selector-parser/releases\"\u003epostcss-selector-parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e6.1.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: tolerate non-node children when serializing selectors\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e6.1.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://github.com/advisories/GHSA-w9m9-85wc-3x92\"\u003eCVE-2026-9358\u003c/a\u003e (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 via backport of (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/pull/316\"\u003e#316\u003c/a\u003e by \u003ca href=\"https://github.com/MoOx\"\u003e\u003ccode\u003e@​MoOx\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md\"\u003epostcss-selector-parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog of \u003ccode\u003epostcss-selector-parser\u003c/code\u003e\u003c/h1\u003e\n\u003ch2\u003e7.1.6 - 2026-09-03\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: parse flat selectors in linear time, closing a CPU exhaustion vulnerability (\u003ca href=\"https://github.com/advisories/GHSA-rj75-hqrm-r3gf\"\u003eGHSA-rj75-hqrm-r3gf\u003c/a\u003e, reported by Wayde Shi)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.5 - 2026-08-07\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: don't treat a non-prefix token before \u003ccode\u003e|\u003c/code\u003e as a namespace (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/pull/324\"\u003e#324\u003c/a\u003e by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix: preserve whitespace before a \u003ccode\u003e*\u003c/code\u003e namespace in attribute selectors (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/pull/325\"\u003e#325\u003c/a\u003e by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix: TypeError on unclosed \u003ccode\u003e[\u003c/code\u003e, \u003ccode\u003e(\u003c/code\u003e and trailing \u003ccode\u003e|\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/pull/330\"\u003e#330\u003c/a\u003e by \u003ca href=\"https://github.com/theRizwan\"\u003e\u003ccode\u003e@​theRizwan\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.4 - 2026-06-11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: tolerate non-node children when serializing selectors\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.3 - 2026-06-11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (clone/walk)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.2 - 2026-06-09\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://github.com/advisories/GHSA-w9m9-85wc-3x92\"\u003eCVE-2026-9358\u003c/a\u003e (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/pull/316\"\u003e#316\u003c/a\u003e by \u003ca href=\"https://github.com/MoOx\"\u003e\u003ccode\u003e@​MoOx\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eperf: replace startsWith with strict equality (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/issues/308\"\u003e#308\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(types): add walkUniversal declaration (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/issues/311\"\u003e#311\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: insert(Before|After) support multiple new node\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFeat: make insertions during iteration safe (major)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/4a7e4e3685db8ab8e52e51ecdbe8162a8568f70c\"\u003e\u003ccode\u003e4a7e4e3\u003c/code\u003e\u003c/a\u003e 7.1.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/e2021c523d5ef1bf27836aef3bd724a28ba7894f\"\u003e\u003ccode\u003ee2021c5\u003c/code\u003e\u003c/a\u003e fix: tolerate non-node children when serializing selectors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/7893b741fa87d0401e39c3a7f00d89cf7408ad32\"\u003e\u003ccode\u003e7893b74\u003c/code\u003e\u003c/a\u003e 7.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/5bc698cef66f8abd12610dc623e5d67cbc0f869d\"\u003e\u003ccode\u003e5bc698c\u003c/code\u003e\u003c/a\u003e Improve fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (clo...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/db3232710d7270b34e50b4ffae493ac19204f570\"\u003e\u003ccode\u003edb32327\u003c/code\u003e\u003c/a\u003e run oxfmt\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/16e2581b40894504cf2b979fc0ebf7d0b2f39366\"\u003e\u003ccode\u003e16e2581\u003c/code\u003e\u003c/a\u003e simplify deps (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/issues/319\"\u003e#319\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/b185e2057871669f9c571ad82e4350799e0a2329\"\u003e\u003ccode\u003eb185e20\u003c/code\u003e\u003c/a\u003e Add description in package.json + full repo url\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/de415f19aac008f0e731590222f3a963193be05c\"\u003e\u003ccode\u003ede415f1\u003c/code\u003e\u003c/a\u003e Add Tidelift security notice\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/c4f2c8c04a8107e4e401f257ef00592b59633774\"\u003e\u003ccode\u003ec4f2c8c\u003c/code\u003e\u003c/a\u003e CI: make Node 14 test job lockfile-v3 compatible (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/issues/318\"\u003e#318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/4e93663bfe861f9fc3173db603c8fadb70f8090a\"\u003e\u003ccode\u003e4e93663\u003c/code\u003e\u003c/a\u003e Fix test run on node \u0026lt; 20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss-selector-parser/compare/v6.1.2...6.1.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~moox\"\u003emoox\u003c/a\u003e, a new releaser for postcss-selector-parser since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss-selector-parser` from 7.1.1 to 7.1.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss-selector-parser/releases\"\u003epostcss-selector-parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e6.1.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: tolerate non-node children when serializing selectors\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e6.1.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://github.com/advisories/GHSA-w9m9-85wc-3x92\"\u003eCVE-2026-9358\u003c/a\u003e (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 via backport of (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/pull/316\"\u003e#316\u003c/a\u003e by \u003ca href=\"https://github.com/MoOx\"\u003e\u003ccode\u003e@​MoOx\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md\"\u003epostcss-selector-parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog of \u003ccode\u003epostcss-selector-parser\u003c/code\u003e\u003c/h1\u003e\n\u003ch2\u003e7.1.6 - 2026-09-03\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: parse flat selectors in linear time, closing a CPU exhaustion vulnerability (\u003ca href=\"https://github.com/advisories/GHSA-rj75-hqrm-r3gf\"\u003eGHSA-rj75-hqrm-r3gf\u003c/a\u003e, reported by Wayde Shi)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.5 - 2026-08-07\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: don't treat a non-prefix token before \u003ccode\u003e|\u003c/code\u003e as a namespace (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/pull/324\"\u003e#324\u003c/a\u003e by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix: preserve whitespace before a \u003ccode\u003e*\u003c/code\u003e namespace in attribute selectors (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/pull/325\"\u003e#325\u003c/a\u003e by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix: TypeError on unclosed \u003ccode\u003e[\u003c/code\u003e, \u003ccode\u003e(\u003c/code\u003e and trailing \u003ccode\u003e|\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/pull/330\"\u003e#330\u003c/a\u003e by \u003ca href=\"https://github.com/theRizwan\"\u003e\u003ccode\u003e@​theRizwan\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.4 - 2026-06-11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: tolerate non-node children when serializing selectors\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.3 - 2026-06-11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (clone/walk)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.2 - 2026-06-09\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://github.com/advisories/GHSA-w9m9-85wc-3x92\"\u003eCVE-2026-9358\u003c/a\u003e (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/pull/316\"\u003e#316\u003c/a\u003e by \u003ca href=\"https://github.com/MoOx\"\u003e\u003ccode\u003e@​MoOx\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eperf: replace startsWith with strict equality (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/issues/308\"\u003e#308\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(types): add walkUniversal declaration (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/issues/311\"\u003e#311\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.1.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: insert(Before|After) support multiple new node\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFeat: make insertions during iteration safe (major)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/4a7e4e3685db8ab8e52e51ecdbe8162a8568f70c\"\u003e\u003ccode\u003e4a7e4e3\u003c/code\u003e\u003c/a\u003e 7.1.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/e2021c523d5ef1bf27836aef3bd724a28ba7894f\"\u003e\u003ccode\u003ee2021c5\u003c/code\u003e\u003c/a\u003e fix: tolerate non-node children when serializing selectors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/7893b741fa87d0401e39c3a7f00d89cf7408ad32\"\u003e\u003ccode\u003e7893b74\u003c/code\u003e\u003c/a\u003e 7.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/5bc698cef66f8abd12610dc623e5d67cbc0f869d\"\u003e\u003ccode\u003e5bc698c\u003c/code\u003e\u003c/a\u003e Improve fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (clo...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/db3232710d7270b34e50b4ffae493ac19204f570\"\u003e\u003ccode\u003edb32327\u003c/code\u003e\u003c/a\u003e run oxfmt\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/16e2581b40894504cf2b979fc0ebf7d0b2f39366\"\u003e\u003ccode\u003e16e2581\u003c/code\u003e\u003c/a\u003e simplify deps (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/issues/319\"\u003e#319\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/b185e2057871669f9c571ad82e4350799e0a2329\"\u003e\u003ccode\u003eb185e20\u003c/code\u003e\u003c/a\u003e Add description in package.json + full repo url\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/de415f19aac008f0e731590222f3a963193be05c\"\u003e\u003ccode\u003ede415f1\u003c/code\u003e\u003c/a\u003e Add Tidelift security notice\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/c4f2c8c04a8107e4e401f257ef00592b59633774\"\u003e\u003ccode\u003ec4f2c8c\u003c/code\u003e\u003c/a\u003e CI: make Node 14 test job lockfile-v3 compatible (\u003ca href=\"https://redirect.github.com/postcss/postcss-selector-parser/issues/318\"\u003e#318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss-selector-parser/commit/4e93663bfe861f9fc3173db603c8fadb70f8090a\"\u003e\u003ccode\u003e4e93663\u003c/code\u003e\u003c/a\u003e Fix test run on node \u0026lt; 20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss-selector-parser/compare/v6.1.2...6.1.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~moox\"\u003emoox\u003c/a\u003e, a new releaser for postcss-selector-parser since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `svgo` from 3.3.4 to 3.3.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/svg/svgo/releases\"\u003esvgo's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.3.5\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBackport the \u003ccode\u003eremoveScriptElement\u003c/code\u003e hardening from SVGO v4 in \u003ca href=\"https://redirect.github.com/svg/svgo/issues/2269\"\u003e#2269\u003c/a\u003e:\n\u003cul\u003e\n\u003cli\u003ereject executable \u003ccode\u003edata:\u003c/code\u003e URLs and legacy \u003ccode\u003evbscript:\u003c/code\u003e URLs\u003c/li\u003e\n\u003cli\u003esanitize executable HTML inside \u003ccode\u003e\u0026lt;foreignObject\u0026gt;\u003c/code\u003e elements\u003c/li\u003e\n\u003cli\u003ehandle namespace-prefixed SVG anchors and URL schemes containing ASCII tabs or newlines\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThis addresses \u003ca href=\"https://github.com/svg/svgo/security/advisories/GHSA-4vpr-x523-8j87\"\u003eGHSA-4vpr-x523-8j87\u003c/a\u003e and \u003ca href=\"https://github.com/svg/svgo/security/advisories/GHSA-w27v-7q3p-w38r\"\u003eGHSA-w27v-7q3p-w38r\u003c/a\u003e for the v3 release line.\u003c/p\u003e\n\u003ch2\u003eSupport\u003c/h2\u003e\n\u003cp\u003eSVGO v3 is not officially supported; please consider upgrading to SVGO v4. This security fix has been backported, but there is no commitment to backport more complex changes in the future.\u003c/p\u003e\n\u003cp\u003eSee the \u003ca href=\"https://svgo.dev/docs/migrations/migration-from-v3-to-v4/\"\u003emigration guide from v3 to v4\u003c/a\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/svg/svgo/commit/438059032950dde2c2d36ce45f912085947e60d0\"\u003e\u003ccode\u003e4380590\u003c/code\u003e\u003c/a\u003e ci: configure v3 publish tag in package metadata (\u003ca href=\"https://redirect.github.com/svg/svgo/issues/2271\"\u003e#2271\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/svg/svgo/commit/4c84fe7ef022f05350404a469ca66321e0afcb47\"\u003e\u003ccode\u003e4c84fe7\u003c/code\u003e\u003c/a\u003e ci: publish v3 with npm trusted publishing (\u003ca href=\"https://redirect.github.com/svg/svgo/issues/2270\"\u003e#2270\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/svg/svgo/commit/994a9f00d79ddec68ce19a1ce9eb8ca08d747e4f\"\u003e\u003ccode\u003e994a9f0\u003c/code\u003e\u003c/a\u003e fix(removeScriptElement): backport security hardening to v3 (\u003ca href=\"https://redirect.github.com/svg/svgo/issues/2269\"\u003e#2269\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/svg/svgo/compare/v3.3.4...v3.3.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for svgo since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `js-yaml` from 4.3.0 to 4.3.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md\"\u003ejs-yaml's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.15.2 - 2026-08-26\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Hard-limit merge sequence size to 100.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Count empty mappings in merge sequences toward \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e\nto limit CPU usage, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/797\"\u003e#797\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/5c45bd6e960603c13644f5cc8b572ca257723b36\"\u003e\u003ccode\u003e5c45bd6\u003c/code\u003e\u003c/a\u003e 3.15.2 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/5a708f9f4f22e78b87ebe363848cfa4fa4818c0d\"\u003e\u003ccode\u003e5a708f9\u003c/code\u003e\u003c/a\u003e dist rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/3485bc06ff8a0251505f44a00414d90df2466639\"\u003e\u003ccode\u003e3485bc0\u003c/code\u003e\u003c/a\u003e Backport merge limits from v5.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/f34812f1cea794f8c21e0a4e1f3a2584b720f305\"\u003e\u003ccode\u003ef34812f\u003c/code\u003e\u003c/a\u003e Update .gitignore\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodeca/js-yaml/compare/3.15.1...3.15.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `svgo` from 4.0.2 to 4.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/svg/svgo/releases\"\u003esvgo's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.3.5\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBackport the \u003ccode\u003eremoveScriptElement\u003c/code\u003e hardening from SVGO v4 in \u003ca href=\"https://redirect.github.com/svg/svgo/issues/2269\"\u003e#2269\u003c/a\u003e:\n\u003cul\u003e\n\u003cli\u003ereject executable \u003ccode\u003edata:\u003c/code\u003e URLs and legacy \u003ccode\u003evbscript:\u003c/code\u003e URLs\u003c/li\u003e\n\u003cli\u003esanitize executable HTML inside \u003ccode\u003e\u0026lt;foreignObject\u0026gt;\u003c/code\u003e elements\u003c/li\u003e\n\u003cli\u003ehandle namespace-prefixed SVG anchors and URL schemes containing ASCII tabs or newlines\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThis addresses \u003ca href=\"https://github.com/svg/svgo/security/advisories/GHSA-4vpr-x523-8j87\"\u003eGHSA-4vpr-x523-8j87\u003c/a\u003e and \u003ca href=\"https://github.com/svg/svgo/security/advisories/GHSA-w27v-7q3p-w38r\"\u003eGHSA-w27v-7q3p-w38r\u003c/a\u003e for the v3 release line.\u003c/p\u003e\n\u003ch2\u003eSupport\u003c/h2\u003e\n\u003cp\u003eSVGO v3 is not officially supported; please consider upgrading to SVGO v4. This security fix has been backported, but there is no commitment to backport more complex changes in the future.\u003c/p\u003e\n\u003cp\u003eSee the \u003ca href=\"https://svgo.dev/docs/migrations/migration-from-v3-to-v4/\"\u003emigration guide from v3 to v4\u003c/a\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/svg/svgo/commit/438059032950dde2c2d36ce45f912085947e60d0\"\u003e\u003ccode\u003e4380590\u003c/code\u003e\u003c/a\u003e ci: configure v3 publish tag in package metadata (\u003ca href=\"https://redirect.github.com/svg/svgo/issues/2271\"\u003e#2271\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/svg/svgo/commit/4c84fe7ef022f05350404a469ca66321e0afcb47\"\u003e\u003ccode\u003e4c84fe7\u003c/code\u003e\u003c/a\u003e ci: publish v3 with npm trusted publishing (\u003ca href=\"https://redirect.github.com/svg/svgo/issues/2270\"\u003e#2270\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/svg/svgo/commit/994a9f00d79ddec68ce19a1ce9eb8ca08d747e4f\"\u003e\u003ccode\u003e994a9f0\u003c/code\u003e\u003c/a\u003e fix(removeScriptElement): backport security hardening to v3 (\u003ca href=\"https://redirect.github.com/svg/svgo/issues/2269\"\u003e#2269\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/svg/svgo/compare/v3.3.4...v3.3.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for svgo since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `astro` from 7.2.4 to 7.3.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/withastro/astro/releases\"\u003eastro's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eastro@7.3.2\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17896\"\u003e#17896\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/a548223607b9bb146d5d90ddda495343f9a2a739\"\u003e\u003ccode\u003ea548223\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e/\u003ccode\u003e\u0026lt;style\u0026gt;\u003c/code\u003e rendering in MDX so that only literal content (including content injected by remark/rehype plugins) is treated as trusted markup. A dynamic value passed as a \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e/\u003ccode\u003e\u0026lt;style\u0026gt;\u003c/code\u003e child (e.g. \u003ccode\u003e\u0026lt;script\u0026gt;{value}\u0026lt;/script\u0026gt;\u003c/code\u003e) is now escaped like any other element's content instead of being rendered raw. Use \u003ccode\u003eset:html\u003c/code\u003e to explicitly opt a dynamic value back into raw rendering.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17931\"\u003e#17931\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/c1a6a89efa577b8388f04c4b42d655913bb4b886\"\u003e\u003ccode\u003ec1a6a89\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes the dev toolbar returning a 504 \u0026quot;Outdated Optimize Dep\u0026quot; error when a workspace-linked package imports a dependency that Vite's initial scan did not discover\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17908\"\u003e#17908\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/42e9188c4ba7360e5ab8ea4cd7f13d6abcf31879\"\u003e\u003ccode\u003e42e9188\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes i18n fallback routing replacing the first substring match instead of the actual locale segment, which mangled paths like \u003ccode\u003e/energy/en/about\u003c/code\u003e into \u003ccode\u003e/esergy/en/about\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17936\"\u003e#17936\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/4b92ddc6ab0795ac78c30aedfe43b081dcf5b6b0\"\u003e\u003ccode\u003e4b92ddc\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes sessions breaking in dev mode with the Cloudflare adapter when middleware is present\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated dependencies [\u003ca href=\"https://github.com/withastro/astro/commit/a548223607b9bb146d5d90ddda495343f9a2a739\"\u003e\u003ccode\u003ea548223\u003c/code\u003e\u003c/a\u003e]:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​astrojs/markdown-satteri\u003c/code\u003e\u003ca href=\"https://github.com/0\"\u003e\u003ccode\u003e@​0\u003c/code\u003e\u003c/a\u003e.4.1\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eastro@7.3.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17899\"\u003e#17899\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/03896405717471f7d6ff54986ed6beaec0cac94f\"\u003e\u003ccode\u003e0389640\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ematipico\"\u003e\u003ccode\u003e@​ematipico\u003c/code\u003e\u003c/a\u003e! - Fixes an error that prevented projects using \u003ccode\u003eastro:assets\u003c/code\u003e from starting or building\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eastro@7.3.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17767\"\u003e#17767\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/ce7c91f77dbd7be03c04bc13f87af9d01fef6cef\"\u003e\u003ccode\u003ece7c91f\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Adds \u003ccode\u003e--ignore-lock\u003c/code\u003e flag to \u003ccode\u003eastro preview\u003c/code\u003e, allowing multiple preview servers to run simultaneously on different ports. This is useful for E2E testing workflows (e.g., Playwright) that need to run several preview servers at once.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17818\"\u003e#17818\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/c0b65811dfa0dafa1aa04b7d6d67fd09250ff8c1\"\u003e\u003ccode\u003ec0b6581\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/florian-lefebvre\"\u003e\u003ccode\u003e@​florian-lefebvre\u003c/code\u003e\u003c/a\u003e! - Adds a \u003ccode\u003elogger\u003c/code\u003e parameter to image services hooks\u003c/p\u003e\n\u003cp\u003eCustom image services now receive Astro's runtime logger as an extra argument. Messages logged with it are routed through the destination configured in \u003ccode\u003elogger\u003c/code\u003e and respect your log level, instead of being written straight to the console:\u003c/p\u003e\n\u003cpre lang=\"ts\"\u003e\u003ccode\u003eimport type { LocalImageService } from 'astro';\n\u003cp\u003econst service: LocalImageService = {\n// ...\nasync transform(inputBuffer, transform, imageConfig, logger) {\nlogger.warn(\u003ccode\u003eCould not optimize \u0026amp;quot;${transform.src}\u0026amp;quot;. Passing it through unchanged.\u003c/code\u003e);\nreturn { data: inputBuffer, format: 'png' };\n},\n};\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eAstro's built-in Sharp service now uses this logger for the warnings it emits when it encounters an unexpected or unsupported source format.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17818\"\u003e#17818\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/c0b65811dfa0dafa1aa04b7d6d67fd09250ff8c1\"\u003e\u003ccode\u003ec0b6581\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/florian-lefebvre\"\u003e\u003ccode\u003e@​florian-lefebvre\u003c/code\u003e\u003c/a\u003e! - Adds \u003ccode\u003elogger\u003c/code\u003e to the context object passed to cache providers\u003c/p\u003e\n\u003cp\u003eCustom cache providers now receive Astro's runtime logger on the context passed to \u003ccode\u003eonRequest()\u003c/code\u003e. Messages logged with it are routed through the destination configured in \u003ccode\u003elogger\u003c/code\u003e and respect your log level, instead of being written straight to the console:\u003c/p\u003e\n\u003cpre lang=\"ts\"\u003e\u003ccode\u003eimport type { CacheProvider } from 'astro';\n\u003cp\u003econst provider: CacheProvider = {\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md\"\u003eastro's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e7.3.2\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17896\"\u003e#17896\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/a548223607b9bb146d5d90ddda495343f9a2a739\"\u003e\u003ccode\u003ea548223\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/matthewp\"\u003e\u003ccode\u003e@​matthewp\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e/\u003ccode\u003e\u0026lt;style\u0026gt;\u003c/code\u003e rendering in MDX so that only literal content (including content injected by remark/rehype plugins) is treated as trusted markup. A dynamic value passed as a \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e/\u003ccode\u003e\u0026lt;style\u0026gt;\u003c/code\u003e child (e.g. \u003ccode\u003e\u0026lt;script\u0026gt;{value}\u0026lt;/script\u0026gt;\u003c/code\u003e) is now escaped like any other element's content instead of being rendered raw. Use \u003ccode\u003eset:html\u003c/code\u003e to explicitly opt a dynamic value back into raw rendering.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17931\"\u003e#17931\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/c1a6a89efa577b8388f04c4b42d655913bb4b886\"\u003e\u003ccode\u003ec1a6a89\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes the dev toolbar returning a 504 \u0026quot;Outdated Optimize Dep\u0026quot; error when a workspace-linked package imports a dependency that Vite's initial scan did not discover\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17908\"\u003e#17908\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/42e9188c4ba7360e5ab8ea4cd7f13d6abcf31879\"\u003e\u003ccode\u003e42e9188\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes i18n fallback routing replacing the first substring match instead of the actual locale segment, which mangled paths like \u003ccode\u003e/energy/en/about\u003c/code\u003e into \u003ccode\u003e/esergy/en/about\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17936\"\u003e#17936\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/4b92ddc6ab0795ac78c30aedfe43b081dcf5b6b0\"\u003e\u003ccode\u003e4b92ddc\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Fixes sessions breaking in dev mode with the Cloudflare adapter when middleware is present\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated dependencies [\u003ca href=\"https://github.com/withastro/astro/commit/a548223607b9bb146d5d90ddda495343f9a2a739\"\u003e\u003ccode\u003ea548223\u003c/code\u003e\u003c/a\u003e]:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​astrojs/markdown-satteri\u003c/code\u003e\u003ca href=\"https://github.com/0\"\u003e\u003ccode\u003e@​0\u003c/code\u003e\u003c/a\u003e.4.1\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.3.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17899\"\u003e#17899\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/03896405717471f7d6ff54986ed6beaec0cac94f\"\u003e\u003ccode\u003e0389640\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ematipico\"\u003e\u003ccode\u003e@​ematipico\u003c/code\u003e\u003c/a\u003e! - Fixes an error that prevented projects using \u003ccode\u003eastro:assets\u003c/code\u003e from starting or building\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e7.3.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17767\"\u003e#17767\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/ce7c91f77dbd7be03c04bc13f87af9d01fef6cef\"\u003e\u003ccode\u003ece7c91f\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/apps/astro-factory\"\u003e\u003ccode\u003e@​astro-factory\u003c/code\u003e\u003c/a\u003e! - Adds \u003ccode\u003e--ignore-lock\u003c/code\u003e flag to \u003ccode\u003eastro preview\u003c/code\u003e, allowing multiple preview servers to run simultaneously on different ports. This is useful for E2E testing workflows (e.g., Playwright) that need to run several preview servers at once.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17818\"\u003e#17818\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/c0b65811dfa0dafa1aa04b7d6d67fd09250ff8c1\"\u003e\u003ccode\u003ec0b6581\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/florian-lefebvre\"\u003e\u003ccode\u003e@​florian-lefebvre\u003c/code\u003e\u003c/a\u003e! - Adds a \u003ccode\u003elogger\u003c/code\u003e parameter to image services hooks\u003c/p\u003e\n\u003cp\u003eCustom image services now receive Astro's runtime logger as an extra argument. Messages logged with it are routed through the destination configured in \u003ccode\u003elogger\u003c/code\u003e and respect your log level, instead of being written straight to the console:\u003c/p\u003e\n\u003cpre lang=\"ts\"\u003e\u003ccode\u003eimport type { LocalImageService } from 'astro';\n\u003cp\u003econst service: LocalImageService = {\n// ...\nasync transform(inputBuffer, transform, imageConfig, logger) {\nlogger.warn(\u003ccode\u003eCould not optimize \u0026amp;quot;${transform.src}\u0026amp;quot;. Passing it through unchanged.\u003c/code\u003e);\nreturn { data: inputBuffer, format: 'png' };\n},\n};\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eAstro's built-in Sharp service now uses this logger for the warnings it emits when it encounters an unexpected or unsupported source format.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/withastro/astro/pull/17818\"\u003e#17818\u003c/a\u003e \u003ca href=\"https://github.com/withastro/astro/commit/c0b65811dfa0dafa1aa04b7d6d67fd09250ff8c1\"\u003e\u003ccode\u003ec0b6581\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/florian-lefebvre\"\u003e\u003ccode\u003e@​florian-lefebvre\u003c/code\u003e\u003c/a\u003e! - Adds \u003ccode\u003elogger\u003c/code\u003e to the context object passed to cache providers\u003c/p\u003e\n\u003cp\u003eCustom cache providers now receive Astro's runtime logger on the context passed to \u003ccode\u003eonRequest()\u003c/code\u003e. Messages logged with it are routed through the destination configured in \u003ccode\u003elogger\u003c/code\u003e and respect your log level, instead of being written straight to the console:\u003c/p\u003e\n\u003cpre lang=\"ts\"\u003e\u003ccode\u003e\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/aa4949e425144e0d276d2ff70f01209e90fdfbe8\"\u003e\u003ccode\u003eaa4949e\u003c/code\u003e\u003c/a\u003e [ci] release (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17915\"\u003e#17915\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/42e9188c4ba7360e5ab8ea4cd7f13d6abcf31879\"\u003e\u003ccode\u003e42e9188\u003c/code\u003e\u003c/a\u003e fix(i18n): replace locale segment by index in fallback routing (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17907\"\u003e#17907\u003c/a\u003e) (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17908\"\u003e#17908\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/4b92ddc6ab0795ac78c30aedfe43b081dcf5b6b0\"\u003e\u003ccode\u003e4b92ddc\u003c/code\u003e\u003c/a\u003e Guard setFetchHandler call in non-runnable dev entrypoint to fix sessions + m...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/c1a6a89efa577b8388f04c4b42d655913bb4b886\"\u003e\u003ccode\u003ec1a6a89\u003c/code\u003e\u003c/a\u003e fix: include .astro files in client optimizeDeps entries to prevent 504 on la...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/a548223607b9bb146d5d90ddda495343f9a2a739\"\u003e\u003ccode\u003ea548223\u003c/code\u003e\u003c/a\u003e Only treat literal script/style content as raw in MDX rendering (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17896\"\u003e#17896\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/92f23cc121d3a1a03c6fb901a519309662b333de\"\u003e\u003ccode\u003e92f23cc\u003c/code\u003e\u003c/a\u003e [ci] release (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17900\"\u003e#17900\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/03896405717471f7d6ff54986ed6beaec0cac94f\"\u003e\u003ccode\u003e0389640\u003c/code\u003e\u003c/a\u003e fix: dont use internal paths (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17899\"\u003e#17899\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/f800de13ffab9542f8d1bd13a8f4481c5f5c083a\"\u003e\u003ccode\u003ef800de1\u003c/code\u003e\u003c/a\u003e [ci] release (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17881\"\u003e#17881\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/1e0b7e6023128ad25a79ac125f6d33e5936a3def\"\u003e\u003ccode\u003e1e0b7e6\u003c/code\u003e\u003c/a\u003e [ci] format\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/withastro/astro/commit/4671a5c2d215545d8d7f763381ec1084dce9b7d1\"\u003e\u003ccode\u003e4671a5c\u003c/code\u003e\u003c/a\u003e chore(deps): update react to v19 in \u003ccode\u003e0-css\u003c/code\u003e fixture (\u003ca href=\"https://github.com/withastro/astro/tree/HEAD/packages/astro/issues/17888\"\u003e#17888\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/withastro/astro/commits/astro@7.3.2/packages/astro\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `sharp` from 0.35.3 to 0.35.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lovell/sharp/releases\"\u003esharp's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.35.4\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\"\u003ehttps://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.35.4-rc.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpgrade to libvips v8.18.6 for upstream bug fixes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7f1a0a22cc285fe180766f4935d50b55af6e8432\"\u003e\u003ccode\u003e7f1a0a2\u003c/code\u003e\u003c/a\u003e Release v0.35.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/f927818924bc5a9493d822a4e8b23ec5857c52e1\"\u003e\u003ccode\u003ef927818\u003c/code\u003e\u003c/a\u003e Upgrade to sharp-libvips v1.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e80209240d005c71e1173a50dd9cd4db4ce2a9e6\"\u003e\u003ccode\u003ee802092\u003c/code\u003e\u003c/a\u003e Prerelease v0.35.4-rc.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e13eb2f97a0a22f1ef726e8d0cd33f7c56835945\"\u003e\u003ccode\u003ee13eb2f\u003c/code\u003e\u003c/a\u003e CI: Fix wasm32 build (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4589\"\u003e#4589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/a82a0b3d58bc25854ad1e925e6eb0a50725d1489\"\u003e\u003ccode\u003ea82a0b3\u003c/code\u003e\u003c/a\u003e Upgrade to libvips v8.18.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/8044fe43e36d0ea7f8beb89f79a37bb0f3342e84\"\u003e\u003ccode\u003e8044fe4\u003c/code\u003e\u003c/a\u003e Bound resize dimensions to coordinate limit\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/147f8591a153bc4a1e199c3fe3150fac2931b30c\"\u003e\u003ccode\u003e147f859\u003c/code\u003e\u003c/a\u003e Docs: changelog entries for \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4578\"\u003e#4578\u003c/a\u003e \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ee5bfb853de75a611c64381783b04032a3a897d8\"\u003e\u003ccode\u003eee5bfb8\u003c/code\u003e\u003c/a\u003e Tests: use yauzl directly rather than via extract-zip wrapper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7a7788928f8a2a429f45039010a87cee35401694\"\u003e\u003ccode\u003e7a77889\u003c/code\u003e\u003c/a\u003e Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4588\"\u003e#4588\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ea5bef24c187b2c7ee3fe3cad3b45c8cb67a46fd\"\u003e\u003ccode\u003eea5bef2\u003c/code\u003e\u003c/a\u003e Improve support for input Streams finishing before output is requested (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/lovell/sharp/compare/v0.35.3...v0.35.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/courtneyr-dev/post-formats-for-block-themes/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/courtneyr-dev/post-formats-for-block-themes/pull/42","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/courtneyr-dev%2Fpost-formats-for-block-themes/issues/42","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/42/packages"}},{"old_version":"3.1.2","new_version":"3.1.7","update_type":"patch","path":"/site","pr_created_at":"2026-09-12T19:23:44.000Z","version_change":"3.1.2 → 3.1.7","issue":{"uuid":"5435504881","node_id":"PR_kwDOUYQOzc8AAAABDR2olg","number":11,"state":"closed","title":"Bump fast-uri from 3.1.2 to 3.1.7 in /site","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-12T22:33:54.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-12T19:23:44.000Z","updated_at":"2026-09-12T22:33:56.000Z","time_to_close":11410,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"fast-uri","old_version":"3.1.2","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"}],"path":"/site","ecosystem":"npm"},"body":"Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.2 to 3.1.7.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=fast-uri\u0026package-manager=npm_and_yarn\u0026previous-version=3.1.2\u0026new-version=3.1.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/sridharrajarao-site/gridrudder/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/sridharrajarao-site/gridrudder/pull/11","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/sridharrajarao-site%2Fgridrudder/issues/11","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/11/packages"}},{"old_version":"3.1.5","new_version":"3.1.7","update_type":"patch","path":"/frontend","pr_created_at":"2026-09-12T17:24:16.000Z","version_change":"3.1.5 → 3.1.7","issue":{"uuid":"5434890359","node_id":"PR_kwDOTio6sM8AAAABDRYj8w","number":31,"state":"closed","title":"chore(deps): bump fast-uri from 3.1.5 to 3.1.7 in /frontend","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":"2026-09-13T09:32:21.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-12T17:24:16.000Z","updated_at":"2026-09-13T09:32:28.000Z","time_to_close":58085,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"fast-uri","old_version":"3.1.5","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"}],"path":"/frontend","ecosystem":"npm"},"body":"Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.5 to 3.1.7.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=fast-uri\u0026package-manager=npm_and_yarn\u0026previous-version=3.1.5\u0026new-version=3.1.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/KahMeng15/hellomyphotos/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/KahMeng15/hellomyphotos/pull/31","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/KahMeng15%2Fhellomyphotos/issues/31","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/31/packages"}},{"old_version":"3.1.5","new_version":"3.1.7","update_type":"patch","path":null,"pr_created_at":"2026-09-12T13:38:25.000Z","version_change":"3.1.5 → 3.1.7","issue":{"uuid":"5433614534","node_id":"PR_kwDOUSRYj88AAAABDQZfUw","number":12,"state":"open","title":"chore: bump fast-uri from 3.1.5 to 3.1.7","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-12T13:38:25.000Z","updated_at":"2026-09-12T13:38:41.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore","packages":[{"name":"fast-uri","old_version":"3.1.5","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"}],"path":null,"ecosystem":"npm"},"body":"Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.5 to 3.1.7.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=fast-uri\u0026package-manager=npm_and_yarn\u0026previous-version=3.1.5\u0026new-version=3.1.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/coreone-io/coretalk/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/coreone-io/coretalk/pull/12","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/coreone-io%2Fcoretalk/issues/12","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/12/packages"}},{"old_version":"3.1.3","new_version":"3.1.7","update_type":"patch","path":null,"pr_created_at":"2026-09-12T10:32:37.000Z","version_change":"3.1.3 → 3.1.7","issue":{"uuid":"5432757500","node_id":"PR_kwDOTLRUms8AAAABDPxCNw","number":154,"state":"open","title":"chore(deps): bump fast-uri from 3.1.3 to 3.1.7","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-12T10:32:37.000Z","updated_at":"2026-09-12T10:32:58.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"fast-uri","old_version":"3.1.3","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"}],"path":null,"ecosystem":"npm"},"body":"Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.3 to 3.1.7.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=fast-uri\u0026package-manager=npm_and_yarn\u0026previous-version=3.1.3\u0026new-version=3.1.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/rubicon/forgejo-mcp/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/rubicon/forgejo-mcp/pull/154","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/rubicon%2Fforgejo-mcp/issues/154","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/154/packages"}},{"old_version":"3.1.0","new_version":"3.1.7","update_type":"patch","path":null,"pr_created_at":"2026-09-12T09:44:06.000Z","version_change":"3.1.0 → 3.1.7","issue":{"uuid":"5432533456","node_id":"PR_kwDORz5mi88AAAABDPmMJw","number":27,"state":"open","title":"chore(deps): bump the npm_and_yarn group across 1 directory with 10 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-12T09:44:06.000Z","updated_at":"2026-09-12T09:44:21.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":10,"packages":[{"name":"ws","old_version":"6.2.3","new_version":"6.2.6","repository_url":"https://github.com/websockets/ws"},{"name":"@babel/core","old_version":"7.29.0","new_version":"7.29.7","repository_url":"https://github.com/babel/babel"},{"name":"brace-expansion","old_version":"1.1.13","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"@humanfs/node","old_version":"0.16.7","new_version":"0.16.8","repository_url":"https://github.com/humanwhocodes/humanfs"},{"name":"js-yaml","old_version":"3.14.2","new_version":"3.15.2","repository_url":"https://github.com/nodeca/js-yaml"},{"name":"@xmldom/xmldom","old_version":"0.8.11","new_version":"0.8.15","repository_url":"https://github.com/xmldom/xmldom"},{"name":"fast-uri","old_version":"3.1.0","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"nanoid","old_version":"3.3.11","new_version":"3.3.19","repository_url":"https://github.com/ai/nanoid"},{"name":"postcss","old_version":"8.4.49","new_version":"8.5.28","repository_url":"https://github.com/postcss/postcss"},{"name":"shell-quote","old_version":"1.8.3","new_version":"1.10.0","repository_url":"https://github.com/ljharb/shell-quote"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 10 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [ws](https://github.com/websockets/ws) | `6.2.3` | `6.2.6` |\n| [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) | `7.29.0` | `7.29.7` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.13` | `1.1.18` |\n| [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node) | `0.16.7` | `0.16.8` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `3.14.2` | `3.15.2` |\n| [@xmldom/xmldom](https://github.com/xmldom/xmldom) | `0.8.11` | `0.8.15` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.0` | `3.1.7` |\n| [nanoid](https://github.com/ai/nanoid) | `3.3.11` | `3.3.19` |\n| [postcss](https://github.com/postcss/postcss) | `8.4.49` | `8.5.28` |\n| [shell-quote](https://github.com/ljharb/shell-quote) | `1.8.3` | `1.10.0` |\n\n\nUpdates `ws` from 6.2.3 to 6.2.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/websockets/ws/releases\"\u003ews's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e6.2.6\u003c/h2\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug introduced in version 6.2.5 that prevented the fragment counter\nfrom resetting (899bf9e5).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e6.2.5\u003c/h2\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eBackported a2f4e7c0 and f197ac65 to the v6.x release line (58ddc8c3, 4f19c0cd).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e6.2.4\u003c/h2\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eBackported 2b2abd45 to the 6.x release line (a76e2111).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/dd3ae14c767e1fc7446439a6853bec43f2a3d8bc\"\u003e\u003ccode\u003edd3ae14\u003c/code\u003e\u003c/a\u003e [dist] 6.2.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/899bf9e56fcfc6da108dbbec08d4940349c8e9fd\"\u003e\u003ccode\u003e899bf9e\u003c/code\u003e\u003c/a\u003e [fix] Reset the fragment counter when the message is complete\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/1a0afaf201c10f374a8ed375c986efa2ff93efc5\"\u003e\u003ccode\u003e1a0afaf\u003c/code\u003e\u003c/a\u003e [dist] 6.2.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/4f19c0cd9e7dce6b345ae425363353ef7abadf17\"\u003e\u003ccode\u003e4f19c0c\u003c/code\u003e\u003c/a\u003e [fix] Lower default values of \u003ccode\u003emaxBufferedChunks\u003c/code\u003e and \u003ccode\u003emaxFragments\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/58ddc8c3f7c9531c0c7c0293d1b4f742a72e1121\"\u003e\u003ccode\u003e58ddc8c\u003c/code\u003e\u003c/a\u003e [fix] Count empty fragments toward the limit (\u003ca href=\"https://redirect.github.com/websockets/ws/issues/2329\"\u003e#2329\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/86d3e8a5fb0246ed373860c5fbb0de88824a27f7\"\u003e\u003ccode\u003e86d3e8a\u003c/code\u003e\u003c/a\u003e [dist] 6.2.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/websockets/ws/commit/a76e2111c91d7e031c00148a73db90db059bf989\"\u003e\u003ccode\u003ea76e211\u003c/code\u003e\u003c/a\u003e [security] Limit retained message parts\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/websockets/ws/compare/6.2.3...6.2.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@babel/core` from 7.29.0 to 7.29.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/babel/babel/releases\"\u003e@​babel/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.7 (2026-05-25)\u003c/h2\u003e\n\u003cp\u003eRe-release all packages with npm provenance attestations\u003c/p\u003e\n\u003ch2\u003ev7.29.6 (2026-05-25)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18014\"\u003e#18014\u003c/a\u003e Catchup source map position in preserveFormat (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18001\"\u003e#18001\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e, \u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17998\"\u003e#17998\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 3\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMateusz Burzyński (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.5 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:house:  Internal\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@babel/*\u003c/code\u003e dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.4 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17974\"\u003e#17974\u003c/a\u003e [7.x backport]fix(systemjs): improve module string name support (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 1\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.3 (2026-04-30)\u003c/h2\u003e\n\u003ch4\u003e:eyeglasses: Spec Compliance\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17923\"\u003e#17923\u003c/a\u003e Support flow extends bound (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-helper-create-class-features-plugin\u003c/code\u003e, \u003ccode\u003ebabel-plugin-proposal-decorators\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17931\"\u003e#17931\u003c/a\u003e fix(decorators): replace super within all removed static elements (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-register\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17915\"\u003e#17915\u003c/a\u003e Fix thread synchronization issues in \u003ccode\u003e@babel/register\u003c/code\u003e (\u003ca href=\"https://github.com/liuxingbaoyu\"\u003e\u003ccode\u003e@​liuxingbaoyu\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-compat-data\u003c/code\u003e, \u003ccode\u003ebabel-plugin-bugfix-safari-rest-destructuring-rhs-array\u003c/code\u003e, \u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17788\"\u003e#17788\u003c/a\u003e Add bugfix plugin for Safari array rest destructuring bug (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:nail_care: Polish\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/4fba7541180bf5f58256d8e358b544e3831ad090\"\u003e\u003ccode\u003e4fba754\u003c/code\u003e\u003c/a\u003e v7.29.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/04ea6b27fdac8f40c3481aec2080ac9678779509\"\u003e\u003ccode\u003e04ea6b2\u003c/code\u003e\u003c/a\u003e v7.29.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/99f498a9b9fa0b900d603fbe8f6601bb3b9e42bb\"\u003e\u003ccode\u003e99f498a\u003c/code\u003e\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/18001\"\u003e#18001\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/feba0a3654c596bd369d1ef1231f5d56666d56dc\"\u003e\u003ccode\u003efeba0a3\u003c/code\u003e\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17998\"\u003e#17998\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/babel/babel/commits/v7.29.7/packages/babel-core\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.13 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24\"\u003e\u003ccode\u003e2203f4f\u003c/code\u003e\u003c/a\u003e 1.1.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd\"\u003e\u003ccode\u003e0b09384\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/10c05fcf3699b1a29ef5e611c011af3d3c97e6e3\"\u003e\u003ccode\u003e10c05fc\u003c/code\u003e\u003c/a\u003e 1.1.14\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.13...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@humanfs/node` from 0.16.7 to 0.16.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/humanwhocodes/humanfs/releases\"\u003e@​humanfs/node's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003enode: v0.16.8\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/compare/node-v0.16.7...node-v0.16.8\"\u003e0.16.8\u003c/a\u003e (2026-04-17)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eInclude type dependencies at runtime (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e956ce7a\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/humanwhocodes/humanfs/issues/145\"\u003e#145\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe following workspace dependencies were updated\n\u003cul\u003e\n\u003cli\u003edependencies\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​humanfs/core\u003c/code\u003e bumped from ^0.19.1 to ^0.19.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/humanwhocodes/humanfs/blob/main/packages/node/CHANGELOG.md\"\u003e@​humanfs/node's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/compare/node-v0.16.7...node-v0.16.8\"\u003e0.16.8\u003c/a\u003e (2026-04-17)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEnsure symlinks are copied as symlinks in \u003ccode\u003ecopy()\u003c/code\u003e and \u003ccode\u003ecopyAll()\u003c/code\u003e (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/22bbaa4487a3e6c1197ca619840de4615d0c3404\"\u003e22bbaa44\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eInclude type dependencies at runtime (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e956ce7a\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/humanwhocodes/humanfs/issues/145\"\u003e#145\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe following workspace dependencies were updated\n\u003cul\u003e\n\u003cli\u003edependencies\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​humanfs/core\u003c/code\u003e bumped from ^0.19.1 to ^0.19.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/e96070e897f017ae8abd2b0676d98d14e49665cc\"\u003e\u003ccode\u003ee96070e\u003c/code\u003e\u003c/a\u003e chore: release main (\u003ca href=\"https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node/issues/146\"\u003e#146\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/22bbaa4487a3e6c1197ca619840de4615d0c3404\"\u003e\u003ccode\u003e22bbaa4\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e\u003ccode\u003e956ce7a\u003c/code\u003e\u003c/a\u003e fix: Include type dependencies at runtime\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/humanwhocodes/humanfs/commits/node-v0.16.8/packages/node\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `js-yaml` from 3.14.2 to 3.15.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md\"\u003ejs-yaml's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.15.2 - 2026-08-26\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Hard-limit merge sequence size to 100.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Count empty mappings in merge sequences toward \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e\nto limit CPU usage, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/797\"\u003e#797\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.15.1 - 2026-07-31\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Remove quadratic complexity from \u003ccode\u003e!!omap\u003c/code\u003e duplicate key detection.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.15.0 - 2026-06-27\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e (10000) loader option to limit the total number of\nkeys processed by YAML merge (\u003ccode\u003e\u0026lt;\u0026lt;\u003c/code\u003e) across one \u003ccode\u003esafeLoad()\u003c/code\u003e / \u003ccode\u003esafeLoadAll()\u003c/code\u003e\ncall.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/5c45bd6e960603c13644f5cc8b572ca257723b36\"\u003e\u003ccode\u003e5c45bd6\u003c/code\u003e\u003c/a\u003e 3.15.2 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/5a708f9f4f22e78b87ebe363848cfa4fa4818c0d\"\u003e\u003ccode\u003e5a708f9\u003c/code\u003e\u003c/a\u003e dist rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/3485bc06ff8a0251505f44a00414d90df2466639\"\u003e\u003ccode\u003e3485bc0\u003c/code\u003e\u003c/a\u003e Backport merge limits from v5.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/f34812f1cea794f8c21e0a4e1f3a2584b720f305\"\u003e\u003ccode\u003ef34812f\u003c/code\u003e\u003c/a\u003e Update .gitignore\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/ab85ae2c622bc6d8cdbceccafe9f9b7df80463ed\"\u003e\u003ccode\u003eab85ae2\u003c/code\u003e\u003c/a\u003e 3.15.1 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/30a5e7647a4454f7bac969bfbbe7eac9921a4279\"\u003e\u003ccode\u003e30a5e76\u003c/code\u003e\u003c/a\u003e dist rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/22a8071ef032117bc6249c330b240ac3aa2d3ded\"\u003e\u003ccode\u003e22a8071\u003c/code\u003e\u003c/a\u003e Backport quadratic complexity fix for !!omap\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/c34b6c40027a769eb0d67958ae615268a1d55f54\"\u003e\u003ccode\u003ec34b6c4\u003c/code\u003e\u003c/a\u003e 3.15.0 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/21e13d363f33501c7ee6ca988b88c29084999f72\"\u003e\u003ccode\u003e21e13d3\u003c/code\u003e\u003c/a\u003e dist rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/4165c62630d64fe4f25fb0d03139c7e137b24b1c\"\u003e\u003ccode\u003e4165c62\u003c/code\u003e\u003c/a\u003e Add v3-legacy tag for publish\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodeca/js-yaml/compare/3.14.2...3.15.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@xmldom/xmldom` from 0.8.11 to 0.8.15\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/xmldom/xmldom/releases\"\u003e@​xmldom/xmldom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.8.15\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/xmldom/xmldom/compare/0.8.14...0.8.15\"\u003eCommits\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity: parsing a deeply or repeatedly namespaced document no longer consumes quadratic memory; the in-scope namespace map is inherited through the prototype chain instead of being copied for every prefix-declaring element (O(N) instead of O(N²)), preventing a denial-of-service reachable from \u003ccode\u003eDOMParser.parseFromString\u003c/code\u003e with default options. Serialized output is byte-identical. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-965w-775f-mr7g\"\u003e\u003ccode\u003eGHSA-965w-775f-mr7g\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: attribute de-duplication during parsing is now O(M) instead of O(M²); the \u003ccode\u003eNamedNodeMap\u003c/code\u003e parse-time dedup path uses a null-prototype membership index, so a well-formed document with a hostile number of duplicate attributes can no longer wedge the parse. Attribute order and duplicate resolution (last value wins, first position kept) are byte-identical, preserving the XML \u003ca href=\"https://www.w3.org/TR/xml/#uniqattspec\"\u003eno-duplicate-attributes well-formedness constraint\u003c/a\u003e. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-8344-3jmq-59r6\"\u003e\u003ccode\u003eGHSA-8344-3jmq-59r6\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: trimming trailing whitespace from an XML end tag (\u003ca href=\"https://www.w3.org/TR/xml/#NT-ETag\"\u003e\u003ccode\u003eETag\u003c/code\u003e\u003c/a\u003e) is now anchored so it runs in linear time instead of backtracking quadratically on a long whitespace run, preventing a ReDoS reachable from \u003ccode\u003eDOMParser.parseFromString\u003c/code\u003e. Trimmed output is byte-identical. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-x4fp-j954-r2f4\"\u003e\u003ccode\u003eGHSA-x4fp-j954-r2f4\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: malformed-input recovery is now linear instead of quadratic — the malformed tag-name scan terminates at an embedded \u003ccode\u003e\u0026lt;\u003c/code\u003e, and \u003ccode\u003eNode.prototype.normalize()\u003c/code\u003e merges adjacent text nodes in O(K) instead of O(K²) (also reachable programmatically), per \u003ca href=\"https://dom.spec.whatwg.org/#dom-node-normalize\"\u003e\u003ccode\u003enormalize()\u003c/code\u003e\u003c/a\u003e in the WHATWG DOM spec. DOM output is unchanged; only the reported error text differs. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-93r5-fhx6-vmg9\"\u003e\u003ccode\u003eGHSA-93r5-fhx6-vmg9\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: \u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e under \u003ccode\u003e{ requireWellFormed: true }\u003c/code\u003e now rejects a DocType \u003ccode\u003ename\u003c/code\u003e that is not a valid XML \u003ca href=\"https://www.w3.org/TR/xml/#NT-Name\"\u003e\u003ccode\u003eName\u003c/code\u003e\u003c/a\u003e, throwing \u003ccode\u003eInvalidStateError\u003c/code\u003e — matching the sibling \u003ccode\u003epublicId\u003c/code\u003e/\u003ccode\u003esystemId\u003c/code\u003e/\u003ccode\u003einternalSubset\u003c/code\u003e checks and preventing XML injection via \u003ccode\u003eDocumentType.name\u003c/code\u003e. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-27p8-2357-5qqv\"\u003e\u003ccode\u003eGHSA-27p8-2357-5qqv\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: \u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e under \u003ccode\u003e{ requireWellFormed: true }\u003c/code\u003e now validates a processing-instruction target as an XML \u003ca href=\"https://www.w3.org/TR/xml-names/#NT-NCName\"\u003e\u003ccode\u003eNCName\u003c/code\u003e\u003c/a\u003e and rejects a case-insensitive \u003ccode\u003exml\u003c/code\u003e, throwing \u003ccode\u003eInvalidStateError\u003c/code\u003e — a check \u003ccode\u003e0.8.x\u003c/code\u003e did not previously perform, preventing PI-target injection via \u003ccode\u003e\u0026gt;\u003c/code\u003e, \u003ccode\u003e?\u003c/code\u003e, or whitespace. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-c7q8-3ch8-vqpv\"\u003e\u003ccode\u003eGHSA-c7q8-3ch8-vqpv\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: \u003ccode\u003eDocument.createEntityReference()\u003c/code\u003e now rejects an invalid XML \u003ca href=\"https://www.w3.org/TR/xml/#NT-Name\"\u003e\u003ccode\u003eName\u003c/code\u003e\u003c/a\u003e at creation, and \u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e under \u003ccode\u003e{ requireWellFormed: true }\u003c/code\u003e validates an \u003ccode\u003eEntityReference\u003c/code\u003e \u003ccode\u003enodeName\u003c/code\u003e as an XML \u003ccode\u003eName\u003c/code\u003e, throwing \u003ccode\u003eInvalidStateError\u003c/code\u003e — preventing XML injection via an entity-reference name. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-6gmq-8vp8-gcm6\"\u003e\u003ccode\u003eGHSA-6gmq-8vp8-gcm6\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: the parser now reports a not-well-formed end tag whose valid name is followed by trailing content as a recoverable \u003ccode\u003eerror\u003c/code\u003e instead of accepting it silently, per the XML \u003ca href=\"https://www.w3.org/TR/xml/#NT-ETag\"\u003e\u003ccode\u003eETag\u003c/code\u003e\u003c/a\u003e production; parsing recovers to the byte-identical DOM. Consumers that want strict rejection can escalate the reported \u003ccode\u003eerror\u003c/code\u003e to fatal via the parser's \u003ccode\u003eerrorHandler\u003c/code\u003e. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-6h8r-xr42-gp59\"\u003e\u003ccode\u003eGHSA-6h8r-xr42-gp59\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThank you,\n\u003ca href=\"https://github.com/ericchiang\"\u003e\u003ccode\u003e@​ericchiang\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/bhaswanthc\"\u003e\u003ccode\u003e@​bhaswanthc\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/arpitjain099\"\u003e\u003ccode\u003e@​arpitjain099\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/Paranoidgrinch\"\u003e\u003ccode\u003e@​Paranoidgrinch\u003c/code\u003e\u003c/a\u003e,\nfor your contributions\u003c/p\u003e\n\u003ch2\u003e0.8.14\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/xmldom/xmldom/compare/0.8.13...0.8.14\"\u003eCommits\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity: \u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e now also rejects invalid element and attribute names when \u003ccode\u003e{ requireWellFormed: true }\u003c/code\u003e is passed, throwing \u003ccode\u003eInvalidStateError\u003c/code\u003e for a name that is not a valid XML \u003ca href=\"https://www.w3.org/TR/xml-names/#NT-QName\"\u003e\u003ccode\u003eQName\u003c/code\u003e\u003c/a\u003e (this covers the namespace prefix, which surfaces in the element qualified name or in a synthesized \u003ccode\u003exmlns:\u003c/code\u003e declaration). This prevents XML injection via \u003ccode\u003ecreateElement()\u003c/code\u003e / \u003ccode\u003esetAttribute()\u003c/code\u003e, extending the existing \u003ccode\u003erequireWellFormed\u003c/code\u003e checks to the serialized name set. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-w2rr-34g9-rvrj\"\u003e\u003ccode\u003eGHSA-w2rr-34g9-rvrj\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-4w3w-2rp5-g8jm\"\u003e\u003ccode\u003eGHSA-4w3w-2rp5-g8jm\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThank you,\n\u003ca href=\"https://github.com/bhaswanthc\"\u003e\u003ccode\u003e@​bhaswanthc\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/jmestwa-coder\"\u003e\u003ccode\u003e@​jmestwa-coder\u003c/code\u003e\u003c/a\u003e,\nfor your contributions\u003c/p\u003e\n\u003ch2\u003e0.8.13\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/xmldom/xmldom/compare/0.8.12...0.8.13\"\u003eCommits\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity: \u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e (and \u003ccode\u003eNode.toString()\u003c/code\u003e, \u003ccode\u003eNodeList.toString()\u003c/code\u003e) now accept a \u003ccode\u003erequireWellFormed\u003c/code\u003e option (fourth argument, after \u003ccode\u003eisHtml\u003c/code\u003e and \u003ccode\u003enodeFilter\u003c/code\u003e). When \u003ccode\u003e{ requireWellFormed: true }\u003c/code\u003e is passed, the serializer throws \u003ccode\u003eInvalidStateError\u003c/code\u003e for injection-prone node content, preventing XML injection via attacker-controlled node data. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-j759-j44w-7fr8\"\u003e\u003ccode\u003eGHSA-j759-j44w-7fr8\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-x6wf-f3px-wcqx\"\u003e\u003ccode\u003eGHSA-x6wf-f3px-wcqx\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-f6ww-3ggp-fr8h\"\u003e\u003ccode\u003eGHSA-f6ww-3ggp-fr8h\u003c/code\u003e\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003eComment: throws when \u003ccode\u003edata\u003c/code\u003e contains \u003ccode\u003e--\u0026gt;\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eProcessingInstruction: throws when \u003ccode\u003edata\u003c/code\u003e contains \u003ccode\u003e?\u0026gt;\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eDocumentType: throws when \u003ccode\u003epublicId\u003c/code\u003e fails \u003ccode\u003ePubidLiteral\u003c/code\u003e, \u003ccode\u003esystemId\u003c/code\u003e fails \u003ccode\u003eSystemLiteral\u003c/code\u003e, or \u003ccode\u003einternalSubset\u003c/code\u003e contains \u003ccode\u003e]\u0026gt;\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSecurity: DOM traversal operations (\u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e, \u003ccode\u003eNode.prototype.normalize()\u003c/code\u003e, \u003ccode\u003eNode.prototype.cloneNode(true)\u003c/code\u003e, \u003ccode\u003eDocument.prototype.importNode(node, true)\u003c/code\u003e, \u003ccode\u003enode.textContent\u003c/code\u003e getter, \u003ccode\u003egetElementsByTagName()\u003c/code\u003e / \u003ccode\u003egetElementsByTagNameNS()\u003c/code\u003e / \u003ccode\u003egetElementsByClassName()\u003c/code\u003e / \u003ccode\u003egetElementById()\u003c/code\u003e) are now iterative. Previously, deeply nested DOM trees would exhaust the JavaScript call stack and throw an unrecoverable \u003ccode\u003eRangeError\u003c/code\u003e. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-2v35-w6hq-6mfw\"\u003e\u003ccode\u003eGHSA-2v35-w6hq-6mfw\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThank you,\n\u003ca href=\"https://github.com/Jvr2022\"\u003e\u003ccode\u003e@​Jvr2022\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/praveen-kv\"\u003e\u003ccode\u003e@​praveen-kv\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/TharVid\"\u003e\u003ccode\u003e@​TharVid\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/decsecre583\"\u003e\u003ccode\u003e@​decsecre583\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/tlsbollei\"\u003e\u003ccode\u003e@​tlsbollei\u003c/code\u003e\u003c/a\u003e,\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/xmldom/xmldom/blob/master/CHANGELOG.md\"\u003e@​xmldom/xmldom's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/xmldom/xmldom/compare/0.8.14...0.8.15\"\u003e0.8.15\u003c/a\u003e\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity: parsing a deeply or repeatedly namespaced document no longer consumes quadratic memory; the in-scope namespace map is inherited through the prototype chain instead of being copied for every prefix-declaring element (O(N) instead of O(N²)), preventing a denial-of-service reachable from \u003ccode\u003eDOMParser.parseFromString\u003c/code\u003e with default options. Serialized output is byte-identical. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-965w-775f-mr7g\"\u003e\u003ccode\u003eGHSA-965w-775f-mr7g\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: attribute de-duplication during parsing is now O(M) instead of O(M²); the \u003ccode\u003eNamedNodeMap\u003c/code\u003e parse-time dedup path uses a null-prototype membership index, so a well-formed document with a hostile number of duplicate attributes can no longer wedge the parse. Attribute order and duplicate resolution (last value wins, first position kept) are byte-identical, preserving the XML \u003ca href=\"https://www.w3.org/TR/xml/#uniqattspec\"\u003eno-duplicate-attributes well-formedness constraint\u003c/a\u003e. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-8344-3jmq-59r6\"\u003e\u003ccode\u003eGHSA-8344-3jmq-59r6\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: trimming trailing whitespace from an XML end tag (\u003ca href=\"https://www.w3.org/TR/xml/#NT-ETag\"\u003e\u003ccode\u003eETag\u003c/code\u003e\u003c/a\u003e) is now anchored so it runs in linear time instead of backtracking quadratically on a long whitespace run, preventing a ReDoS reachable from \u003ccode\u003eDOMParser.parseFromString\u003c/code\u003e. Trimmed output is byte-identical. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-x4fp-j954-r2f4\"\u003e\u003ccode\u003eGHSA-x4fp-j954-r2f4\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: malformed-input recovery is now linear instead of quadratic — the malformed tag-name scan terminates at an embedded \u003ccode\u003e\u0026lt;\u003c/code\u003e, and \u003ccode\u003eNode.prototype.normalize()\u003c/code\u003e merges adjacent text nodes in O(K) instead of O(K²) (also reachable programmatically), per \u003ca href=\"https://dom.spec.whatwg.org/#dom-node-normalize\"\u003e\u003ccode\u003enormalize()\u003c/code\u003e\u003c/a\u003e in the WHATWG DOM spec. DOM output is unchanged; only the reported error text differs. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-93r5-fhx6-vmg9\"\u003e\u003ccode\u003eGHSA-93r5-fhx6-vmg9\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: \u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e under \u003ccode\u003e{ requireWellFormed: true }\u003c/code\u003e now rejects a DocType \u003ccode\u003ename\u003c/code\u003e that is not a valid XML \u003ca href=\"https://www.w3.org/TR/xml/#NT-Name\"\u003e\u003ccode\u003eName\u003c/code\u003e\u003c/a\u003e, throwing \u003ccode\u003eInvalidStateError\u003c/code\u003e — matching the sibling \u003ccode\u003epublicId\u003c/code\u003e/\u003ccode\u003esystemId\u003c/code\u003e/\u003ccode\u003einternalSubset\u003c/code\u003e checks and preventing XML injection via \u003ccode\u003eDocumentType.name\u003c/code\u003e. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-27p8-2357-5qqv\"\u003e\u003ccode\u003eGHSA-27p8-2357-5qqv\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: \u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e under \u003ccode\u003e{ requireWellFormed: true }\u003c/code\u003e now validates a processing-instruction target as an XML \u003ca href=\"https://www.w3.org/TR/xml-names/#NT-NCName\"\u003e\u003ccode\u003eNCName\u003c/code\u003e\u003c/a\u003e and rejects a case-insensitive \u003ccode\u003exml\u003c/code\u003e, throwing \u003ccode\u003eInvalidStateError\u003c/code\u003e — a check \u003ccode\u003e0.8.x\u003c/code\u003e did not previously perform, preventing PI-target injection via \u003ccode\u003e\u0026gt;\u003c/code\u003e, \u003ccode\u003e?\u003c/code\u003e, or whitespace. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-c7q8-3ch8-vqpv\"\u003e\u003ccode\u003eGHSA-c7q8-3ch8-vqpv\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: \u003ccode\u003eDocument.createEntityReference()\u003c/code\u003e now rejects an invalid XML \u003ca href=\"https://www.w3.org/TR/xml/#NT-Name\"\u003e\u003ccode\u003eName\u003c/code\u003e\u003c/a\u003e at creation, and \u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e under \u003ccode\u003e{ requireWellFormed: true }\u003c/code\u003e validates an \u003ccode\u003eEntityReference\u003c/code\u003e \u003ccode\u003enodeName\u003c/code\u003e as an XML \u003ccode\u003eName\u003c/code\u003e, throwing \u003ccode\u003eInvalidStateError\u003c/code\u003e — preventing XML injection via an entity-reference name. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-6gmq-8vp8-gcm6\"\u003e\u003ccode\u003eGHSA-6gmq-8vp8-gcm6\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: the parser now reports a not-well-formed end tag whose valid name is followed by trailing content as a recoverable \u003ccode\u003eerror\u003c/code\u003e instead of accepting it silently, per the XML \u003ca href=\"https://www.w3.org/TR/xml/#NT-ETag\"\u003e\u003ccode\u003eETag\u003c/code\u003e\u003c/a\u003e production; parsing recovers to the byte-identical DOM. Consumers that want strict rejection can escalate the reported \u003ccode\u003eerror\u003c/code\u003e to fatal via the parser's \u003ccode\u003eerrorHandler\u003c/code\u003e. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-6h8r-xr42-gp59\"\u003e\u003ccode\u003eGHSA-6h8r-xr42-gp59\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThank you,\n\u003ca href=\"https://github.com/ericchiang\"\u003e\u003ccode\u003e@​ericchiang\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/bhaswanthc\"\u003e\u003ccode\u003e@​bhaswanthc\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/arpitjain099\"\u003e\u003ccode\u003e@​arpitjain099\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/Paranoidgrinch\"\u003e\u003ccode\u003e@​Paranoidgrinch\u003c/code\u003e\u003c/a\u003e,\nfor your contributions\u003c/p\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/xmldom/xmldom/compare/0.9.10...0.9.11\"\u003e0.9.11\u003c/a\u003e\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity: \u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e now also rejects invalid element and attribute names when \u003ccode\u003e{ requireWellFormed: true }\u003c/code\u003e is passed, throwing \u003ccode\u003eInvalidStateError\u003c/code\u003e for a name that is not a valid XML \u003ca href=\"https://www.w3.org/TR/xml-names/#NT-QName\"\u003e\u003ccode\u003eQName\u003c/code\u003e\u003c/a\u003e (this covers the namespace prefix, which surfaces in the element qualified name or in a synthesized \u003ccode\u003exmlns:\u003c/code\u003e declaration). This prevents XML injection via \u003ccode\u003ecreateElement()\u003c/code\u003e / \u003ccode\u003esetAttribute()\u003c/code\u003e, extending the existing \u003ccode\u003erequireWellFormed\u003c/code\u003e checks to the serialized name set. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-w2rr-34g9-rvrj\"\u003e\u003ccode\u003eGHSA-w2rr-34g9-rvrj\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-4w3w-2rp5-g8jm\"\u003e\u003ccode\u003eGHSA-4w3w-2rp5-g8jm\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSecurity: the processing-instruction grammar regex no longer backtracks quadratically on an unterminated processing instruction (\u003ccode\u003e\u0026lt;?…\u003c/code\u003e with no closing \u003ccode\u003e?\u0026gt;\u003c/code\u003e), preventing a denial-of-service (ReDoS) reachable from \u003ccode\u003eDOMParser.parseFromString\u003c/code\u003e with default options. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-g53g-w8rj-fmg7\"\u003e\u003ccode\u003eGHSA-g53g-w8rj-fmg7\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eCharacterData\u003c/code\u003e \u003ccode\u003enodeValue\u003c/code\u003e and \u003ccode\u003edata\u003c/code\u003e are now kept in sync \u003ca href=\"https://redirect.github.com/xmldom/xmldom/pull/990\"\u003e\u003ccode\u003e[#990](https://github.com/xmldom/xmldom/issues/990)\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChore\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eupdated dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThank you,\n\u003ca href=\"https://github.com/bhaswanthc\"\u003e\u003ccode\u003e@​bhaswanthc\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/jmestwa-coder\"\u003e\u003ccode\u003e@​jmestwa-coder\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/stevenobiajulu\"\u003e\u003ccode\u003e@​stevenobiajulu\u003c/code\u003e\u003c/a\u003e,\nfor your contributions\u003c/p\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/xmldom/xmldom/compare/0.8.13...0.8.14\"\u003e0.8.14\u003c/a\u003e\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity: \u003ccode\u003eXMLSerializer.serializeToString()\u003c/code\u003e now also rejects invalid element and attribute names when \u003ccode\u003e{ requireWellFormed: true }\u003c/code\u003e is passed, throwing \u003ccode\u003eInvalidStateError\u003c/code\u003e for a name that is not a valid XML \u003ca href=\"https://www.w3.org/TR/xml-names/#NT-QName\"\u003e\u003ccode\u003eQName\u003c/code\u003e\u003c/a\u003e (this covers the namespace prefix, which surfaces in the element qualified name or in a synthesized \u003ccode\u003exmlns:\u003c/code\u003e declaration). This prevents XML injection via \u003ccode\u003ecreateElement()\u003c/code\u003e / \u003ccode\u003esetAttribute()\u003c/code\u003e, extending the existing \u003ccode\u003erequireWellFormed\u003c/code\u003e checks to the serialized name set. \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-w2rr-34g9-rvrj\"\u003e\u003ccode\u003eGHSA-w2rr-34g9-rvrj\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://github.com/xmldom/xmldom/security/advisories/GHSA-4w3w-2rp5-g8jm\"\u003e\u003ccode\u003eGHSA-4w3w-2rp5-g8jm\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThank you,\n\u003ca href=\"https://github.com/bhaswanthc\"\u003e\u003ccode\u003e@​bhaswanthc\u003c/code\u003e\u003c/a\u003e,\n\u003ca href=\"https://github.com/jmestwa-coder\"\u003e\u003ccode\u003e@​jmestwa-coder\u003c/code\u003e\u003c/a\u003e,\nfor your contributions\u003c/p\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/xmldom/xmldom/compare/0.9.9...0.9.10\"\u003e0.9.10\u003c/a\u003e\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/xmldom/xmldom/commit/b5b8fb5b579ae1183b34e74b3bc39d7eb50a226a\"\u003e\u003ccode\u003eb5b8fb5\u003c/code\u003e\u003c/a\u003e 0.8.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/xmldom/xmldom/commit/327508ea98d169285b2c0559836332a9879de213\"\u003e\u003ccode\u003e327508e\u003c/code\u003e\u003c/a\u003e docs: add 0.8.15 CHANGELOG entry\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/xmldom/xmldom/commit/f40ccb861eee0acbf5ee4feb9a34932e87b329c9\"\u003e\u003ccode\u003ef40ccb8\u003c/code\u003e\u003c/a\u003e fix: prevent quadratic malformed-tag recovery and normalize() adjacent-text m...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/xmldom/xmldom/commit/3abb0934f5a8a84d83a1f9cde0f2bd04c08b2a09\"\u003e\u003ccode\u003e3abb093\u003c/code\u003e\u003c/a\u003e fix: prevent end-tag whitespace-trim ReDoS via anchored trim (GHSA-x4fp-j954-...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/xmldom/xmldom/commit/2c548f200cfec991cd5846627ef8f03542309213\"\u003e\u003ccode\u003e2c548f2\u003c/code\u003e\u003c/a\u003e fix: prevent quadratic attribute de-duplication via null-prototype membership...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/xmldom/xmldom/commit/08a74b47c7f29d2e9b3212682856b959040d1838\"\u003e\u003ccode\u003e08a74b4\u003c/code\u003e\u003c/a\u003e test: characterize NamedNodeMap attribute de-duplication before the index ref...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/xmldom/xmldom/commit/954370f58c046223faf95ba77efcbc8ce014409d\"\u003e\u003ccode\u003e954370f\u003c/code\u003e\u003c/a\u003e fix: prevent quadratic namespace-map memory consumption via prototype-chain i...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/xmldom/xmldom/commit/4430189660b0d380ee9c9ee7550a1358688e8828\"\u003e\u003ccode\u003e4430189\u003c/code\u003e\u003c/a\u003e fix: report not-well-formed end-tag trailing content (GHSA-6h8r-xr42-gp59)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/xmldom/xmldom/commit/6c3fb5ffeafe7901ec928ce9010988dd716c94a0\"\u003e\u003ccode\u003e6c3fb5f\u003c/code\u003e\u003c/a\u003e fix: prevent XML injection via unsafe EntityReference name (GHSA-6gmq-8vp8-gcm6)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/xmldom/xmldom/commit/3b694872bcb5c7e3cbadba961a4be2488750ce5b\"\u003e\u003ccode\u003e3b69487\u003c/code\u003e\u003c/a\u003e fix: prevent XML injection via unsafe processing instruction target serializa...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/xmldom/xmldom/compare/0.8.11...0.8.15\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~karfau\"\u003ekarfau\u003c/a\u003e, a new releaser for \u003ccode\u003e@​xmldom/xmldom\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-uri` from 3.1.0 to 3.1.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastify/fast-uri/releases\"\u003efast-uri's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1.7\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis is a security release that fixes the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3\"\u003eGHSA-qw65-cvwx-89v3\u003c/a\u003e — authority injection via an unvalidated port in \u003ccode\u003eserialize()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g\"\u003eGHSA-58mr-gqgx-xq4g\u003c/a\u003e — host confusion via unbalanced or misplaced IP-literal brackets\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.7.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.6...v3.1.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.6\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eThis release addresses the following high-severity security advisories:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-5jgf-p345-68v8\"\u003eGHSA-5jgf-p345-68v8\u003c/a\u003e — host confusion via skipped IDN canonicalization on scheme-relative references\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-fph4-wmhf-6fwf\"\u003eGHSA-fph4-wmhf-6fwf\u003c/a\u003e — server-side request forgery via repeated hostname percent-decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-f65p-4m7j-42xc\"\u003eGHSA-f65p-4m7j-42xc\u003c/a\u003e — server-side request forgery via malformed IPv6 normalization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-jqff-g426-hqxp\"\u003eGHSA-jqff-g426-hqxp\u003c/a\u003e — host confusion via percent-encoded scheme normalization\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eUsers of the v3.x release line should upgrade to v3.1.6.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.5\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Warning\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-7p8r-x3mc-p8w7\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.4...v3.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.4\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cp\u003eFix for \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.3\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes: \u003ca href=\"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\"\u003ehttps://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\"\u003ehttps://github.com/fastify/fast-uri/compare/v3.1.2...v3.1.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security Release\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/412e40abd4eb8beabfb952d80abf949a2baf27a3\"\u003e\u003ccode\u003e412e40a\u003c/code\u003e\u003c/a\u003e Bumped v3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/9f4c943e4d2133e8d78e0941203879216255bb01\"\u003e\u003ccode\u003e9f4c943\u003c/code\u003e\u003c/a\u003e fix: backport port and IP-literal validation to v3.x (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/216\"\u003e#216\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/1eb3ce436fe050807caba79f886ab894f485a588\"\u003e\u003ccode\u003e1eb3ce4\u003c/code\u003e\u003c/a\u003e fix: treat unterminated bracket hosts as reg-names again (\u003ca href=\"https://redirect.github.com/fastify/fast-uri/issues/214\"\u003e#214\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/6f970b2951fd896aa0f3a7ff28eeb6640c137d33\"\u003e\u003ccode\u003e6f970b2\u003c/code\u003e\u003c/a\u003e Bumped v3.1.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/d941579a84273ec7e96bde596b1f7a8be447df2a\"\u003e\u003ccode\u003ed941579\u003c/code\u003e\u003c/a\u003e fix: never run IDN canonicalization on bracketed IP literals\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/c0f0279cf370cb89ee56b04bbcde2a7afbe81aba\"\u003e\u003ccode\u003ec0f0279\u003c/code\u003e\u003c/a\u003e test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/37f3417c82994279656854f83ce938acd81c3862\"\u003e\u003ccode\u003e37f3417\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/607bfbe953f28a14c2e06ae64aff38c81ca2937f\"\u003e\u003ccode\u003e607bfbe\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/ae92a4c5d8c4b6c9e447f048d5fcbde7eebd5514\"\u003e\u003ccode\u003eae92a4c\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastify/fast-uri/commit/444ecdad447db2cc23c4d422acc6f0daa6fa8eef\"\u003e\u003ccode\u003e444ecda\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastify/fast-uri/compare/v3.1.0...v3.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nanoid` from 3.3.11 to 3.3.19\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/releases\"\u003enanoid's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed breaking Nano ID by requesting big ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/blob/main/CHANGELOG.md\"\u003enanoid's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID (by \u003ca href=\"https://github.com/geoffrey-diederichs\"\u003e\u003ccode\u003e@​geoffrey-diederichs\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed breaking Nano ID by requesting big ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/eb63bd6775188dc35d143bf24868be094f19b5ee\"\u003e\u003ccode\u003eeb63bd6\u003c/code\u003e\u003c/a\u003e Release 3.3.19 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9067e0361a643ab2c94ddd67606efbf275f6c0dd\"\u003e\u003ccode\u003e9067e03\u003c/code\u003e\u003c/a\u003e Sync CJS and ESM\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9ad98052b316c5e707f8098ace509d2ae165e54d\"\u003e\u003ccode\u003e9ad9805\u003c/code\u003e\u003c/a\u003e Release 3.3.18 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/55e50a0621ec084b4bb4000ea4e86e1191bd3da8\"\u003e\u003ccode\u003e55e50a0\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e10f8d40ce9d1ab47f66d65a16b48086432730d0\"\u003e\u003ccode\u003ee10f8d4\u003c/code\u003e\u003c/a\u003e Update index.native.js (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/606\"\u003e#606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/73d67168136b36fd3b644159b0cff149da4905d9\"\u003e\u003ccode\u003e73d6716\u003c/code\u003e\u003c/a\u003e Release 3.3.17 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/f9d13f150847d117877adee3460a46eceb0cf49b\"\u003e\u003ccode\u003ef9d13f1\u003c/code\u003e\u003c/a\u003e Sync 0 size behaviour with PostCSS 5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9760e112757cf7d46a79abd7a133bc4958757bb8\"\u003e\u003ccode\u003e9760e11\u003c/code\u003e\u003c/a\u003e Release 3.3.16 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66d\"\u003e\u003ccode\u003ee835c9b\u003c/code\u003e\u003c/a\u003e fix(non-secure): clamp negative size to prevent infinite loop (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/601\"\u003e#601\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/96dd086eb24396a275fa93ee78d73b2fece35809\"\u003e\u003ccode\u003e96dd086\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ai/nanoid/compare/3.3.11...3.3.19\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for nanoid since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.4.49 to 8.5.28\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.28\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes types regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed removing any comments starting with \u003ccode\u003e/*#\u003c/code\u003e (by \u003ca href=\"https://github.com/dylanpulver\"\u003e\u003ccode\u003e@​dylanpulver\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e*\u003c/code\u003e hack before a comment in Custom Properties (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed empty values in the middle of \u003ccode\u003elist.comma()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed whitespace-only values in \u003ccode\u003elist.space()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed rule’s end position on space before semicolon (by \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/romainmenke\"\u003e\u003ccode\u003e@​romainmenke\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed Chinese text in deprecation warning (by \u003ca href=\"https://github.com/Jesse205\"\u003e\u003ccode\u003e@​Jesse205\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.28\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes types regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed removing any comments starting with \u003ccode\u003e/*#\u003c/code\u003e (by \u003ca href=\"https://github.com/dylanpulver\"\u003e\u003ccode\u003e@​dylanpulver\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e*\u003c/code\u003e hack before a comment in Custom Properties (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed empty values in the middle of \u003ccode\u003elist.comma()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed whitespace-only values in \u003ccode\u003elist.space()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed rule’s end position on space before semicolon (by \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/romainmenke\"\u003e\u003ccode\u003e@​romainmenke\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed Chinese text in deprecation warning (by \u003ca href=\"https://github.com/Jesse205\"\u003e\u003ccode\u003e@​Jesse205\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/e544bffc4f4b3966d8ec69c41744b3ed65afc64a\"\u003e\u003ccode\u003ee544bff\u003c/code\u003e\u003c/a\u003e Release 8.5.28 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f8fc2525717a6a7216659f7be43c525f60c6a15a\"\u003e\u003ccode\u003ef8fc252\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/5039fd78962d285abea5d7b3aebef32f053781ce\"\u003e\u003ccode\u003e5039fd7\u003c/code\u003e\u003c/a\u003e Add missed release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/ae40ca499cf6a9afdbb264c0ec09e71fe934e2af\"\u003e\u003ccode\u003eae40ca4\u003c/code\u003e\u003c/a\u003e Release 8.5.27 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/62b1626bb7fbb28eda616d002cbd525d239b18ba\"\u003e\u003ccode\u003e62b1626\u003c/code\u003e\u003c/a\u003e Fix linter\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/1dba9384515a2dbc64517697c2f738b6d5c3f9a4\"\u003e\u003ccode\u003e1dba938\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3e82edc9f037faa41647342dceceba9b841f9881\"\u003e\u003ccode\u003e3e82edc\u003c/code\u003e\u003c/a\u003e Keep non-annotation comments when the processor has no plugins (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2150\"\u003e#2150\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/6d23bc362203118478bc8051b81f2910907ebe6e\"\u003e\u003ccode\u003e6d23bc3\u003c/code\u003e\u003c/a\u003e Fix link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/508e9976be81536292e7666741e1c35e876b9a6a\"\u003e\u003ccode\u003e508e997\u003c/code\u003e\u003c/a\u003e Add GitHub Sponsors link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/e993739dc49b6055f7dfc59b161d75702f0b2b8b\"\u003e\u003ccode\u003ee993739\u003c/code\u003e\u003c/a\u003e Add CodeRabbit sponsor (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2145\"\u003e#2145\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.4.49...8.5.28\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `shell-quote` from 1.8.3 to 1.10.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md\"\u003eshell-quote's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.9.0...v1.10.0\"\u003ev1.10.0\u003c/a\u003e - 2026-07-10\u003c/h2\u003e\n\u003ch3\u003eMerged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[New] \u003ccode\u003eparse\u003c/code\u003e: add opt-in \u003ccode\u003esplitUnquoted\u003c/code\u003e option for shell field-splitting of unquoted expansions \u003ca href=\"https://redirect.github.com/ljharb/shell-quote/pull/1\"\u003e\u003ccode\u003e[#1](https://github.com/ljharb/shell-quote/issues/1)\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: match nested \u003ccode\u003e${...}\u003c/code\u003e braces so nested parameter expansion is consumed as one substitution \u003ca href=\"https://github.com/ljharb/shell-quote/commit/c0842c8a7a034066da2496a75e91cbe500ff736c\"\u003e\u003ccode\u003ec0842c8\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003eparse\u003c/code\u003e: pin single-quote literalness and unmatched-quote handling \u003ca href=\"https://github.com/ljharb/shell-quote/commit/a0d03e35c8ede24016502c4433b8f5d6b3100a62\"\u003e\u003ccode\u003ea0d03e3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] remove the space in js code fences so evalmd evaluates them \u003ca href=\"https://github.com/ljharb/shell-quote/commit/2116fa36aeea77fe8d561b0db46b1f9b26b8cf1b\"\u003e\u003ccode\u003e2116fa3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003equote\u003c/code\u003e: pin conservative escaping of \u003ccode\u003e=\u003c/code\u003e, \u003ccode\u003e@\u003c/code\u003e, \u003ccode\u003e^\u003c/code\u003e, \u003ccode\u003e,\u003c/code\u003e, \u003ccode\u003e:\u003c/code\u003e, \u003ccode\u003e!\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/1c36f3ff77d26d200620c1027e5c271050120b8e\"\u003e\u003ccode\u003e1c36f3f\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] document that \u003ccode\u003equote\u003c/code\u003e outputs POSIX quoting, not \u003ccode\u003ecmd.exe\u003c/code\u003e/PowerShell \u003ca href=\"https://github.com/ljharb/shell-quote/commit/100e96e0ffadcca97d63dda15651c70b9f83507c\"\u003e\u003ccode\u003e100e96e\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] document \u003ccode\u003eparse\u003c/code\u003e's supported parameter-expansion subset \u003ca href=\"https://github.com/ljharb/shell-quote/commit/e1c75cd6e4a3c60003792c7f2802587d328622cb\"\u003e\u003ccode\u003ee1c75cd\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: a backslash inside single quotes must not escape the closing quote \u003ca href=\"https://github.com/ljharb/shell-quote/commit/5d460a332b54b83153297fe7d1964330b28fa491\"\u003e\u003ccode\u003e5d460a3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] fix stale example outputs \u003ca href=\"https://github.com/ljharb/shell-quote/commit/2de86f5d44f44d3ac9df36413d8a05f3534cdec6\"\u003e\u003ccode\u003e2de86f5\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003equote\u003c/code\u003e: pin that a backslash with whitespace is not doubled in single quotes (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/14\"\u003e#14\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/190e236bcf1d81caa8e40e8ea3bb11998575be71\"\u003e\u003ccode\u003e190e236\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] \u003ccode\u003equote\u003c/code\u003e: use output verbatim; do not re-quote it (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/1b364683b1e9e8d078fd3017cde82cf10c9c04a5\"\u003e\u003ccode\u003e1b36468\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Refactor] \u003ccode\u003eparse\u003c/code\u003e: fix swapped \u003ccode\u003eSINGLE_QUOTE\u003c/code\u003e/\u003ccode\u003eDOUBLE_QUOTE\u003c/code\u003e variable names \u003ca href=\"https://github.com/ljharb/shell-quote/commit/801af5c935b27d6dcda63b3975d5e92a7b6f887f\"\u003e\u003ccode\u003e801af5c\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[types] fix an error TS v6 ignores but v7 fails on \u003ca href=\"https://github.com/ljharb/shell-quote/commit/59bbf8b81bf3236842deb72805744d489f650eba\"\u003e\u003ccode\u003e59bbf8b\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@arethetypeswrong/cli\u003c/code\u003e, \u003ccode\u003eevalmd\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/a04d47516e1cd5b1b4d3f720ddf97561ed0082fc\"\u003e\u003ccode\u003ea04d475\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@arethetypeswrong/ci\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/d390f9a92b97a04b1f799298634e90dc581021e6\"\u003e\u003ccode\u003ed390f9a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003equote\u003c/code\u003e: the tilde test escapes every \u003ccode\u003e~\u003c/code\u003e, not just a leading one (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/9\"\u003e#9\u003c/a\u003e) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/617d119795c7b44d6e49a4d41f80195c4aa5735c\"\u003e\u003ccode\u003e617d119\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.4...v1.9.0\"\u003ev1.9.0\u003c/a\u003e - 2026-06-24\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[New] add types \u003ca href=\"https://github.com/ljharb/shell-quote/commit/dca6e21a02df4cc1a83ed1b5baa4d82df134170a\"\u003e\u003ccode\u003edca6e21\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9aa9e8f60991f8c4053a29e476795d891ff851ad\"\u003e\u003ccode\u003e9aa9e8f\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: finalize tokens in linear time (GHSA-395f-4hp3-45gv) \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7ff5488599d01c323514f02f5efb74088dd134ec\"\u003e\u003ccode\u003e7ff5488\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] update workflows \u003ca href=\"https://github.com/ljharb/shell-quote/commit/75e849741ffaf2d3aa53ae0e18ef6bf9929ef478\"\u003e\u003ccode\u003e75e8497\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] Windows + node 4/6/7: pin eslint to 9 before install, since npm 2/3 cannot stage eslint 10\u003ccode\u003e@types/esrecurse\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/3fb739de44b81c69431947d54fbfc18998dd6d72\"\u003e\u003ccode\u003e3fb739d\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] retry \u003ccode\u003enpm install\u003c/code\u003e on Windows to survive npm 2/3 staging-rename flake \u003ca href=\"https://github.com/ljharb/shell-quote/commit/abe0163293c82963fa8a16cfaa87181846d5aced\"\u003e\u003ccode\u003eabe0163\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[actions] Windows + node 5/7: install deps with a modern node \u003ca href=\"https://github.com/ljharb/shell-quote/commit/b4bafa2e7e58d53d9839b1c24976f61e54b43326\"\u003e\u003ccode\u003eb4bafa2\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003equote\u003c/code\u003e: escape leading \u003ccode\u003e~\u003c/code\u003e to prevent shell tilde-expansion \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7a76c1a12d8461c2234a1c655b943cee84cbff91\"\u003e\u003ccode\u003e7a76c1a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003etape\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/7184b4458b65c17b931e126d8cb5f586c6717dc8\"\u003e\u003ccode\u003e7184b44\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] apparently \u003ccode\u003ejackspeak\u003c/code\u003e is no longer in the graph \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9ba368a4057b9f498b0fef23b5b15543ef81b98c\"\u003e\u003ccode\u003e9ba368a\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.3...v1.8.4\"\u003ev1.8.4\u003c/a\u003e - 2026-05-22\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] \u003ccode\u003equote\u003c/code\u003e: validate object-token shapes \u003ca href=\"https://github.com/ljharb/shell-quote/commit/4378a6e613db5948168684864e49b42b83134d2d\"\u003e\u003ccode\u003e4378a6e\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003enpmignore\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/22ebec04349065a45ad8afc8cc8d53c4624634a6\"\u003e\u003ccode\u003e22ebec0\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] increase coverage \u003ca href=\"https://github.com/ljharb/shell-quote/commit/9f3caa31900cc6ee64858b31134144c648ce206d\"\u003e\u003ccode\u003e9f3caa3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[readme] replace runkit CI badge with shields.io check-runs badge \u003ca href=\"https://github.com/ljharb/shell-quote/commit/3344a047dd1e95f71c4ca27522cbfd05c56277e0\"\u003e\u003ccode\u003e3344a04\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e \u003ca href=\"https://github.com/ljharb/shell-quote/commit/699c5113d135f4d4591574bebf173334ffa453d4\"\u003e\u003ccode\u003e699c511\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/64988d9a0e73a2ae710488952e3614958ef289d4\"\u003e\u003ccode\u003e64988d9\u003c/code\u003e\u003c/a\u003e v1.10.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/617d119795c7b44d6e49a4d41f80195c4aa5735c\"\u003e\u003ccode\u003e617d119\u003c/code\u003e\u003c/a\u003e [Tests] \u003ccode\u003equote\u003c/code\u003e: the tilde test escapes every \u003ccode\u003e~\u003c/code\u003e, not just a leading one (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/9\"\u003e#9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/59bbf8b81bf3236842deb72805744d489f650eba\"\u003e\u003ccode\u003e59bbf8b\u003c/code\u003e\u003c/a\u003e [types] fix an error TS v6 ignores but v7 fails on\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/190e236bcf1d81caa8e40e8ea3bb11998575be71\"\u003e\u003ccode\u003e190e236\u003c/code\u003e\u003c/a\u003e [Tests] \u003ccode\u003equote\u003c/code\u003e: pin that a backslash with whitespace is not doubled in singl...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/a04d47516e1cd5b1b4d3f720ddf97561ed0082fc\"\u003e\u003ccode\u003ea04d475\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003e@arethetypeswrong/cli\u003c/code\u003e, \u003ccode\u003eevalmd\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/b9545b39f4de17aa169410823c98acf58387e474\"\u003e\u003ccode\u003eb9545b3\u003c/code\u003e\u003c/a\u003e [New] \u003ccode\u003eparse\u003c/code\u003e: add opt-in \u003ccode\u003esplitUnquoted\u003c/code\u003e option for shell field-splitting of...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/1b364683b1e9e8d078fd3017cde82cf10c9c04a5\"\u003e\u003ccode\u003e1b36468\u003c/code\u003e\u003c/a\u003e [readme] \u003ccode\u003equote\u003c/code\u003e: use output verbatim; do not re-quote it (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/1c36f3ff77d26d200620c1027e5c271050120b8e\"\u003e\u003ccode\u003e1c36f3f\u003c/code\u003e\u003c/a\u003e [Tests] \u003ccode\u003equote\u003c/code\u003e: pin conservative escaping of \u003ccode\u003e=\u003c/code\u003e, \u003ccode\u003e@\u003c/code\u003e, \u003ccode\u003e^\u003c/code\u003e, \u003ccode\u003e,\u003c/code\u003e, \u003ccode\u003e:\u003c/code\u003e, \u003ccode\u003e!\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ljharb/shell-quote/issues/11\"\u003e#11\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/e1c75cd6e4a3c60003792c7f2802587d328622cb\"\u003e\u003ccode\u003ee1c75cd\u003c/code\u003e\u003c/a\u003e [readme] document \u003ccode\u003eparse\u003c/code\u003e's supported parameter-expansion subset\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/shell-quote/commit/c0842c8a7a034066da2496a75e91cbe500ff736c\"\u003e\u003ccode\u003ec0842c8\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003eparse\u003c/code\u003e: match nested \u003ccode\u003e${...}\u003c/code\u003e braces so nested parameter expansion is ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ljharb/shell-quote/compare/v1.8.3...v1.10.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/alvarolorentedev/opencode-mobile/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/alvarolorentedev/opencode-mobile/pull/27","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/alvarolorentedev%2Fopencode-mobile/issues/27","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/27/packages"}},{"old_version":"3.1.2","new_version":"3.1.7","update_type":"patch","path":null,"pr_created_at":"2026-09-12T01:37:52.000Z","version_change":"3.1.2 → 3.1.7","issue":{"uuid":"5430398047","node_id":"PR_kwDOS7WM1s8AAAABDN8dFA","number":13,"state":"open","title":"chore(deps): bump the npm-minor-patch group with 72 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-12T01:37:52.000Z","updated_at":"2026-09-12T01:39:55.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm-minor-patch","update_count":72,"packages":[{"name":"@applemusic-like-lyrics/vue","old_version":"0.5.1","new_version":"0.5.2","repository_url":"https://github.com/amll-dev/applemusic-like-lyrics"},{"name":"@neteasecloudmusicapienhanced/api","old_version":"4.35.1","new_version":"4.40.1","repository_url":"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced"},{"name":"@sansenjian/qq-music-api","old_version":"2.4.0","new_version":"2.6.0","repository_url":"https://github.com/sansenjian/qq-music-api"},{"name":"@sentry/node","old_version":"10.57.0","new_version":"10.73.0","repository_url":"https://github.com/getsentry/sentry-javascript"},{"name":"@sentry/vue","old_version":"10.57.0","new_version":"10.73.0","repository_url":"https://github.com/getsentry/sentry-javascript"},{"name":"@simplewebauthn/server","old_version":"13.3.1","new_version":"13.3.3","repository_url":"https://github.com/MasterKale/SimpleWebAuthn"},{"name":"@types/pg","old_version":"8.20.0","new_version":"8.23.1","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"axios","old_version":"1.17.0","new_version":"1.20.0","repository_url":"https://github.com/axios/axios"},{"name":"dayjs","old_version":"1.11.21","new_version":"1.11.23","repository_url":"https://github.com/iamkun/dayjs"},{"name":"jszip","old_version":"3.10.1","new_version":"3.10.2","repository_url":"https://github.com/Stuk/jszip"},{"name":"multer","old_version":"2.1.1","new_version":"2.3.0","repository_url":"https://github.com/expressjs/multer"},{"name":"@types/multer","old_version":"2.1.0","new_version":"2.2.0","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"sass","old_version":"1.101.0","new_version":"1.104.0","repository_url":"https://github.com/sass/dart-sass"},{"name":"tsx","old_version":"4.22.4","new_version":"4.23.13","repository_url":"https://github.com/privatenumber/tsx"},{"name":"zod","old_version":"4.4.3","new_version":"4.5.4","repository_url":"https://github.com/colinhacks/zod"},{"name":"prettier","old_version":"3.8.4","new_version":"3.9.6","repository_url":"https://github.com/prettier/prettier"},{"name":"@applemusic-like-lyrics/core","old_version":"0.5.1","new_version":"0.5.2","repository_url":"https://github.com/amll-dev/applemusic-like-lyrics"},{"name":"@babel/plugin-transform-modules-systemjs","old_version":"7.29.7","new_version":"7.29.8","repository_url":"https://github.com/babel/babel"},{"name":"@babel/plugin-transform-regenerator","old_version":"7.29.7","new_version":"7.29.8","repository_url":"https://github.com/babel/babel"},{"name":"@babel/plugin-transform-spread","old_version":"7.29.7","new_version":"7.29.8","repository_url":"https://github.com/babel/babel"},{"name":"@neteasecloudmusicapienhanced/unblockmusic-utils","old_version":"0.3.3","new_version":"0.4.4","repository_url":"https://github.com/NeteaseCloudMusicApiEnhanced/UnblockNeteaseMusic-utils"},{"name":"@opentelemetry/api-logs","old_version":"0.214.0","new_version":"0.220.0","repository_url":"https://github.com/open-telemetry/opentelemetry-js"},{"name":"@opentelemetry/core","old_version":"2.8.0","new_version":"2.11.0","repository_url":"https://github.com/open-telemetry/opentelemetry-js"},{"name":"@opentelemetry/instrumentation","old_version":"0.214.0","new_version":"0.220.0","repository_url":"https://github.com/open-telemetry/opentelemetry-js"},{"name":"@opentelemetry/resources","old_version":"2.8.0","new_version":"2.11.0","repository_url":"https://github.com/open-telemetry/opentelemetry-js"},{"name":"@opentelemetry/sdk-trace-base","old_version":"2.8.0","new_version":"2.11.0","repository_url":"https://github.com/open-telemetry/opentelemetry-js"},{"name":"@opentelemetry/semantic-conventions","old_version":"1.41.1","new_version":"1.43.0","repository_url":"https://github.com/open-telemetry/opentelemetry-js"},{"name":"@parcel/watcher-android-arm64","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-darwin-arm64","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-darwin-x64","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-freebsd-x64","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-linux-arm-glibc","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-linux-arm-musl","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-linux-arm64-glibc","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-linux-arm64-musl","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-linux-x64-glibc","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-linux-x64-musl","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-win32-arm64","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher-win32-x64","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@parcel/watcher","old_version":"2.5.6","new_version":"2.6.0","repository_url":"https://github.com/parcel-bundler/watcher"},{"name":"@peculiar/asn1-android","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@peculiar/asn1-cms","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@peculiar/asn1-csr","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@peculiar/asn1-ecc","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@peculiar/asn1-pfx","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@peculiar/asn1-pkcs8","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@peculiar/asn1-pkcs9","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@peculiar/asn1-rsa","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@peculiar/asn1-schema","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@peculiar/asn1-x509-attr","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@peculiar/asn1-x509","old_version":"2.8.0","new_version":"2.9.4","repository_url":"https://github.com/PeculiarVentures/asn1-schema"},{"name":"@sentry/browser","old_version":"10.57.0","new_version":"10.73.0","repository_url":"https://github.com/getsentry/sentry-javascript"},{"name":"@sentry/core","old_version":"10.57.0","new_version":"10.73.0","repository_url":"https://github.com/getsentry/sentry-javascript"},{"name":"@sentry/node-core","old_version":"10.57.0","new_version":"10.73.0","repository_url":"https://github.com/getsentry/sentry-javascript"},{"name":"@sentry/opentelemetry","old_version":"10.57.0","new_version":"10.73.0","repository_url":"https://github.com/getsentry/sentry-javascript"},{"name":"@types/express-serve-static-core","old_version":"5.1.1","new_version":"5.1.3","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"body-parser","old_version":"1.20.5","new_version":"1.20.8","repository_url":"https://github.com/expressjs/body-parser"},{"name":"cjs-module-lexer","old_version":"2.2.0","new_version":"2.2.1","repository_url":"https://github.com/nodejs/cjs-module-lexer"},{"name":"es-to-primitive","old_version":"1.3.0","new_version":"1.3.4","repository_url":"https://github.com/ljharb/es-to-primitive"},{"name":"fast-uri","old_version":"3.1.2","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"immutable","old_version":"5.1.6","new_version":"5.1.9","repository_url":"https://github.com/immutable-js/immutable-js"},{"name":"import-in-the-middle","old_version":"3.0.2","new_version":"3.5.0","repository_url":"https://github.com/nodejs/import-in-the-middle"},{"name":"ip-address","old_version":"10.2.0","new_version":"10.7.0","repository_url":"https://github.com/beaugunderson/ip-address"},{"name":"music-metadata","old_version":"11.13.0","new_version":"11.15.0","repository_url":"https://github.com/Borewit/music-metadata"},{"name":"own-keys","old_version":"1.0.1","new_version":"1.0.2","repository_url":"https://github.com/ljharb/own-keys"},{"name":"pg-protocol","old_version":"1.14.0","new_version":"1.16.0","repository_url":"https://github.com/brianc/node-postgres"},{"name":"pvutils","old_version":"1.1.5","new_version":"1.2.0","repository_url":"https://github.com/PeculiarVentures/pvutils"},{"name":"qs","old_version":"6.15.2","new_version":"6.15.3","repository_url":"https://github.com/ljharb/qs"},{"name":"sax","old_version":"1.6.0","new_version":"1.6.1","repository_url":"https://github.com/isaacs/sax-js"},{"name":"socks","old_version":"2.8.9","new_version":"2.8.10","repository_url":"https://github.com/JoshGlazebrook/socks"},{"name":"string.prototype.matchall","old_version":"4.0.12","new_version":"4.1.0","repository_url":"https://github.com/es-shims/String.prototype.matchAll"},{"name":"universalify","old_version":"2.0.1","new_version":"0.2.0","repository_url":"https://github.com/RyanZim/universalify"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm-minor-patch group with 72 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@applemusic-like-lyrics/vue](https://github.com/amll-dev/applemusic-like-lyrics/tree/HEAD/packages/vue) | `0.5.1` | `0.5.2` |\n| [@neteasecloudmusicapienhanced/api](https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced) | `4.35.1` | `4.40.1` |\n| [@sansenjian/qq-music-api](https://github.com/sansenjian/qq-music-api) | `2.4.0` | `2.6.0` |\n| [@sentry/node](https://github.com/getsentry/sentry-javascript) | `10.57.0` | `10.73.0` |\n| [@sentry/vue](https://github.com/getsentry/sentry-javascript) | `10.57.0` | `10.73.0` |\n| [@simplewebauthn/server](https://github.com/MasterKale/SimpleWebAuthn/tree/HEAD/packages/server) | `13.3.1` | `13.3.3` |\n| [@types/pg](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/pg) | `8.20.0` | `8.23.1` |\n| [axios](https://github.com/axios/axios) | `1.17.0` | `1.20.0` |\n| [dayjs](https://github.com/iamkun/dayjs) | `1.11.21` | `1.11.23` |\n| [jszip](https://github.com/Stuk/jszip) | `3.10.1` | `3.10.2` |\n| [multer](https://github.com/expressjs/multer) | `2.1.1` | `2.3.0` |\n| [@types/multer](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/multer) | `2.1.0` | `2.2.0` |\n| [sass](https://github.com/sass/dart-sass) | `1.101.0` | `1.104.0` |\n| [tsx](https://github.com/privatenumber/tsx) | `4.22.4` | `4.23.13` |\n| [zod](https://github.com/colinhacks/zod) | `4.4.3` | `4.5.4` |\n| [prettier](https://github.com/prettier/prettier) | `3.8.4` | `3.9.6` |\n| [@applemusic-like-lyrics/core](https://github.com/amll-dev/applemusic-like-lyrics/tree/HEAD/packages/core) | `0.5.1` | `0.5.2` |\n| [@babel/plugin-transform-modules-systemjs](https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs) | `7.29.7` | `7.29.8` |\n| [@babel/plugin-transform-regenerator](https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-regenerator) | `7.29.7` | `7.29.8` |\n| [@babel/plugin-transform-spread](https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-spread) | `7.29.7` | `7.29.8` |\n| [@neteasecloudmusicapienhanced/unblockmusic-utils](https://github.com/NeteaseCloudMusicApiEnhanced/UnblockNeteaseMusic-utils) | `0.3.3` | `0.4.4` |\n| [@opentelemetry/api-logs](https://github.com/open-telemetry/opentelemetry-js) | `0.214.0` | `0.220.0` |\n| [@opentelemetry/core](https://github.com/open-telemetry/opentelemetry-js) | `2.8.0` | `2.11.0` |\n| [@opentelemetry/instrumentation](https://github.com/open-telemetry/opentelemetry-js) | `0.214.0` | `0.220.0` |\n| [@opentelemetry/resources](https://github.com/open-telemetry/opentelemetry-js) | `2.8.0` | `2.11.0` |\n| [@opentelemetry/sdk-trace-base](https://github.com/open-telemetry/opentelemetry-js) | `2.8.0` | `2.11.0` |\n| [@opentelemetry/semantic-conventions](https://github.com/open-telemetry/opentelemetry-js) | `1.41.1` | `1.43.0` |\n| [@parcel/watcher-android-arm64](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-darwin-arm64](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-darwin-x64](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-freebsd-x64](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-linux-arm-glibc](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-linux-arm-musl](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-linux-arm64-glibc](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-linux-arm64-musl](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-linux-x64-glibc](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-linux-x64-musl](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-win32-arm64](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher-win32-x64](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@parcel/watcher](https://github.com/parcel-bundler/watcher) | `2.5.6` | `2.6.0` |\n| [@peculiar/asn1-android](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/android) | `2.8.0` | `2.9.4` |\n| [@peculiar/asn1-cms](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/cms) | `2.8.0` | `2.9.4` |\n| [@peculiar/asn1-csr](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/csr) | `2.8.0` | `2.9.4` |\n| [@peculiar/asn1-ecc](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/ecc) | `2.8.0` | `2.9.4` |\n| [@peculiar/asn1-pfx](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/pfx) | `2.8.0` | `2.9.4` |\n| [@peculiar/asn1-pkcs8](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/pkcs8) | `2.8.0` | `2.9.4` |\n| [@peculiar/asn1-pkcs9](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/pkcs9) | `2.8.0` | `2.9.4` |\n| [@peculiar/asn1-rsa](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/rsa) | `2.8.0` | `2.9.4` |\n| [@peculiar/asn1-schema](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/schema) | `2.8.0` | `2.9.4` |\n| [@peculiar/asn1-x509-attr](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/x509-attr) | `2.8.0` | `2.9.4` |\n| [@peculiar/asn1-x509](https://github.com/PeculiarVentures/asn1-schema/tree/HEAD/packages/x509) | `2.8.0` | `2.9.4` |\n| [@sentry/browser](https://github.com/getsentry/sentry-javascript) | `10.57.0` | `10.73.0` |\n| [@sentry/core](https://github.com/getsentry/sentry-javascript) | `10.57.0` | `10.73.0` |\n| [@sentry/node-core](https://github.com/getsentry/sentry-javascript) | `10.57.0` | `10.73.0` |\n| [@sentry/opentelemetry](https://github.com/getsentry/sentry-javascript) | `10.57.0` | `10.73.0` |\n| [@types/express-serve-static-core](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/express-serve-static-core) | `5.1.1` | `5.1.3` |\n| [body-parser](https://github.com/expressjs/body-parser) | `1.20.5` | `1.20.8` |\n| [cjs-module-lexer](https://github.com/nodejs/cjs-module-lexer) | `2.2.0` | `2.2.1` |\n| [es-to-primitive](https://github.com/ljharb/es-to-primitive) | `1.3.0` | `1.3.4` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.2` | `3.1.7` |\n| [immutable](https://github.com/immutable-js/immutable-js) | `5.1.6` | `5.1.9` |\n| [import-in-the-middle](https://github.com/nodejs/import-in-the-middle) | `3.0.2` | `3.5.0` |\n| [ip-address](https://github.com/beaugunderson/ip-address) | `10.2.0` | `10.7.0` |\n| [music-metadata](https://github.com/Borewit/music-metadata) | `11.13.0` | `11.15.0` |\n| [own-keys](https://github.com/ljharb/own-keys) | `1.0.1` | `1.0.2` |\n| [pg-protocol](https://github.com/brianc/node-postgres/tree/HEAD/packages/pg-protocol) | `1.14.0` | `1.16.0` |\n| [pvutils](https://github.com/PeculiarVentures/pvutils) | `1.1.5` | `1.2.0` |\n| [qs](https://github.com/ljharb/qs) | `6.15.2` | `6.15.3` |\n| [sax](https://github.com/isaacs/sax-js) | `1.6.0` | `1.6.1` |\n| [socks](https://github.com/JoshGlazebrook/socks) | `2.8.9` | `2.8.10` |\n| [string.prototype.matchall](https://github.com/es-shims/String.prototype.matchAll) | `4.0.12` | `4.1.0` |\n| [universalify](https://github.com/RyanZim/universalify) | `2.0.1` | `0.2.0` |\n\nUpdates `@applemusic-like-lyrics/vue` from 0.5.1 to 0.5.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/amll-dev/applemusic-like-lyrics/releases\"\u003e@​applemusic-like-lyrics/vue's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e最新 main 分支开发调试构建\u003c/h2\u003e\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e修正工作流 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/4e586361026cd31b79d7d60ce41a6d3c5106d666\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e修正工作流 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/f9fa644e4726d5dec5f661036aa0a22cac58fa22\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e修正工作流 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/f090519d8393abb8fff76ed048e68b432917f214\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e修正顶栏 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/44ada57bc07f57f532bb7289c1dd0d42b7acb542\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e增加文档页面列表 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/6c2115fee0a4a0653c238ec125d13ea5d86e3b00\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e增加代码高亮，修改排版和样式 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/6b1c1f9deabfce77b4b218cf1bae84e24d44c871\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e增加表格和其他样式支持 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/a47b5db16ccf67d31185457188292d9247d45a10\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e优化样式 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/6c91b4b70a75e69635e7ee62b11d45de8caafa3e\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e增加歌词编辑器文档（感谢 \u003ca href=\"https://github.com/Xionghaizi001\"\u003e\u003ccode\u003e@​Xionghaizi001\u003c/code\u003e\u003c/a\u003e ） (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/4cddb8666f83da2d256127ba1fab694e03311216\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eCommits\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e解耦部分模块 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/804a0de7b6626b4982c55a2f0a875e2274423406\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e支持调节背景帧数和渲染精度 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/f4dd4e1eada165482c76fa3d73290118fd3b1c55\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e更新构建工作流 NodeJS 版本 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/289faae66c38aa8958473b3ce55ab65f6f7f033c\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e增加 ESLyric 歌词格式支持 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/13c05e66271281fb3b10f0877611760cc7cab7dd\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e补充说明 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/41479a6050164bbdac1909ea8203db5028bd290e\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e让歌词行保持在 GPU 层以缓解 CPU 压力 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/2c815abc09a0546bcf4bf72dc4c2b8ea2b94bbe0\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ea41d7f8: 更改辉光判定和渲染 (Eplor)\u003c/li\u003e\n\u003cli\u003e将是否应用强调效果的条件还原回去 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/8d30cf51f32d3b7aa7591eca35a43f92c3e0ba56\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e重新调节了辉光效果和相关样式的匹配 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/e0c9048083e213d7fffda290ab68b2d41e9342f2\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e57b243b: 优化请求接口 (SteveXMH)\u003c/li\u003e\n\u003cli\u003e增加镜像源以加速 AMLL TTML DB 歌词获取 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/3631c69fe56fcdb58e237e9b6719469f9eb046cc\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e完成对接低频数据到背景渲染器实现特殊效果 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/868cbc2edfb2a80f48b62c45020ffa34a2380eb1\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e5e45dbd: Merge branch 'dev' of github.com:Steve-xmh/applemusic-like-lyrics into dev (SteveXMH)\u003c/li\u003e\n\u003cli\u003e更新构建 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/5c47f87fd08b4d8573ff88c3fb8545767875875a\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e统一了音频可视化数据源 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/dfe5278eef72e5cb618aed9dbd3f42bc5017f40d\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e可以让背景接收音频可视化数据了 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/33ac4620f06d74279a80ad11258fcd7e2641e8e3\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e传入fttLowCut Shader实现 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/7d5208f73ed265bdc49128b0cf3e2859f401a638\"\u003eEplor\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e90ab6b5: Merge branch 'dev' of github.com:Steve-xmh/applemusic-like-lyrics into dev (SteveXMH)\u003c/li\u003e\n\u003cli\u003e支持传参FFT到背景 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/9ab091134ea35004998f0df76dca3e8c463ea0b8\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e微调了音频可视化效果 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/e1195a8260a580d8d827f4680cdf5f2f6f0070d3\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e增加作为组件嵌入其他项目的环境类别 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/1ad21dc4b47cf8c51310d3ee0be2c2476d812bd3\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e调优了窗口较小时的布局 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/171e35fefe7db68e7a8b6cce57ac3852b4d9edea\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e优化竖向布局 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/b43e28d53ca943dea16b5914f908621687fdadd5\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e流体FFT动画算法超级更新 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/187c1166f274576d53a08c69cc9e06b1d806e912\"\u003eEplor\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e修复FFT流体动态效果幅度 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/a72a4744ebac168a91a3fa4cb0ebd1a1dbb52925\"\u003eEplor\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e优化背景跳动算法 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/eba9040ccff32fe498ecef78d5be7fc59b3b0d6e\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e增加显示背景调试数据功能 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/188a761885727eaa889eb2f3c569998adcfaf428\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e稍微调整了一下fft动画算法 core: 给shader加了一个参数 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/97ca78af3130407be9587f7015fb529e2f0c15ff\"\u003eEplor\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e构建 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/4f55e86cbec878ff8a84eb7b190a9dac06ebddd3\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e支持 Eplor 背景修改流动速度 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/d38babacfb7c141684614ff2fa3c956359631230\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e修正产物类型定义文件指向 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/55b45b3f82f8b3b175ad2b14772eed8164b0ded6\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e修正样式 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/3291134e3392a48c38d14c92891c9f21a4955f22\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e为 Eplor 流体背景增加切换图像过渡效果 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/d8d4b3bda1129034e642bb72bbe1b2fc7b7bfeb5\"\u003eSteve-xmh\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e增加根据是否有歌词调节背景效果 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/e443e6842bad69e08e07347b10f763aa75133dac\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e可配置禁用混色效果 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/efa6f0914ec7986140d329cb95d08da601cbf8a9\"\u003eSteveXMH\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e调整背景动画 更好的背景渲染效果 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/5906b725e6a0ecad1732c96d58f16f3eb8c1dc14\"\u003eEplor\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e调整了流体渲染效果 基本完美 (\u003ca href=\"https://github.com/Steve-xmh/applemusic-like-lyrics/commit/a2e1833b9b0b9204a5001e894a769263b180bcd4\"\u003eEplor\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/amll-dev/applemusic-like-lyrics/blob/main/packages/vue/CHANGELOG.md\"\u003e@​applemusic-like-lyrics/vue's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.5.2 (2026-07-09)\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003erefactor(core):\u003c/strong\u003e 将点击相关事件和样式由歌词行上移至歌词组 (\u003ca href=\"https://redirect.github.com/amll-dev/applemusic-like-lyrics/pull/538\"\u003e#538\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003echore(core):\u003c/strong\u003e 一些简单的代码优化避免样式重新计算 (\u003ca href=\"https://redirect.github.com/amll-dev/applemusic-like-lyrics/pull/540\"\u003e#540\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003echore(core):\u003c/strong\u003e 简单优化一点Mesh着色器的代码 (\u003ca href=\"https://redirect.github.com/amll-dev/applemusic-like-lyrics/pull/558\"\u003e#558\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003echore:\u003c/strong\u003e 修复 linter 警告 (\u003ca href=\"https://redirect.github.com/amll-dev/applemusic-like-lyrics/pull/539\"\u003e#539\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eContributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eapoint123 \u003ca href=\"https://github.com/apoint123\"\u003e\u003ccode\u003e@​apoint123\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eLinho\u003c/li\u003e\n\u003cli\u003eSteveXMH \u003ca href=\"https://github.com/Steve-xmh\"\u003e\u003ccode\u003e@​Steve-xmh\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/amll-dev/applemusic-like-lyrics/commit/fd7ec2d597daa2a66a37ca5f3214d6757ec17cfa\"\u003e\u003ccode\u003efd7ec2d\u003c/code\u003e\u003c/a\u003e chore(release): publish\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/amll-dev/applemusic-like-lyrics/commits/core-bundle@0.5.2/packages/vue\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@neteasecloudmusicapienhanced/api` from 4.35.1 to 4.40.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/releases\"\u003e@​neteasecloudmusicapienhanced/api's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eRelease v4.40.1\u003c/h1\u003e\n\u003ch2\u003e更新内容 / Changelog\u003c/h2\u003e\n\u003cp\u003e从 \u003ccode\u003ev4.40.0\u003c/code\u003e 到 \u003ccode\u003ev4.40.1\u003c/code\u003e 的提交记录：\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eci: fix pnpm has no pnpm-workspace.yaml (4a91f77)\u003c/li\u003e\n\u003cli\u003efeat: 更新歌曲相关接口 (a7437f7)\u003c/li\u003e\n\u003cli\u003edocs: 补全私人漫游模式文档内容 (7b17a08)\u003c/li\u003e\n\u003cli\u003efix: /song/url/v1/302 \u0026amp; /song/download/url/v1 支持臻音全景声 (0b5c392)\u003c/li\u003e\n\u003cli\u003efix: /song/url/v1 支持臻音全景声 (881267c)\u003c/li\u003e\n\u003cli\u003efix: 错误的docker配置 (d7c0db9)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e自动发布 via GitHub Actions\u003c/p\u003e\n\u003ch1\u003eRelease v4.40.0\u003c/h1\u003e\n\u003ch2\u003e更新内容 / Changelog\u003c/h2\u003e\n\u003cp\u003e从 \u003ccode\u003ev4.39.0\u003c/code\u003e 到 \u003ccode\u003ev4.40.0\u003c/code\u003e 的提交记录：\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efixes (a2a2a40)\u003c/li\u003e\n\u003cli\u003efix: pkg打包node18兼容 (543660f)\u003c/li\u003e\n\u003cli\u003efix: node18兼容 (98a9500)\u003c/li\u003e\n\u003cli\u003erefactor: 重写checkToken V2模块 (c4a3d83)\u003c/li\u003e\n\u003cli\u003eMerge branch 'pr/235' (c1fe1eb)\u003c/li\u003e\n\u003cli\u003eupd (3357317)\u003c/li\u003e\n\u003cli\u003eci: test ci with the workflow file (5b780ad)\u003c/li\u003e\n\u003cli\u003eci: test ci with workflow file (fc9f418)\u003c/li\u003e\n\u003cli\u003eformat docs (5859944)\u003c/li\u003e\n\u003cli\u003eremove disclaimer (aaa6459)\u003c/li\u003e\n\u003cli\u003efeat: 新增云贝任务相关接口 (a898e1d)\u003c/li\u003e\n\u003cli\u003erevert: revert some changes (686e8bf)\u003c/li\u003e\n\u003cli\u003efix: V-001 security vulnerability (9214cb9)\u003c/li\u003e\n\u003cli\u003efix: 修正workflow文件 (a79a2d9)\u003c/li\u003e\n\u003cli\u003efix(voice): load created podcasts in upload example (9608da9)\u003c/li\u003e\n\u003cli\u003efeat(voice): support cover image uploads (93b3e62)\u003c/li\u003e\n\u003cli\u003eci(test): test ci with the workflow file (15f515c)\u003c/li\u003e\n\u003cli\u003efix: V-001 security vulnerability (e255e8f)\u003c/li\u003e\n\u003cli\u003eci(test): test ci workflow file (16aa61f)\u003c/li\u003e\n\u003cli\u003eci(test): test ci workflow file (a939003)\u003c/li\u003e\n\u003cli\u003eperf: 更新接口定义 (8f4873f)\u003c/li\u003e\n\u003cli\u003eci: 更新问题管理工作流 (1a70281)\u003c/li\u003e\n\u003cli\u003efeat: add complete current-user event listing (f5f4ff6)\u003c/li\u003e\n\u003cli\u003efeat: add event privacy endpoint (eb1b5ba)\u003c/li\u003e\n\u003cli\u003eci(test): test ci workflow file (6732fc7)\u003c/li\u003e\n\u003cli\u003efix: 修复分享笔记接口 (6ce6b84)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/commit/4a91f77e622fe22e95dea7c9b73f0eeb27f2f0aa\"\u003e\u003ccode\u003e4a91f77\u003c/code\u003e\u003c/a\u003e ci: fix pnpm has no pnpm-workspace.yaml\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/commit/a7437f7ca4160e6816893a7cf8736afcb505c8d3\"\u003e\u003ccode\u003ea7437f7\u003c/code\u003e\u003c/a\u003e feat: 更新歌曲相关接口\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/commit/498945c401bbca8f739388449632877aa0613539\"\u003e\u003ccode\u003e498945c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/issues/241\"\u003e#241\u003c/a\u003e from 1254qwer/fix/song-url-v1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/commit/7b17a08628dd08202c62fe831be4f9158ac163cf\"\u003e\u003ccode\u003e7b17a08\u003c/code\u003e\u003c/a\u003e docs: 补全私人漫游模式文档内容\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/commit/0b5c3927c91bad932b93f9219bd8e738d1b619db\"\u003e\u003ccode\u003e0b5c392\u003c/code\u003e\u003c/a\u003e fix: /song/url/v1/302 \u0026amp; /song/download/url/v1 支持臻音全景声\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/commit/881267c56dbeb562993b3d3a20085602f9c74bc8\"\u003e\u003ccode\u003e881267c\u003c/code\u003e\u003c/a\u003e fix: /song/url/v1 支持臻音全景声\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/commit/d7c0db9455ef991be72a182789549969fb3ba99c\"\u003e\u003ccode\u003ed7c0db9\u003c/code\u003e\u003c/a\u003e fix: 错误的docker配置\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/commit/c1d14a86d9f612d40cbd9352521a670d911ff972\"\u003e\u003ccode\u003ec1d14a8\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/issues/237\"\u003e#237\u003c/a\u003e from NeteaseCloudMusicApiEnhanced/fix/yidun\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/commit/a2a2a40d7173cd0cc2d5d55b1e510a38fc844026\"\u003e\u003ccode\u003ea2a2a40\u003c/code\u003e\u003c/a\u003e fixes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/commit/543660fcdf1a13341790f4b5630ab05159b4e5a4\"\u003e\u003ccode\u003e543660f\u003c/code\u003e\u003c/a\u003e fix: pkg打包node18兼容\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/NeteaseCloudMusicApiEnhanced/api-enhanced/compare/v4.35.1...v4.40.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@sansenjian/qq-music-api` from 2.4.0 to 2.6.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/sansenjian/qq-music-api/blob/main/CHANGELOG.md\"\u003e@​sansenjian/qq-music-api's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.6.0 (2026-08-27)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e增加微信登录二维码相关接口与功能 (\u003ca href=\"https://redirect.github.com/sansenjian/qq-music-api/issues/45\"\u003e#45\u003c/a\u003e) (\u003ca href=\"https://github.com/sansenjian/qq-music-api/commit/15a38f8b8e0663aa7afea1440f92c6dd3b36100f\"\u003e15a38f8\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.5.0 (2026-08-10)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eaddress PR 41 review comments (\u003ca href=\"https://redirect.github.com/sansenjian/qq-music-api/issues/42\"\u003e#42\u003c/a\u003e) (\u003ca href=\"https://github.com/sansenjian/qq-music-api/commit/ba107d1b427436d03ea138f68ad86efe5f08c76b\"\u003eba107d1\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/sansenjian/qq-music-api/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@sentry/node` from 10.57.0 to 10.73.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/getsentry/sentry-javascript/releases\"\u003e@​sentry/node's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e10.73.0\u003c/h2\u003e\n\u003ch3\u003eImportant Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003efeat(v10/nextjs): Add \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e entry point (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23766\"\u003e#23766\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003ewithSentryConfig\u003c/code\u003e is now available from \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e, the path it moves to in v11. Importing it from \u003ccode\u003e@sentry/nextjs\u003c/code\u003e still works on v10 but logs a warning once, so you can change your \u003ccode\u003enext.config\u003c/code\u003e file today and upgrade to v11 without touching it again.\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// next.config.mjs\n- import { withSentryConfig } from '@sentry/nextjs';\n+ import { withSentryConfig } from '@sentry/nextjs/config';\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(v10/node): Deprecate \u003ccode\u003eshouldHandleError\u003c/code\u003e on \u003ccode\u003esetupExpressErrorHandler\u003c/code\u003e and \u003ccode\u003esetupFasitfyErrorHandler\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23734\"\u003e#23734\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/cloudflare): Instrument Durable Object handlers installed as read-only properties (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23769\"\u003e#23769\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003etest(v10/nextjs): Drop nextjs-16-cf-workers canary variant (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23775\"\u003e#23775\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eBundle size 📦\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003ePath\u003c/th\u003e\n\u003cth\u003eSize\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e27.1 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e - with treeshaking flags\u003c/td\u003e\n\u003ctd\u003e25.58 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing)\u003c/td\u003e\n\u003ctd\u003e45.54 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing + Span Streaming)\u003c/td\u003e\n\u003ctd\u003e47.28 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Profiling)\u003c/td\u003e\n\u003ctd\u003e50.17 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay)\u003c/td\u003e\n\u003ctd\u003e83.87 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay) - with treeshaking flags\u003c/td\u003e\n\u003ctd\u003e73.74 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay with Canvas)\u003c/td\u003e\n\u003ctd\u003e88.49 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay, Feedback)\u003c/td\u003e\n\u003ctd\u003e100.83 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Feedback)\u003c/td\u003e\n\u003ctd\u003e43.87 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. sendFeedback)\u003c/td\u003e\n\u003ctd\u003e31.78 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. FeedbackAsync)\u003c/td\u003e\n\u003ctd\u003e36.79 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Metrics)\u003c/td\u003e\n\u003ctd\u003e28.16 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Logs)\u003c/td\u003e\n\u003ctd\u003e28.38 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Metrics \u0026amp; Logs)\u003c/td\u003e\n\u003ctd\u003e29.06 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/react\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e28.86 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/react\u003c/code\u003e (incl. Tracing)\u003c/td\u003e\n\u003ctd\u003e47.74 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/vue\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e32.4 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/vue\u003c/code\u003e (incl. Tracing)\u003c/td\u003e\n\u003ctd\u003e47.46 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/svelte\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e27.12 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eCDN Bundle\u003c/td\u003e\n\u003ctd\u003e29.43 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/getsentry/sentry-javascript/blob/10.73.0/CHANGELOG.md\"\u003e@​sentry/node's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e10.73.0\u003c/h2\u003e\n\u003ch3\u003eImportant Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003efeat(v10/nextjs): Add \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e entry point (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23766\"\u003e#23766\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003ewithSentryConfig\u003c/code\u003e is now available from \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e, the path it moves to in v11. Importing it from \u003ccode\u003e@sentry/nextjs\u003c/code\u003e still works on v10 but logs a warning once, so you can change your \u003ccode\u003enext.config\u003c/code\u003e file today and upgrade to v11 without touching it again.\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// next.config.mjs\n- import { withSentryConfig } from '@sentry/nextjs';\n+ import { withSentryConfig } from '@sentry/nextjs/config';\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(v10/node): Deprecate \u003ccode\u003eshouldHandleError\u003c/code\u003e on \u003ccode\u003esetupExpressErrorHandler\u003c/code\u003e and \u003ccode\u003esetupFasitfyErrorHandler\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23734\"\u003e#23734\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/cloudflare): Instrument Durable Object handlers installed as read-only properties (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23769\"\u003e#23769\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003etest(v10/nextjs): Drop nextjs-16-cf-workers canary variant (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23775\"\u003e#23775\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e10.72.0\u003c/h2\u003e\n\u003ch3\u003eImportant Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eAI integrations no longer report errors that propagate to the caller (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23638\"\u003e#23638\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23639\"\u003e#23639\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23640\"\u003e#23640\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eAcross all AI integrations (OpenAI, Anthropic, Google GenAI, LangChain, and LangGraph), the SDK no longer sends an event to Sentry for errors that the AI framework propagates to your code. Previously the instrumentation reported these as unhandled (\u003ccode\u003ehandled: false\u003c/code\u003e) before your own error handling ran, so an error your code caught still showed up in Sentry as an unhandled crash. The span is still marked as errored and the error still propagates, so reporting is left to your application: if your code does not handle the error, it reaches Sentry's global error handlers and is captured as unhandled, just like any other uncaught error. Errors that a provider surfaces as data on an otherwise successful response (such as Anthropic error-shaped responses or Google GenAI blocked content) are still captured, since your code never sees them propagate.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003efeat(v10/cloudflare): Add \u003ccode\u003erpcTracePropagationBindings\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23737\"\u003e#23737\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23738\"\u003e#23738\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe new \u003ccode\u003erpcTracePropagationBindings\u003c/code\u003e option names the \u003ccode\u003eenv\u003c/code\u003e bindings that outgoing RPC calls propagate trace context to. Strings match a binding name exactly, regular expressions match by pattern, and the default empty array propagates to nothing. RPC has no headers to carry trace context, so the SDK appends it as a trailing argument that only a Sentry-instrumented receiver removes again. List only the bindings whose receiver you know runs Sentry. Setting the option takes precedence over \u003ccode\u003eenableRpcTracePropagation\u003c/code\u003e, which is now deprecated. When you build with the Sentry Cloudflare Vite plugin, the bindings that resolve to this worker (its own Durable Objects and self service bindings) are derived from your wrangler config and added for you.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(v10/astro): support astro v7 route patterns properly (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23657\"\u003e#23657\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/bundler-plugins): Preserve full file path in component annotation source maps (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23595\"\u003e#23595\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/core): Store child span timeout handle in \u003ccode\u003e_childSpanTimeoutID\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23673\"\u003e#23673\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/node): Only end the process session when it is still ok (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23731\"\u003e#23731\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/react-router): Use react-router's own instrumentation types instead of a mirrored copy (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23589\"\u003e#23589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/replay): Suppress Worker destroyed error on session expiry (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23654\"\u003e#23654\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/server-utils): Keep orchestrion registration out of tree-shaking (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23591\"\u003e#23591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/server-utils): Stop shipping orchestrion bundler plugins as production dependencies (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23667\"\u003e#23667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/server-utils): Support openai v7 in auto-instrumentation (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23713\"\u003e#23713\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/sveltekit): Detect native tracing in flattened SvelteKit 3 config (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23656\"\u003e#23656\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/f109d922f5971e2ade549b6c755524168b101818\"\u003e\u003ccode\u003ef109d92\u003c/code\u003e\u003c/a\u003e release: 10.73.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/1a3e04edc4d1c97a702861a9bddd3ed577a71de4\"\u003e\u003ccode\u003e1a3e04e\u003c/code\u003e\u003c/a\u003e meta(changelog): Update changelog for 10.73.0 (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23778\"\u003e#23778\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/da8d7696b08432cd94e78552d9f4c9322c1dc746\"\u003e\u003ccode\u003eda8d769\u003c/code\u003e\u003c/a\u003e test(v10/nextjs): Drop nextjs-16-cf-workers canary variant (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23775\"\u003e#23775\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/bea4d38bf5422ae917275d0b68ad575a2b2b475b\"\u003e\u003ccode\u003ebea4d38\u003c/code\u003e\u003c/a\u003e feat(v10/node): Deprecate \u003ccode\u003eshouldHandleError\u003c/code\u003e on \u003ccode\u003esetupExpressErrorHandler\u003c/code\u003e a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/605caaf2aa85f78ed9a180b273a335fe798bf30c\"\u003e\u003ccode\u003e605caaf\u003c/code\u003e\u003c/a\u003e feat(v10/nextjs): Add \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e entry point (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23766\"\u003e#23766\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/da17307e9e1898a48a3d4037aff96d5849f123fb\"\u003e\u003ccode\u003eda17307\u003c/code\u003e\u003c/a\u003e fix(v10/cloudflare): Instrument Durable Object handlers installed as read-onl...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/2c4ca38e52cb0e4c4ee69cbdc218c9cabd52eccf\"\u003e\u003ccode\u003e2c4ca38\u003c/code\u003e\u003c/a\u003e Merge branch 'release/10.72.0' into v10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/0d236289ba889ac8f007882726aaa62d9a83cc15\"\u003e\u003ccode\u003e0d23628\u003c/code\u003e\u003c/a\u003e release: 10.72.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/ac2094d469ace03e883abb5fc98b5dc678ccfe49\"\u003e\u003ccode\u003eac2094d\u003c/code\u003e\u003c/a\u003e meta(changelog): Update changelog for 10.72.0 (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23743\"\u003e#23743\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/f3254344c4b63382c12cec95b64e7c54f9e45ff9\"\u003e\u003ccode\u003ef325434\u003c/code\u003e\u003c/a\u003e feat(v10/cloudflare): Derive rpcTracePropagationBindings from the wrangler co...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/getsentry/sentry-javascript/compare/10.57.0...10.73.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@sentry/vue` from 10.57.0 to 10.73.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/getsentry/sentry-javascript/releases\"\u003e@​sentry/vue's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e10.73.0\u003c/h2\u003e\n\u003ch3\u003eImportant Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003efeat(v10/nextjs): Add \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e entry point (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23766\"\u003e#23766\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003ewithSentryConfig\u003c/code\u003e is now available from \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e, the path it moves to in v11. Importing it from \u003ccode\u003e@sentry/nextjs\u003c/code\u003e still works on v10 but logs a warning once, so you can change your \u003ccode\u003enext.config\u003c/code\u003e file today and upgrade to v11 without touching it again.\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// next.config.mjs\n- import { withSentryConfig } from '@sentry/nextjs';\n+ import { withSentryConfig } from '@sentry/nextjs/config';\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(v10/node): Deprecate \u003ccode\u003eshouldHandleError\u003c/code\u003e on \u003ccode\u003esetupExpressErrorHandler\u003c/code\u003e and \u003ccode\u003esetupFasitfyErrorHandler\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23734\"\u003e#23734\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/cloudflare): Instrument Durable Object handlers installed as read-only properties (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23769\"\u003e#23769\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003etest(v10/nextjs): Drop nextjs-16-cf-workers canary variant (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23775\"\u003e#23775\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eBundle size 📦\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003ePath\u003c/th\u003e\n\u003cth\u003eSize\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e27.1 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e - with treeshaking flags\u003c/td\u003e\n\u003ctd\u003e25.58 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing)\u003c/td\u003e\n\u003ctd\u003e45.54 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing + Span Streaming)\u003c/td\u003e\n\u003ctd\u003e47.28 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Profiling)\u003c/td\u003e\n\u003ctd\u003e50.17 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay)\u003c/td\u003e\n\u003ctd\u003e83.87 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay) - with treeshaking flags\u003c/td\u003e\n\u003ctd\u003e73.74 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay with Canvas)\u003c/td\u003e\n\u003ctd\u003e88.49 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay, Feedback)\u003c/td\u003e\n\u003ctd\u003e100.83 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Feedback)\u003c/td\u003e\n\u003ctd\u003e43.87 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. sendFeedback)\u003c/td\u003e\n\u003ctd\u003e31.78 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. FeedbackAsync)\u003c/td\u003e\n\u003ctd\u003e36.79 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Metrics)\u003c/td\u003e\n\u003ctd\u003e28.16 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Logs)\u003c/td\u003e\n\u003ctd\u003e28.38 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Metrics \u0026amp; Logs)\u003c/td\u003e\n\u003ctd\u003e29.06 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/react\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e28.86 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/react\u003c/code\u003e (incl. Tracing)\u003c/td\u003e\n\u003ctd\u003e47.74 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/vue\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e32.4 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/vue\u003c/code\u003e (incl. Tracing)\u003c/td\u003e\n\u003ctd\u003e47.46 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/svelte\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e27.12 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eCDN Bundle\u003c/td\u003e\n\u003ctd\u003e29.43 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/getsentry/sentry-javascript/blob/10.73.0/CHANGELOG.md\"\u003e@​sentry/vue's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e10.73.0\u003c/h2\u003e\n\u003ch3\u003eImportant Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003efeat(v10/nextjs): Add \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e entry point (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23766\"\u003e#23766\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003ewithSentryConfig\u003c/code\u003e is now available from \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e, the path it moves to in v11. Importing it from \u003ccode\u003e@sentry/nextjs\u003c/code\u003e still works on v10 but logs a warning once, so you can change your \u003ccode\u003enext.config\u003c/code\u003e file today and upgrade to v11 without touching it again.\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// next.config.mjs\n- import { withSentryConfig } from '@sentry/nextjs';\n+ import { withSentryConfig } from '@sentry/nextjs/config';\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(v10/node): Deprecate \u003ccode\u003eshouldHandleError\u003c/code\u003e on \u003ccode\u003esetupExpressErrorHandler\u003c/code\u003e and \u003ccode\u003esetupFasitfyErrorHandler\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23734\"\u003e#23734\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/cloudflare): Instrument Durable Object handlers installed as read-only properties (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23769\"\u003e#23769\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003etest(v10/nextjs): Drop nextjs-16-cf-workers canary variant (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23775\"\u003e#23775\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e10.72.0\u003c/h2\u003e\n\u003ch3\u003eImportant Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eAI integrations no longer report errors that propagate to the caller (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23638\"\u003e#23638\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23639\"\u003e#23639\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23640\"\u003e#23640\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eAcross all AI integrations (OpenAI, Anthropic, Google GenAI, LangChain, and LangGraph), the SDK no longer sends an event to Sentry for errors that the AI framework propagates to your code. Previously the instrumentation reported these as unhandled (\u003ccode\u003ehandled: false\u003c/code\u003e) before your own error handling ran, so an error your code caught still showed up in Sentry as an unhandled crash. The span is still marked as errored and the error still propagates, so reporting is left to your application: if your code does not handle the error, it reaches Sentry's global error handlers and is captured as unhandled, just like any other uncaught error. Errors that a provider surfaces as data on an otherwise successful response (such as Anthropic error-shaped responses or Google GenAI blocked content) are still captured, since your code never sees them propagate.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003efeat(v10/cloudflare): Add \u003ccode\u003erpcTracePropagationBindings\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23737\"\u003e#23737\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23738\"\u003e#23738\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe new \u003ccode\u003erpcTracePropagationBindings\u003c/code\u003e option names the \u003ccode\u003eenv\u003c/code\u003e bindings that outgoing RPC calls propagate trace context to. Strings match a binding name exactly, regular expressions match by pattern, and the default empty array propagates to nothing. RPC has no headers to carry trace context, so the SDK appends it as a trailing argument that only a Sentry-instrumented receiver removes again. List only the bindings whose receiver you know runs Sentry. Setting the option takes precedence over \u003ccode\u003eenableRpcTracePropagation\u003c/code\u003e, which is now deprecated. When you build with the Sentry Cloudflare Vite plugin, the bindings that resolve to this worker (its own Durable Objects and self service bindings) are derived from your wrangler config and added for you.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(v10/astro): support astro v7 route patterns properly (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23657\"\u003e#23657\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/bundler-plugins): Preserve full file path in component annotation source maps (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23595\"\u003e#23595\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/core): Store child span timeout handle in \u003ccode\u003e_childSpanTimeoutID\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23673\"\u003e#23673\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/node): Only end the process session when it is still ok (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23731\"\u003e#23731\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/react-router): Use react-router's own instrumentation types instead of a mirrored copy (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23589\"\u003e#23589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/replay): Suppress Worker destroyed error on session expiry (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23654\"\u003e#23654\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/server-utils): Keep orchestrion registration out of tree-shaking (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23591\"\u003e#23591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/server-utils): Stop shipping orchestrion bundler plugins as production dependencies (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23667\"\u003e#23667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/server-utils): Support openai v7 in auto-instrumentation (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23713\"\u003e#23713\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/sveltekit): Detect native tracing in flattened SvelteKit 3 config (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23656\"\u003e#23656\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/f109d922f5971e2ade549b6c755524168b101818\"\u003e\u003ccode\u003ef109d92\u003c/code\u003e\u003c/a\u003e release: 10.73.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/1a3e04edc4d1c97a702861a9bddd3ed577a71de4\"\u003e\u003ccode\u003e1a3e04e\u003c/code\u003e\u003c/a\u003e meta(changelog): Update changelog for 10.73.0 (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23778\"\u003e#23778\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/da8d7696b08432cd94e78552d9f4c9322c1dc746\"\u003e\u003ccode\u003eda8d769\u003c/code\u003e\u003c/a\u003e test(v10/nextjs): Drop nextjs-16-cf-workers canary variant (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23775\"\u003e#23775\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/bea4d38bf5422ae917275d0b68ad575a2b2b475b\"\u003e\u003ccode\u003ebea4d38\u003c/code\u003e\u003c/a\u003e feat(v10/node): Deprecate \u003ccode\u003eshouldHandleError\u003c/code\u003e on \u003ccode\u003esetupExpressErrorHandler\u003c/code\u003e a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/605caaf2aa85f78ed9a180b273a335fe798bf30c\"\u003e\u003ccode\u003e605caaf\u003c/code\u003e\u003c/a\u003e feat(v10/nextjs): Add \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e entry point (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23766\"\u003e#23766\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/da17307e9e1898a48a3d4037aff96d5849f123fb\"\u003e\u003ccode\u003eda17307\u003c/code\u003e\u003c/a\u003e fix(v10/cloudflare): Instrument Durable Object handlers installed as read-onl...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/2c4ca38e52cb0e4c4ee69cbdc218c9cabd52eccf\"\u003e\u003ccode\u003e2c4ca38\u003c/code\u003e\u003c/a\u003e Merge branch 'release/10.72.0' into v10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/0d236289ba889ac8f007882726aaa62d9a83cc15\"\u003e\u003ccode\u003e0d23628\u003c/code\u003e\u003c/a\u003e release: 10.72.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/ac2094d469ace03e883abb5fc98b5dc678ccfe49\"\u003e\u003ccode\u003eac2094d\u003c/code\u003e\u003c/a\u003e meta(changelog): Update changelog for 10.72.0 (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23743\"\u003e#23743\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/f3254344c4b63382c12cec95b64e7c54f9e45ff9\"\u003e\u003ccode\u003ef325434\u003c/code\u003e\u003c/a\u003e feat(v10/cloudflare): Derive rpcTracePropagationBindings from the wrangler co...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/getsentry/sentry-javascript/compare/10.57.0...10.73.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@simplewebauthn/server` from 13.3.1 to 13.3.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/releases\"\u003e@​simplewebauthn/server's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev13.3.3\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eChanges:\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e[server]\u003c/strong\u003e Updated MDS blob signature verification to support more algorithms (\u003ca href=\"https://redirect.github.com/MasterKale/SimpleWebAuthn/pull/788\"\u003e#788\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e[server]\u003c/strong\u003e Updated \u003ccode\u003eMetadataService\u003c/code\u003e to know about the new FIDO MDS blob trust anchor certificate (\u003ca href=\"https://redirect.github.com/MasterKale/SimpleWebAuthn/pull/789\"\u003e#789\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev13.3.2\u003c/h2\u003e\n\u003cp\u003eThis update fixes a CVSS v4 Low (2.0) security vulnerability identified in \u003cstrong\u003e\u003ccode\u003e@​simplewebauthn/server\u003c/code\u003e\u003c/strong\u003e. See the security advisory linked below for more information.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eChanges:\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e[server]\u003c/strong\u003e Fixed an issue with \u003ccode\u003everifyRegistrationResponse()\u003c/code\u003e allowing a maliciously-crafted attestation statement's \u003ccode\u003ex5c\u003c/code\u003e to contain a self-signed \u0026quot;root certificate\u0026quot; instead of chaining back to an RP-specified trust anchor (\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/security/advisories/GHSA-6hxq-p678-4hr2\"\u003eGHSA-6hxq-p678-4hr2\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/blob/master/CHANGELOG.md\"\u003e@​simplewebauthn/server's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev13.3.3\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eChanges:\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e[server]\u003c/strong\u003e Updated MDS blob signature verification to support more algorithms\n(\u003ca href=\"https://redirect.github.com/MasterKale/SimpleWebAuthn/pull/788\"\u003e#788\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e[server]\u003c/strong\u003e Updated \u003ccode\u003eMetadataService\u003c/code\u003e to know about the new FIDO MDS blob trust anchor\ncertificate (\u003ca href=\"https://redirect.github.com/MasterKale/SimpleWebAuthn/pull/789\"\u003e#789\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev13.3.2\u003c/h2\u003e\n\u003cp\u003eThis update fixes a CVSS v4 Low (2.0) security vulnerability identified in\n\u003cstrong\u003e\u003ccode\u003e@​simplewebauthn/server\u003c/code\u003e\u003c/strong\u003e. See the security advisory linked below for more information.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eChanges:\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e[server]\u003c/strong\u003e Fixed an issue with \u003ccode\u003everifyRegistrationResponse()\u003c/code\u003e allowing a maliciously-crafted\nattestation statement's \u003ccode\u003ex5c\u003c/code\u003e to contain a self-signed \u0026quot;root certificate\u0026quot; instead of chaining back\nto an RP-specified trust anchor\n(\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/security/advisories/GHSA-6hxq-p678-4hr2\"\u003eGHSA-6hxq-p678-4hr2\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commit/4b189bdfd6ffd5e3d30023b2d3e9970d81c89ce9\"\u003e\u003ccode\u003e4b189bd\u003c/code\u003e\u003c/a\u003e Update server version to 13.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commit/05db595392530c13074064f081b71c47e25cc7cc\"\u003e\u003ccode\u003e05db595\u003c/code\u003e\u003c/a\u003e Add GlobalSign Root R46 to FIDO MDS default root certs (\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/tree/HEAD/packages/server/issues/789\"\u003e#789\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commit/9bf80bfa0acb6c2d9e479588841915c48e406e3e\"\u003e\u003ccode\u003e9bf80bf\u003c/code\u003e\u003c/a\u003e Use JWT header alg when verifying MDS blob (\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/tree/HEAD/packages/server/issues/788\"\u003e#788\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commit/84656fff764256609193b9e0a0661c82dd379ebb\"\u003e\u003ccode\u003e84656ff\u003c/code\u003e\u003c/a\u003e Update version to 13.3.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commit/dd0d73c716a528e6645efafbd43a972b64df71f9\"\u003e\u003ccode\u003edd0d73c\u003c/code\u003e\u003c/a\u003e Fail cert path validation closed instead\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commit/213e9ba052632c9915704edbab48d4667141c3f2\"\u003e\u003ccode\u003e213e9ba\u003c/code\u003e\u003c/a\u003e Add test for failure to chain to trust anchor\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commit/989507a62d23960933b44018c1b090da0e73c803\"\u003e\u003ccode\u003e989507a\u003c/code\u003e\u003c/a\u003e Add tests for notAfter enforcement\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commit/b55f4b957881ca6a0c93d05aebca6cdf6424fffb\"\u003e\u003ccode\u003eb55f4b9\u003c/code\u003e\u003c/a\u003e Move explanation into test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commit/7bed04ce33a8fc2e4b0c2f8c84d7c171f001905f\"\u003e\u003ccode\u003e7bed04c\u003c/code\u003e\u003c/a\u003e Update comments around cert chain validity\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commit/6ee964484ad9bb9365c45c95b32e0065db45ed96\"\u003e\u003ccode\u003e6ee9644\u003c/code\u003e\u003c/a\u003e Add new tests\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/MasterKale/SimpleWebAuthn/commits/v13.3.3/packages/server\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@types/pg` from 8.20.0 to 8.23.1\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/pg\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `axios` from 1.17.0 to 1.20.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/axios/axios/releases\"\u003eaxios's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.20.0 — August 19, 2026\u003c/h2\u003e\n\u003cp\u003eThis release hardens runtime option handling, adds RFC 9110 status-code aliases, fixes Node.js and XHR reliability issues, and refreshes project tooling and documentation.\u003c/p\u003e\n\u003ch2\u003e⚠️ Breaking Changes \u0026amp; Deprecations\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHTTP Status Naming: Added ContentTooLarge (413) and UnprocessableContent (422), while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11082\"\u003e#11082\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRuntime Option Handling: Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects. This also clarifies Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection; see the PR for documented compatibility effects. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11141\"\u003e#11141\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eInterceptor Lifecycle: Prevented unbounded handler-array growth by trimming trailing ejected interceptors without changing iteration semantics, and kept interceptor operations safe when the public handlers field is nullish. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11087\"\u003e#11087\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11118\"\u003e#11118\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequest Error Preservation: Prevented custom Error.prepareStackTrace implementations that return non-string values from replacing the original request failure with an unrelated TypeError. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11109\"\u003e#11109\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eXHR Reliability: Navigation-canceled requests now reject with ECONNABORTED instead of resolving with status 0, while successful downloads flush their final progress callback during the live loadend dispatch. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11094\"\u003e#11094\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11121\"\u003e#11121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNode.js Socket Memory: Removed request-context retention from per-socket error listeners, preventing completed response data from being pinned for the lifetime of pooled keep-alive sockets. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11091\"\u003e#11091\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCore Methods and HTTP Errors: Prevented structural method-header buckets from leaking into outgoing headers, standardized invalid DNS lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE, and corrected the timeoutErrorMessage merge strategy. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11096\"\u003e#11096\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔧 Maintenance \u0026amp; Chores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDependencies: Updated fast-uri, postcss, js-yaml, mocha, development-tooling groups, and GitHub Actions dependencies. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11092\"\u003e#11092\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11098\"\u003e#11098\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11099\"\u003e#11099\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11106\"\u003e#11106\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11107\"\u003e#11107\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11122\"\u003e#11122\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11123\"\u003e#11123\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11126\"\u003e#11126\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11127\"\u003e#11127\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11133\"\u003e#11133\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11140\"\u003e#11140\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11143\"\u003e#11143\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11144\"\u003e#11144\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDocumentation: Applied the v1.19.0 documentation updates, added the missing fs import to the README stream example, introduced localized global search, and repaired the interceptor test link. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11101\"\u003e#11101\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11113\"\u003e#11113\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11097\"\u003e#11097\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11119\"\u003e#11119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSponsorship: Updated sponsorship links and data and added ScrapingBee as a sponsor. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11124\"\u003e#11124\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11136\"\u003e#11136\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11137\"\u003e#11137\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCI and Release: Switched ESM smoke tests to locked dependencies and synchronized package and runtime version metadata for v1.20.0. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11128\"\u003e#11128\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11152\"\u003e#11152\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🌟 New Contributors\u003c/h2\u003e\n\u003cp\u003eWe are thrilled to welcome our new contributors. Thank you for helping improve axios:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yens1\"\u003e\u003ccode\u003e@​yens1\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11109\"\u003e#11109\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Sasireddy001\"\u003e\u003ccode\u003e@​Sasireddy001\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11113\"\u003e#11113\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ari-token-security\"\u003e\u003ccode\u003e@​ari-token-security\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11094\"\u003e#11094\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timothyokooboh\"\u003e\u003ccode\u003e@​timothyokooboh\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11097\"\u003e#11097\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gi9439041-png\"\u003e\u003ccode\u003e@​gi9439041-png\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11119\"\u003e#11119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Hashim1999164\"\u003e\u003ccode\u003e@​Hashim1999164\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11082\"\u003e#11082\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/v-dev-cl\"\u003e\u003ccode\u003e@​v-dev-cl\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11091\"\u003e#11091\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0h1tb\"\u003e\u003ccode\u003e@​r0h1tb\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11118\"\u003e#11118\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ostapondo\"\u003e\u003ccode\u003e@​ostapondo\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11121\"\u003e#11121\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFull Changelog (\u003ca href=\"https://github.com/axios/axios/compare/v1.19.0...v1.20.0\"\u003ehttps://github.com/axios/axios/compare/v1.19.0...v1.20.0\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003ev1.19.0 - July 22, 2026\u003c/h2\u003e\n\u003cp\u003eThis release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMultipart Form Data: Raised the form-data dependency floor to ^4.0.6, preventing fresh installations from resolving versions affected by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (\u003ca href=\"https://github.com/advisories/GHSA-hmw2-7cc7-3qxx\"\u003ehttps://github.com/advisories/GHSA-hmw2-7cc7-3qxx\u003c/a\u003e). (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11028\"\u003e#11028\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/axios/axios/blob/v1.x/CHANGELOG.md\"\u003eaxios's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog\u003c/h1\u003e\n\u003ch2\u003ev1.19.0 — July 22, 2026\u003c/h2\u003e\n\u003cp\u003eThis release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMultipart Form Data: Raised the form-data dependency floor to ^4.0.6, preventing fresh installations from resolving versions affected by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (\u003ca href=\"https://github.com/advisories/GHSA-hmw2-7cc7-3qxx\"\u003ehttps://github.com/advisories/GHSA-hmw2-7cc7-3qxx\u003c/a\u003e). (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11028\"\u003e#11028\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚀 New Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eConfiguration Extensibility: Preserved own-enumerable symbol-keyed fields through mergeConfig and added a generic params type across public TypeScript declarations, responses, errors,\nadapters, and serializers. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11043\"\u003e#11043\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11081\"\u003e#11081\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHeader Parameter Parsing: Added the opt-in AxiosHeaders.parseParameters() parser for quote-aware, RFC-style HTTP parameter parsing while preserving legacy parsing behavior. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11051\"\u003e#11051\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHTTP Status Codes: Added the missing Cloudflare 520 WebServerReturnsAnUnknownError status and matching ESM/CJS declarations. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11067\"\u003e#11067\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eForm Data Conversion: Limited formDataToJSON path splitting to dot and bracket notation, preserving literal punctuation in keys, and removed browser-facing Buffer.from usage from toFormData to avoid unnecessary polyfills. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11006\"\u003e#11006\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11018\"\u003e#11018\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eProxy Bypass: Canonicalized IPv4 shorthand, octal, and hexadecimal forms during NO_PROXY matching and honored * entries within comma- or space-separated bypass lists. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11029\"\u003e#11029\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11053\"\u003e#11053\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eCancellation: Propagated already-aborted input signals immediately when composing abort signals. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11035\"\u003e#11035\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eHeader Handling: Preserved empty first values for duplicate singleton headers and made AxiosHeaders#getSetCookie() consistently return arrays for present values. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11036\"\u003e#11036\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11037\"\u003e#11037\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eURL Handling: Included normalized, safely redacted offending URLs in malformed-protocol errors and removed repeated trailing slashes when combining base URLs. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11008\"\u003e#11008\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11038\"\u003e#11038\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eProgress Events: Clamped malformed negative progress values to zero and ensured final Node.js download progress events are delivered before streamed responses close. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11039\"\u003e#11039\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11040\"\u003e#11040\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eError and JSON Serialization: Serialized Set values as arrays in JSON-compatible snapshots and synthesized useful AxiosError messages from otherwise-empty AggregateError instances. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11044\"\u003e#11044\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11059\"\u003e#11059\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eContent-Length Enforcement: Corrected base64 data: URL size estimation so maxContentLength is enforced consistently by the HTTP and Fetch adapters. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11061\"\u003e#11061\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSynchronous Interceptors: Prevented requests from being dispatched after synchronous request interceptors fail unless their paired rejection handler resolves successfully. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11071\"\u003e#11071\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔧 Maintenance \u0026amp; Chores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDependencies: Updated development and test tooling, the docs fixture's Axios version, and GitHub Actions integrations including Checkout, Setup Node, Setup Deno, and Zizmor. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11031\"\u003e#11031\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11055\"\u003e#11055\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11056\"\u003e#11056\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11058\"\u003e#11058\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11079\"\u003e#11079\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11080\"\u003e#11080\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11088\"\u003e#11088\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11089\"\u003e#11089\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11090\"\u003e#11090\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBuild Outputs: Limited sourcemap generation to published minified bundles, removing broken map references from non-minified builds. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11054\"\u003e#11054\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eForm Data Internals: Centralized FormData header handling and made the Node.js adapter tolerate getHeaders() returning undefined under the content-only policy. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11062\"\u003e#11062\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeveloper Experience: Ignored common local AI-tooling directories and fixed a constant-reassignment crash when the development sandbox serves its root path. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11032\"\u003e#11032\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11073\"\u003e#11073\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDocumentation: Updated sponsor information, clarified that baseURL is not a path-security boundary, scoped provenance claims to attested releases, and corrected the configuration-defaults documentation. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11041\"\u003e#11041\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11068\"\u003e#11068\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11076\"\u003e#11076\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11078\"\u003e#11078\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePublishing: Simplified v1 publishing to use the npm version bundled with Node.js 26 and updated package metadata for the 1.19.0 release. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11083\"\u003e#11083\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11095\"\u003e#11095\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🌟 New Contributors\u003c/h2\u003e\n\u003cp\u003eWe are thrilled to welcome our new contributors. Thank you for helping improve Axios:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/afonsojramos\"\u003e\u003ccode\u003e@​afonsojramos\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11028\"\u003e#11028\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11006\"\u003e#11006\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yassertawfik4\"\u003e\u003ccode\u003e@​yassertawfik4\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/1...\n\n_Description has been truncated_","html_url":"https://github.com/nonameinnameaaaa/VoiceHub/pull/13","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/nonameinnameaaaa%2FVoiceHub/issues/13","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/13/packages"}},{"old_version":"3.1.2","new_version":"3.1.7","update_type":"patch","path":null,"pr_created_at":"2026-09-11T23:12:14.000Z","version_change":"3.1.2 → 3.1.7","issue":{"uuid":"5429737493","node_id":"PR_kwDOPhFD_88AAAABDNb95w","number":22,"state":"open","title":"chore(deps): bump the npm_and_yarn group across 1 directory with 14 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T23:12:14.000Z","updated_at":"2026-09-11T23:12:23.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":14,"packages":[{"name":"axios","old_version":"1.16.0","new_version":"1.18.0","repository_url":"https://github.com/axios/axios"},{"name":"postcss","old_version":"8.5.15","new_version":"8.5.28","repository_url":"https://github.com/postcss/postcss"},{"name":"vite","old_version":"7.3.2","new_version":"7.3.6","repository_url":"https://github.com/vitejs/vite"},{"name":"@babel/core","old_version":"7.28.3","new_version":"7.29.0","repository_url":"https://github.com/babel/babel"},{"name":"@humanfs/node","old_version":"0.16.6","new_version":"0.16.7","repository_url":"https://github.com/humanwhocodes/humanfs"},{"name":"brace-expansion","old_version":"2.0.2","new_version":"2.1.4","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"brace-expansion","old_version":"1.1.12","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"brace-expansion","old_version":"1.1.13","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"browserslist","old_version":"4.25.3","new_version":"4.28.1","repository_url":"https://github.com/browserslist/browserslist"},{"name":"esbuild","old_version":"0.27.7","new_version":"0.28.2","repository_url":"https://github.com/evanw/esbuild"},{"name":"fast-uri","old_version":"3.1.2","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"form-data","old_version":"4.0.5","new_version":"4.0.6","repository_url":"https://github.com/form-data/form-data"},{"name":"js-yaml","old_version":"4.1.1","new_version":"4.3.2","repository_url":"https://github.com/nodeca/js-yaml"},{"name":"postcss-selector-parser","old_version":"6.1.2","new_version":"6.1.4","repository_url":"https://github.com/postcss/postcss-selector-parser"},{"name":"shell-quote","old_version":"1.8.4","new_version":"1.10.0","repository_url":"https://github.com/ljharb/shell-quote"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 13 updates in the /src/ForexRateAlerter.Web directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [axios](https://github.com/axios/axios) | `1.16.0` | `1.18.0` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.15` | `8.5.28` |\n| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `7.3.2` | `7.3.6` |\n| [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) | `7.28.3` | `7.29.0` |\n| [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node) | `0.16.6` | `0.16.7` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `2.0.2` | `2.1.4` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.12` | `1.1.18` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.13` | `1.1.18` |\n| [browserslist](https://github.com/browserslist/browserslist) | `4.25.3` | `4.28.1` |\n| [esbuild](https://github.com/evanw/esbuild) | `0.27.7` | `0.28.2` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.2` | `3.1.7` |\n| [form-data](https://github.com/form-data/form-data) | `4.0.5` | `4.0.6` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.1` | `4.3.2` |\n| [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) | `6.1.2` | `6.1.4` |\n| [shell-quote](https://github.com/ljharb/shell-quote) | `1.8.4` | `1.10.0` |\n\n\nUpdates `axios` from 1.16.0 to 1.18.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/axios/axios/releases\"\u003eaxios's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.18.0 — June 13, 2026\u003c/h2\u003e\n\u003cp\u003eThis release hardens redirect and URL handling, improves the validateStatus configuration semantics, and includes updates to documentation, dependencies, and release metadata.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRedirect Header Safety:\u003c/strong\u003e Added Node HTTP adapter support for stripping caller-specified sensitive headers on cross-origin redirects, helping prevent custom auth headers such as API keys from leaking to another origin. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10892\"\u003e#10892\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eURL And Request Hardening:\u003c/strong\u003e Rejects malformed \u003ccode\u003ehttp:\u003c/code\u003e and \u003ccode\u003ehttps:\u003c/code\u003e URLs that omit \u003ccode\u003e//\u003c/code\u003e with \u003ccode\u003eERR_INVALID_URL\u003c/code\u003e, while tightening prototype-pollution-safe config reads, stream size limits, FormData depth handling, data URL sizing, and local \u003ccode\u003eNO_PROXY\u003c/code\u003e matching. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11000\"\u003e#11000\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eStatus Validation:\u003c/strong\u003e Added \u003ccode\u003etransitional.validateStatusUndefinedResolves\u003c/code\u003e so applications can opt in to treating \u003ccode\u003evalidateStatus: undefined\u003c/code\u003e like the option was omitted, while \u003ccode\u003evalidateStatus: null\u003c/code\u003e remains the explicit way to accept every status. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔧 Maintenance \u0026amp; Chores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDocumentation:\u003c/strong\u003e Published the v1.17.0 release notes, fixed a changelog typo, clarified the package update PR policy, and marked the \u003ccode\u003eproxy\u003c/code\u003e request config as Node.js-only in the advanced docs. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10988\"\u003e#10988\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10992\"\u003e#10992\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDependencies:\u003c/strong\u003e Bumped \u003ccode\u003e@babel/core\u003c/code\u003e, \u003ccode\u003e@babel/preset-env\u003c/code\u003e, \u003ccode\u003e@commitlint/cli\u003c/code\u003e, \u003ccode\u003e@commitlint/config-conventional\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-babel\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-commonjs\u003c/code\u003e, \u003ccode\u003e@vitest/browser\u003c/code\u003e, \u003ccode\u003e@vitest/browser-playwright\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003elint-staged\u003c/code\u003e, \u003ccode\u003erollup\u003c/code\u003e, \u003ccode\u003evitest\u003c/code\u003e, and \u003ccode\u003eactions/checkout\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10989\"\u003e#10989\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10996\"\u003e#10996\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10997\"\u003e#10997\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRelease Metadata:\u003c/strong\u003e Prepared the 1.18.0 release by updating package metadata and the runtime \u003ccode\u003eVERSION\u003c/code\u003e value. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11003\"\u003e#11003\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🌟 New Contributors\u003c/h2\u003e\n\u003cp\u003eWe are thrilled to welcome our new contributors. Thank you for helping improve axios:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/drori12\"\u003e\u003ccode\u003e@​drori12\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/eyupcanakman\"\u003e\u003ccode\u003e@​eyupcanakman\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/Adi-Beker\"\u003e\u003ccode\u003e@​Adi-Beker\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/axios/axios/compare/v1.17.0...v1.18.0\"\u003eFull Changelog\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.17.0 — June 1, 2026\u003c/h2\u003e\n\u003cp\u003eThis release adds Node HTTP zstd decompression, hardens config and release workflows, and fixes authentication, header, proxy, and type-handling regressions.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eConfig Hardening:\u003c/strong\u003e Guarded \u003ccode\u003esocketPath\u003c/code\u003e, \u003ccode\u003eparams\u003c/code\u003e, and \u003ccode\u003eparamsSerializer\u003c/code\u003e reads with own-property checks to prevent inherited prototype values from affecting request behavior, including SSRF-sensitive paths. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10901\"\u003e#10901\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10922\"\u003e#10922\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRelease Publishing:\u003c/strong\u003e Switched the publish workflow to npm staged publishing for safer, auditable package releases with provenance. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10926\"\u003e#10926\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚀 New Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eHTTP Compression:\u003c/strong\u003e Added Node HTTP adapter support for zstd response decompression, with \u003ccode\u003etransitional.advertiseZstdAcceptEncoding\u003c/code\u003e controlling whether \u003ccode\u003ezstd\u003c/code\u003e is advertised in \u003ccode\u003eAccept-Encoding\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/6792\"\u003e#6792\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10920\"\u003e#10920\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eAuthentication Handling:\u003c/strong\u003e Restored Basic auth on same-origin Node redirects while continuing to strip credentials cross-origin, and aligned the fetch adapter with HTTP adapter behavior for URL-embedded Basic auth. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10929\"\u003e#10929\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10896\"\u003e#10896\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eProxy TLS:\u003c/strong\u003e Preserved user \u003ccode\u003ehttpsAgent\u003c/code\u003e TLS options when tunneling HTTPS requests through HTTP CONNECT proxies. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10957\"\u003e#10957\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReact Native FormData:\u003c/strong\u003e Cleared default \u003ccode\u003eContent-Type\u003c/code\u003e for React Native \u003ccode\u003eFormData\u003c/code\u003e so multipart boundaries can be generated correctly. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10898\"\u003e#10898\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/axios/axios/blob/v1.x/CHANGELOG.md\"\u003eaxios's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.18.0 — June 13, 2026\u003c/h2\u003e\n\u003cp\u003eThis release hardens redirect and URL handling, improves the validateStatus configuration semantics, and includes updates to documentation, dependencies, and release metadata.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRedirect Header Safety:\u003c/strong\u003e Added Node HTTP adapter support for stripping caller-specified sensitive headers on cross-origin redirects, helping prevent custom auth headers such as API keys from leaking to another origin. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10892\"\u003e#10892\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eURL And Request Hardening:\u003c/strong\u003e Rejects malformed \u003ccode\u003ehttp:\u003c/code\u003e and \u003ccode\u003ehttps:\u003c/code\u003e URLs that omit \u003ccode\u003e//\u003c/code\u003e with \u003ccode\u003eERR_INVALID_URL\u003c/code\u003e, while tightening prototype-pollution-safe config reads, stream size limits, FormData depth handling, data URL sizing, and local \u003ccode\u003eNO_PROXY\u003c/code\u003e matching. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11000\"\u003e#11000\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eStatus Validation:\u003c/strong\u003e Added \u003ccode\u003etransitional.validateStatusUndefinedResolves\u003c/code\u003e so applications can opt in to treating \u003ccode\u003evalidateStatus: undefined\u003c/code\u003e like the option was omitted, while \u003ccode\u003evalidateStatus: null\u003c/code\u003e remains the explicit way to accept every status. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔧 Maintenance \u0026amp; Chores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDocumentation:\u003c/strong\u003e Published the v1.17.0 release notes, fixed a changelog typo, clarified the package update PR policy, and marked the \u003ccode\u003eproxy\u003c/code\u003e request config as Node.js-only in the advanced docs. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10988\"\u003e#10988\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10992\"\u003e#10992\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDependencies:\u003c/strong\u003e Bumped \u003ccode\u003e@babel/core\u003c/code\u003e, \u003ccode\u003e@babel/preset-env\u003c/code\u003e, \u003ccode\u003e@commitlint/cli\u003c/code\u003e, \u003ccode\u003e@commitlint/config-conventional\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-babel\u003c/code\u003e, \u003ccode\u003e@rollup/plugin-commonjs\u003c/code\u003e, \u003ccode\u003e@vitest/browser\u003c/code\u003e, \u003ccode\u003e@vitest/browser-playwright\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003elint-staged\u003c/code\u003e, \u003ccode\u003erollup\u003c/code\u003e, \u003ccode\u003evitest\u003c/code\u003e, and \u003ccode\u003eactions/checkout\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10989\"\u003e#10989\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10996\"\u003e#10996\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10997\"\u003e#10997\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eRelease Metadata:\u003c/strong\u003e Prepared the 1.18.0 release by updating package metadata and the runtime \u003ccode\u003eVERSION\u003c/code\u003e value. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/11003\"\u003e#11003\u003c/a\u003e\u003c/strong\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🌟 New Contributors\u003c/h2\u003e\n\u003cp\u003eWe are thrilled to welcome our new contributors. Thank you for helping improve axios:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/drori12\"\u003e\u003ccode\u003e@​drori12\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10984\"\u003e#10984\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/eyupcanakman\"\u003e\u003ccode\u003e@​eyupcanakman\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/Adi-Beker\"\u003e\u003ccode\u003e@​Adi-Beker\u003c/code\u003e\u003c/a\u003e\u003c/strong\u003e (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/axios/axios/compare/v1.17.0...v1.18.0\"\u003eFull Changelog\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.17.0 — June 1, 2026\u003c/h2\u003e\n\u003cp\u003eThis release adds Node HTTP zstd decompression, hardens config and release workflows, and fixes authentication, header, proxy, and type-handling regressions.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eConfig Hardening:\u003c/strong\u003e Guarded \u003ccode\u003esocketPath\u003c/code\u003e, \u003ccode\u003eparams\u003c/code\u003e, and \u003ccode\u003eparamsSerializer\u003c/code\u003e reads with own-property checks to prevent inherited prototype values from affecting request behavior, including SSRF-sensitive paths. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10901\"\u003e#10901\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10922\"\u003e#10922\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRelease Publishing:\u003c/strong\u003e Switched the publish workflow to npm staged publishing for safer, auditable package releases with provenance. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10926\"\u003e#10926\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚀 New Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eHTTP Compression:\u003c/strong\u003e Added Node HTTP adapter support for zstd response decompression, with \u003ccode\u003etransitional.advertiseZstdAcceptEncoding\u003c/code\u003e controlling whether \u003ccode\u003ezstd\u003c/code\u003e is advertised in \u003ccode\u003eAccept-Encoding\u003c/code\u003e. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/6792\"\u003e#6792\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10920\"\u003e#10920\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eAuthentication Handling:\u003c/strong\u003e Restored Basic auth on same-origin Node redirects while continuing to strip credentials cross-origin, and aligned the fetch adapter with HTTP adapter behavior for URL-embedded Basic auth. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10929\"\u003e#10929\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10896\"\u003e#10896\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eProxy TLS:\u003c/strong\u003e Preserved user \u003ccode\u003ehttpsAgent\u003c/code\u003e TLS options when tunneling HTTPS requests through HTTP CONNECT proxies. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10957\"\u003e#10957\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReact Native FormData:\u003c/strong\u003e Cleared default \u003ccode\u003eContent-Type\u003c/code\u003e for React Native \u003ccode\u003eFormData\u003c/code\u003e so multipart boundaries can be generated correctly. (\u003cstrong\u003e\u003ca href=\"https://redirect.github.com/axios/axios/issues/10898\"\u003e#10898\u003c/a\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/2d06f96e8602c2db13b65a26340ee4a1bbc0b61f\"\u003e\u003ccode\u003e2d06f96\u003c/code\u003e\u003c/a\u003e chore(release): prepare release 1.18.0 (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11003\"\u003e#11003\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/32fc489632377d214db55bfa4e2c48486a7d7ce2\"\u003e\u003ccode\u003e32fc489\u003c/code\u003e\u003c/a\u003e fix: malformed http urls (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11000\"\u003e#11000\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/b40ce498abfa10d90b873b4fd08f520afa5d2545\"\u003e\u003ccode\u003eb40ce49\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump the development_dependencies group with 10 updates (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10\"\u003e#10\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/fe964f960ecb52c3e1155b0daf7be77541956b01\"\u003e\u003ccode\u003efe964f9\u003c/code\u003e\u003c/a\u003e docs: mark proxy config as Node.js only (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10995\"\u003e#10995\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/5f229d2d1f018d1db3dab6bbe034dbf3f9041b99\"\u003e\u003ccode\u003e5f229d2\u003c/code\u003e\u003c/a\u003e chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/fae9d4e7db6a858c407c75e607a071c533c5c4f6\"\u003e\u003ccode\u003efae9d4e\u003c/code\u003e\u003c/a\u003e docs: clarify package update PR policy (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10992\"\u003e#10992\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/28ab2ced820e55192806c53472ab3eb0cbb68dc2\"\u003e\u003ccode\u003e28ab2ce\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump the development_dependencies group with 2 updates (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10989\"\u003e#10989\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/a8e4f13aeecc45a3b8fab3ecfd9ddb5d70fb772b\"\u003e\u003ccode\u003ea8e4f13\u003c/code\u003e\u003c/a\u003e fix(core): keep default validateStatus when request passes undefined (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10899\"\u003e#10899\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/614f4552a17de757d4171ad7c3bd38c9c1025fd8\"\u003e\u003ccode\u003e614f455\u003c/code\u003e\u003c/a\u003e docs: publish v1.17.0 release notes (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10988\"\u003e#10988\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/6bb12c191f5380fad321322fb90216ae0dc36985\"\u003e\u003ccode\u003e6bb12c1\u003c/code\u003e\u003c/a\u003e fix: custom auth headers not stripped on cross-origin redirects (\u003ca href=\"https://redirect.github.com/axios/axios/issues/10892\"\u003e#10892\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/axios/axios/compare/v1.16.0...v1.18.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.15 to 8.5.28\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.28\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes types regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed removing any comments starting with \u003ccode\u003e/*#\u003c/code\u003e (by \u003ca href=\"https://github.com/dylanpulver\"\u003e\u003ccode\u003e@​dylanpulver\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e*\u003c/code\u003e hack before a comment in Custom Properties (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed empty values in the middle of \u003ccode\u003elist.comma()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed whitespace-only values in \u003ccode\u003elist.space()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed rule’s end position on space before semicolon (by \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/romainmenke\"\u003e\u003ccode\u003e@​romainmenke\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed Chinese text in deprecation warning (by \u003ca href=\"https://github.com/Jesse205\"\u003e\u003ccode\u003e@​Jesse205\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.28\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes types regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed removing any comments starting with \u003ccode\u003e/*#\u003c/code\u003e (by \u003ca href=\"https://github.com/dylanpulver\"\u003e\u003ccode\u003e@​dylanpulver\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e*\u003c/code\u003e hack before a comment in Custom Properties (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed empty values in the middle of \u003ccode\u003elist.comma()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed whitespace-only values in \u003ccode\u003elist.space()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed rule’s end position on space before semicolon (by \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/romainmenke\"\u003e\u003ccode\u003e@​romainmenke\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed Chinese text in deprecation warning (by \u003ca href=\"https://github.com/Jesse205\"\u003e\u003ccode\u003e@​Jesse205\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/e544bffc4f4b3966d8ec69c41744b3ed65afc64a\"\u003e\u003ccode\u003ee544bff\u003c/code\u003e\u003c/a\u003e Release 8.5.28 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f8fc2525717a6a7216659f7be43c525f60c6a15a\"\u003e\u003ccode\u003ef8fc252\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/5039fd78962d285abea5d7b3aebef32f053781ce\"\u003e\u003ccode\u003e5039fd7\u003c/code\u003e\u003c/a\u003e Add missed release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/ae40ca499cf6a9afdbb264c0ec09e71fe934e2af\"\u003e\u003ccode\u003eae40ca4\u003c/code\u003e\u003c/a\u003e Release 8.5.27 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/62b1626bb7fbb28eda616d002cbd525d239b18ba\"\u003e\u003ccode\u003e62b1626\u003c/code\u003e\u003c/a\u003e Fix linter\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/1dba9384515a2dbc64517697c2f738b6d5c3f9a4\"\u003e\u003ccode\u003e1dba938\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3e82edc9f037faa41647342dceceba9b841f9881\"\u003e\u003ccode\u003e3e82edc\u003c/code\u003e\u003c/a\u003e Keep non-annotation comments when the processor has no plugins (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2150\"\u003e#2150\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/6d23bc362203118478bc8051b81f2910907ebe6e\"\u003e\u003ccode\u003e6d23bc3\u003c/code\u003e\u003c/a\u003e Fix link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/508e9976be81536292e7666741e1c35e876b9a6a\"\u003e\u003ccode\u003e508e997\u003c/code\u003e\u003c/a\u003e Add GitHub Sponsors link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/e993739dc49b6055f7dfc59b161d75702f0b2b8b\"\u003e\u003ccode\u003ee993739\u003c/code\u003e\u003c/a\u003e Add CodeRabbit sponsor (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2145\"\u003e#2145\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.15...8.5.28\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `vite` from 7.3.2 to 7.3.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/releases\"\u003evite's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.3.6\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.6/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.3.5\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.5/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.3.3\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.3/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.6/packages/vite/CHANGELOG.md\"\u003evite's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.5...v7.3.6\"\u003e7.3.6\u003c/a\u003e (2026-06-25)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eallow esbuild 0.28 (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22743\"\u003e#22743\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/a24931e7934e80eff5895b89d9e612ad3ad3e1f4\"\u003ea24931e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.3...v7.3.5\"\u003e7.3.5\u003c/a\u003e (2026-06-01)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ebackport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22572\"\u003e#22572\u003c/a\u003e, reject windows alternate paths (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22574\"\u003e#22574\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8c1855607b7c9884c4565d897ee98899a008a2d0\"\u003e8c18556\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e backport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22571\"\u003e#22571\u003c/a\u003e, reject UNC paths for launch-editor-middleware (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22573\"\u003e#22573\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/f20d64bef6e0ef1e4fa7a9783281c7bba0ce5292\"\u003ef20d64b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMiscellaneous Chores\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eskip v7.3.4 release (\u003ca href=\"https://github.com/vitejs/vite/commit/8a6a0c9fc734dbfe293ac33a4954506ee50430e1\"\u003e8a6a0c9\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.3...v7.3.4\"\u003e7.3.4\u003c/a\u003e (2026-06-01)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ebackport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22572\"\u003e#22572\u003c/a\u003e, reject windows alternate paths (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22574\"\u003e#22574\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8c1855607b7c9884c4565d897ee98899a008a2d0\"\u003e8c18556\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e backport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22571\"\u003e#22571\u003c/a\u003e, reject UNC paths for launch-editor-middleware (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22573\"\u003e#22573\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/f20d64bef6e0ef1e4fa7a9783281c7bba0ce5292\"\u003ef20d64b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.2...v7.3.3\"\u003e7.3.3\u003c/a\u003e (2026-05-07)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eavoid destructure lowering for newer safari (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22346\"\u003e#22346\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/5ab51c0f76f0896175e02ad797c1f5fe116d02f4\"\u003e5ab51c0\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/0a7b53ba230c6e68f502a89864534c607d393ab7\"\u003e\u003ccode\u003e0a7b53b\u003c/code\u003e\u003c/a\u003e release: v7.3.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/a24931e7934e80eff5895b89d9e612ad3ad3e1f4\"\u003e\u003ccode\u003ea24931e\u003c/code\u003e\u003c/a\u003e feat: allow esbuild 0.28 (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22743\"\u003e#22743\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/077945cb60df372a52cf999b6e532ba70fac7423\"\u003e\u003ccode\u003e077945c\u003c/code\u003e\u003c/a\u003e release: v7.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/8a6a0c9fc734dbfe293ac33a4954506ee50430e1\"\u003e\u003ccode\u003e8a6a0c9\u003c/code\u003e\u003c/a\u003e chore: skip v7.3.4 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/8c1855607b7c9884c4565d897ee98899a008a2d0\"\u003e\u003ccode\u003e8c18556\u003c/code\u003e\u003c/a\u003e fix: backport \u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22572\"\u003e#22572\u003c/a\u003e, reject windows alternate paths (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22574\"\u003e#22574\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/f20d64bef6e0ef1e4fa7a9783281c7bba0ce5292\"\u003e\u003ccode\u003ef20d64b\u003c/code\u003e\u003c/a\u003e fix(deps): backport \u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22571\"\u003e#22571\u003c/a\u003e, reject UNC paths for launch-editor-middleware (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/2\"\u003e#2\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/ca31424cccb075c88131132b929a63527d0e2b69\"\u003e\u003ccode\u003eca31424\u003c/code\u003e\u003c/a\u003e release: v7.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/5ab51c0f76f0896175e02ad797c1f5fe116d02f4\"\u003e\u003ccode\u003e5ab51c0\u003c/code\u003e\u003c/a\u003e fix: avoid destructure lowering for newer safari (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22346\"\u003e#22346\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/vitejs/vite/commits/v7.3.6/packages/vite\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@babel/core` from 7.28.3 to 7.29.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/babel/babel/releases\"\u003e@​babel/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0 (2026-01-31)\u003c/h2\u003e\n\u003cp\u003eThanks \u003ca href=\"https://github.com/simbahax\"\u003e\u003ccode\u003e@​simbahax\u003c/code\u003e\u003c/a\u003e for your first PR!\u003c/p\u003e\n\u003ch4\u003e:rocket: New Feature\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-types\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17750\"\u003e#17750\u003c/a\u003e [7.x backport] Add attributes import declaration builder (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-standalone\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17663\"\u003e#17663\u003c/a\u003e [7.x backport] feat(standalone): export async transform (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17725\"\u003e#17725\u003c/a\u003e [7.x backport] feat: read standalone targets from data-targets (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17765\"\u003e#17765\u003c/a\u003e fix(parser): correctly parse type assertions in \u003ccode\u003eextends\u003c/code\u003e clause (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17723\"\u003e#17723\u003c/a\u003e [7.x backport] fix(parser): improve super type argument parsing (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-traverse\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17708\"\u003e#17708\u003c/a\u003e fix(traverse): provide a hub when traversing a File or Program and no parentPath is given (\u003ca href=\"https://github.com/simbahax\"\u003e\u003ccode\u003e@​simbahax\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-transform-block-scoping\u003c/code\u003e, \u003ccode\u003ebabel-traverse\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17737\"\u003e#17737\u003c/a\u003e [7.x backport] fix: Rename switch discriminant references when body creates shadowing variable (\u003ca href=\"https://github.com/magic-akari\"\u003e\u003ccode\u003e@​magic-akari\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:running_woman: Performance\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e, \u003ccode\u003ebabel-runtime-corejs3\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17642\"\u003e#17642\u003c/a\u003e [Babel 7] Improve generator performance (\u003ca href=\"https://github.com/liuxingbaoyu\"\u003e\u003ccode\u003e@​liuxingbaoyu\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 6\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eDavid (\u003ca href=\"https://github.com/simbahax\"\u003e\u003ccode\u003e@​simbahax\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/liuxingbaoyu\"\u003e\u003ccode\u003e@​liuxingbaoyu\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/magic-akari\"\u003e\u003ccode\u003e@​magic-akari\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.28.6 (2026-01-12)\u003c/h2\u003e\n\u003cp\u003eThanks \u003ca href=\"https://github.com/kadhirash\"\u003e\u003ccode\u003e@​kadhirash\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/kolvian\"\u003e\u003ccode\u003e@​kolvian\u003c/code\u003e\u003c/a\u003e for your first PRs!\u003c/p\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-cli\u003c/code\u003e, \u003ccode\u003ebabel-code-frame\u003c/code\u003e, \u003ccode\u003ebabel-core\u003c/code\u003e, \u003ccode\u003ebabel-helper-check-duplicate-nodes\u003c/code\u003e, \u003ccode\u003ebabel-helper-fixtures\u003c/code\u003e, \u003ccode\u003ebabel-helper-plugin-utils\u003c/code\u003e, \u003ccode\u003ebabel-node\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-flow-comments\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-modules-commonjs\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-property-mutators\u003c/code\u003e, \u003ccode\u003ebabel-preset-env\u003c/code\u003e, \u003ccode\u003ebabel-traverse\u003c/code\u003e, \u003ccode\u003ebabel-types\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17589\"\u003e#17589\u003c/a\u003e Improve Unicode handling in code-frame tokenizer (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-transform-regenerator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17556\"\u003e#17556\u003c/a\u003e fix: \u003ccode\u003etransform-regenerator\u003c/code\u003e correctly handles scope (\u003ca href=\"https://github.com/liuxingbaoyu\"\u003e\u003ccode\u003e@​liuxingbaoyu\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-transform-react-jsx\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17538\"\u003e#17538\u003c/a\u003e fix: Keep jsx comments (\u003ca href=\"https://github.com/liuxingbaoyu\"\u003e\u003ccode\u003e@​liuxingbaoyu\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:nail_care: Polish\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e, \u003ccode\u003ebabel-standalone\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17606\"\u003e#17606\u003c/a\u003e Polish(standalone): improve message on invalid preset/plugin (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:house: Internal\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-bugfix-v8-static-class-fields-redefine-readonly\u003c/code\u003e, \u003ccode\u003ebabel-plugin-proposal-decorators\u003c/code\u003e, \u003ccode\u003ebabel-plugin-proposal-import-attributes-to-assertions\u003c/code\u003e, \u003ccode\u003ebabel-plugin-proposal-import-wasm-source\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-async-do-expressions\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-decorators\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-destructuring-private\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-do-expressions\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-explicit-resource-management\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-export-default-from\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-flow\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-function-bind\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-function-sent\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-import-assertions\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-import-attributes\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-import-defer\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-import-source\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-jsx\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-module-blocks\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-optional-chaining-assign\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-partial-application\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-pipeline-operator\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-throw-expressions\u003c/code\u003e, \u003ccode\u003ebabel-plugin-syntax-typescript\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-async-generator-functions\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-async-to-generator\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-class-properties\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-class-static-block\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-dotall-regex\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-duplicate-named-capturing-groups-regex\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-explicit-resource-management\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-exponentiation-operator\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-json-strings\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-logical-assignment-operators\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-nullish-coalescing-operator\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-numeric-separator\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-object-rest-spread\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-optional-catch-binding\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-optional-chaining\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-private-methods\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-private-property-in-object\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-regexp-modifiers\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-unicode-property-regex\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-unicode-sets-regex\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17580\"\u003e#17580\u003c/a\u003e Allow Babel 8 in compatible Babel 7 plugins (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/aa8394e454337d118ac3d40bfa3ee1a3cb3f3ed2\"\u003e\u003ccode\u003eaa8394e\u003c/code\u003e\u003c/a\u003e v7.29.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/ad0d03f0c92404a60ec6b1c12f15febd38e2397a\"\u003e\u003ccode\u003ead0d03f\u003c/code\u003e\u003c/a\u003e [7.x backport] feat: Allow specifying startLine in code frame (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17739\"\u003e#17739\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/d7f400889567ae18ef9ac41b024b5120f6060e17\"\u003e\u003ccode\u003ed7f4008\u003c/code\u003e\u003c/a\u003e v7.28.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/e130225028e93e106135586f344cfa44c4aac847\"\u003e\u003ccode\u003ee130225\u003c/code\u003e\u003c/a\u003e Polish(standalone): improve message on invalid preset/plugin (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17606\"\u003e#17606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/99dcba5e71de3bd81ce14077cfa5b6df58e9b177\"\u003e\u003ccode\u003e99dcba5\u003c/code\u003e\u003c/a\u003e chore: enable some ts-eslint rules (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17592\"\u003e#17592\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/c92c4919771105140015167f25f7bacac77c90d9\"\u003e\u003ccode\u003ec92c491\u003c/code\u003e\u003c/a\u003e Improve Unicode handling in code-frame tokenizer (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17589\"\u003e#17589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/d725e399fd6a4da463cff4918cf71aa03b8beb14\"\u003e\u003ccode\u003ed725e39\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003eBABEL_7_TO_8_DANGEROUSLY_DISABLE_VERSION_CHECK\u003c/code\u003e (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17569\"\u003e#17569\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/c1b55f6ad56523ccc96fa68721de0bed2f2cdb23\"\u003e\u003ccode\u003ec1b55f6\u003c/code\u003e\u003c/a\u003e Use \u003ccode\u003eeslint.config.mts\u003c/code\u003e (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17573\"\u003e#17573\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/61647ae2397c82c3c71f077b5ab109106a5cac0f\"\u003e\u003ccode\u003e61647ae\u003c/code\u003e\u003c/a\u003e v7.28.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/42cb285b59fc99a8102d69bef6223b75617e9f46\"\u003e\u003ccode\u003e42cb285\u003c/code\u003e\u003c/a\u003e Improve \u003ccode\u003e@babel/core\u003c/code\u003e types (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17404\"\u003e#17404\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/babel/babel/commits/v7.29.0/packages/babel-core\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​babel/core\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@humanfs/node` from 0.16.6 to 0.16.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/humanwhocodes/humanfs/releases\"\u003e@​humanfs/node's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003enode: v0.16.7\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/compare/node-v0.16.6...node-v0.16.7\"\u003e0.16.7\u003c/a\u003e (2024-11-27)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd directory to package.json (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/f691b60a0df2ce9a5894b6af51acc2461654cf6b\"\u003ef691b60\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/humanwhocodes/humanfs/blob/main/packages/node/CHANGELOG.md\"\u003e@​humanfs/node's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/compare/node-v0.16.6...node-v0.16.7\"\u003e0.16.7\u003c/a\u003e (2024-11-27)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd directory to package.json (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/f691b60a0df2ce9a5894b6af51acc2461654cf6b\"\u003ef691b60\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/257b7b53eb2800daca06453ea385f9f2a098fcb9\"\u003e\u003ccode\u003e257b7b5\u003c/code\u003e\u003c/a\u003e chore: release main (\u003ca href=\"https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node/issues/142\"\u003e#142\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/f691b60a0df2ce9a5894b6af51acc2461654cf6b\"\u003e\u003ccode\u003ef691b60\u003c/code\u003e\u003c/a\u003e fix: Add directory to package.json\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/7b81d9accf36bed41883e5e0c2eaaefce8c15fee\"\u003e\u003ccode\u003e7b81d9a\u003c/code\u003e\u003c/a\u003e chore(deps): Upgrading retry dependency in node package. (\u003ca href=\"https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node/issues/140\"\u003e#140\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/humanwhocodes/humanfs/commits/node-v0.16.7/packages/node\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 2.0.2 to 2.1.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.1.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v2 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/109\"\u003e#109\u003c/a\u003e)  c3a817c\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v2.1.0...v2.1.1\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v2.1.0...v2.1.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/b25213dff0446d622f97d736420b9830ee1abc32\"\u003e\u003ccode\u003eb25213d\u003c/code\u003e\u003c/a\u003e 2.1.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac\"\u003e\u003ccode\u003e1e30c93\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/878df3989e816dfb28cbe0d64de0b88738ff0ed6\"\u003e\u003ccode\u003e878df39\u003c/code\u003e\u003c/a\u003e 2.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/c8bd93cfff4e45cb295557d2be17e1d1d4e52a11\"\u003e\u003ccode\u003ec8bd93c\u003c/code\u003e\u003c/a\u003e npm ignore .claude\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d13ff455a58b0d56704f0111e3c2a0b16ceb06eb\"\u003e\u003ccode\u003ed13ff45\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/130\"\u003e#130\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/9e67a3b151e418679ac4800f31f874ec6d220b4a\"\u003e\u003ccode\u003e9e67a3b\u003c/code\u003e\u003c/a\u003e 2.1.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/835d6be91201122d9adffb0c0c8c094189ace265\"\u003e\u003ccode\u003e835d6be\u003c/code\u003e\u003c/a\u003e fix: v2 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/123\"\u003e#123\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/64b71d31d7c43b956ce64fccc1dda5a3729be728\"\u003e\u003ccode\u003e64b71d3\u003c/code\u003e\u003c/a\u003e 2.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/c3a817c8e5421d19a37c9babcf3f216b6bf2e6b4\"\u003e\u003ccode\u003ec3a817c\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v2 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/109\"\u003e#109\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/1ee4a9069c69a51bd502aab289c0c6629c8920ca\"\u003e\u003ccode\u003e1ee4a90\u003c/code\u003e\u003c/a\u003e 2.1.0\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v2.0.2...v2.1.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.12 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.1.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v2 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/109\"\u003e#109\u003c/a\u003e)  c3a817c\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v2.1.0...v2.1.1\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v2.1.0...v2.1.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/b25213dff0446d622f97d736420b9830ee1abc32\"\u003e\u003ccode\u003eb25213d\u003c/code\u003e\u003c/a\u003e 2.1.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac\"\u003e\u003ccode\u003e1e30c93\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/878df3989e816dfb28cbe0d64de0b88738ff0ed6\"\u003e\u003ccode\u003e878df39\u003c/code\u003e\u003c/a\u003e 2.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/c8bd93cfff4e45cb295557d2be17e1d1d4e52a11\"\u003e\u003ccode\u003ec8bd93c\u003c/code\u003e\u003c/a\u003e npm ignore .claude\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d13ff455a58b0d56704f0111e3c2a0b16ceb06eb\"\u003e\u003ccode\u003ed13ff45\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/130\"\u003e#130\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/9e67a3b151e418679ac4800f31f874ec6d220b4a\"\u003e\u003ccode\u003e9e67a3b\u003c/code\u003e\u003c/a\u003e 2.1.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/835d6be91201122d9adffb0c0c8c094189ace265\"\u003e\u003ccode\u003e835d6be\u003c/code\u003e\u003c/a\u003e fix: v2 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/123\"\u003e#123\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/64b71d31d7c43b956ce64fccc1dda5a3729be728\"\u003e\u003ccode\u003e64b71d3\u003c/code\u003e\u003c/a\u003e 2.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/c3a817c8e5421d19a37c9babcf3f216b6bf2e6b4\"\u003e\u003ccode\u003ec3a817c\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v2 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/109\"\u003e#109\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/1ee4a9069c69a51bd502aab289c0c6629c8920ca\"\u003e\u003ccode\u003e1ee4a90\u003c/code\u003e\u003c/a\u003e 2.1.0\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v2.0.2...v2.1.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.13 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.1.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v2 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/109\"\u003e#109\u003c/a\u003e)  c3a817c\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v2.1.0...v2.1.1\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v2.1.0...v2.1.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/b25213dff0446d622f97d736420b9830ee1abc32\"\u003e\u003ccode\u003eb25213d\u003c/code\u003e\u003c/a\u003e 2.1.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac\"\u003e\u003ccode\u003e1e30c93\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/878df3989e816dfb28cbe0d64de0b88738ff0ed6\"\u003e\u003ccode\u003e878df39\u003c/code\u003e\u003c/a\u003e 2.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/c8bd93cfff4e45cb295557d2be17e1d1d4e52a11\"\u003e\u003ccode\u003ec8bd93c\u003c/code\u003e\u003c/a\u003e npm ignore .claude\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d13ff455a58b0d56704f0111e3c2a0b16ceb06eb\"\u003e\u003ccode\u003ed13ff45\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/130\"\u003e#130\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/9e67a3b151e418679ac4800f31f874ec6d220b4a\"\u003e\u003ccode\u003e9e67a3b\u003c/code\u003e\u003c/a\u003e 2.1.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/835d6be91201122d9adffb0c0c8c094189ace265\"\u003e\u003ccode\u003e835d6be\u003c/code\u003e\u003c/a\u003e fix: v2 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/123\"\u003e#123\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/64b71d31d7c43b956ce64fccc1dda5a3729be728\"\u003e\u003ccode\u003e64b71d3\u003c/code\u003e\u003c/a\u003e 2.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/c3a817c8e5421d19a37c9babcf3f216b6bf2e6b4\"\u003e\u003ccode\u003ec3a817c\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v2 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/109\"\u003e#109\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/1ee4a9069c69a51bd502aab289c0c6629c8920ca\"\u003e\u003ccode\u003e1ee4a90\u003c/code\u003e\u003c/a\u003e 2.1.0\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v2.0.2...v2.1.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `browserslist` from 4.25.3 to 4.28.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/releases\"\u003ebrowserslist's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved Baseline warning since we have it own warning.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.27.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003eBROWSERSLIST_TRACE_WARNING\u003c/code\u003e environment variable.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003ethrowOnMissing\u003c/code\u003e with \u003ccode\u003eextends\u003c/code\u003e query (by \u003ca href=\"https://github.com/alexander-akait\"\u003e\u003ccode\u003e@​alexander-akait\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003ebaseline-browser-mapping\u003c/code\u003e version requirement.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated Firefox ESR.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded Baseline queries (by \u003ca href=\"https://github.com/tonypconway\"\u003e\u003ccode\u003e@​tonypconway\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.25.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Windows support for custom stats (by \u003ca href=\"https://github.com/torgeilo\"\u003e\u003ccode\u003e@​torgeilo\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md\"\u003ebrowserslist's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved Baseline warning since we have it own warning.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.48.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003efirefox \u0026gt;= esr\u003c/code\u003e query support (by \u003ca href=\"https://github.com/SethFalco\"\u003e\u003ccode\u003e@​SethFalco\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/SethFalco\"\u003e\u003ccode\u003e@​SethFalco\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.27.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003eBROWSERSLIST_TRACE_WARNING\u003c/code\u003e environment variable.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003ethrowOnMissing\u003c/code\u003e with \u003ccode\u003eextends\u003c/code\u003e query (by \u003ca href=\"https://github.com/alexander-akait\"\u003e\u003ccode\u003e@​alexander-akait\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003ebaseline-browser-mapping\u003c/code\u003e version requirement.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated Firefox ESR.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded Baseline queries (by \u003ca href=\"https://github.com/tonypconway\"\u003e\u003ccode\u003e@​tonypconway\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.25.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Windows support for custom stats (by \u003ca href=\"https://github.com/torgeilo\"\u003e\u003ccode\u003e@​torgeilo\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/5cad191bc1a1e5beb7768ca263503cc15d0dcc7d\"\u003e\u003ccode\u003e5cad191\u003c/code\u003e\u003c/a\u003e Release 4.28.1 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/592e11969e5ba65ec1d71ded09c2404e2cdc41a2\"\u003e\u003ccode\u003e592e119\u003c/code\u003e\u003c/a\u003e Update dependencies to use new baseline library with a way to supress warning\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/dc1ea132f4922164eb4d649db5a1c50d38f0de01\"\u003e\u003ccode\u003edc1ea13\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/bb4fcc6d0317352597354135fde12262402a38bf\"\u003e\u003ccode\u003ebb4fcc6\u003c/code\u003e\u003c/a\u003e Fix link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/67a7b669b385812c6f9a45aa79eacfcb5f1b1581\"\u003e\u003ccode\u003e67a7b66\u003c/code\u003e\u003c/a\u003e Add browserslist-plausible link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/a4006b0c324b081971acf3367780660f8e4ddb23\"\u003e\u003ccode\u003ea4006b0\u003c/code\u003e\u003c/a\u003e Release 4.28.0 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/5644b5e8272e4af1b5e8ef1cd6df805975b04ccb\"\u003e\u003ccode\u003e5644b5e\u003c/code\u003e\u003c/a\u003e Update dependencies and add Multiocular to track changes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/90721c859e78f4cc311db39e11afb7042e279470\"\u003e\u003ccode\u003e90721c8\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/browserslist/browserslist/issues/909\"\u003e#909\u003c/a\u003e from SethFalco/esr-range\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/98d83747223c88c98e424e086a83dec50152bfe5\"\u003e\u003ccode\u003e98d8374\u003c/code\u003e\u003c/a\u003e feat: allow esr alias in firefox version ranges\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/436f4600a7bcab8e80ff6dd43f9f3b08f6273eec\"\u003e\u003ccode\u003e436f460\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/browserslist/browserslist/issues/910\"\u003e#910\u003c/a\u003e from SethFalco/docs\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/browserslist/browserslist/compare/4.25.3...4.28.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `esbuild` from 0.27.7 to 0.28.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/evanw/esbuild/releases\"\u003eesbuild's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.28.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix tree shaking bug due to TypeScript import alias (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4507\"\u003e#4507\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific \u003ccode\u003eimport\u003c/code\u003e assignment and looks something like this:\u003c/p\u003e\n\u003cpre lang=\"ts\"\u003e\u003ccode\u003eimport Base from './dep.js';\r\nimport Alias = Base.SomeType;\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix CSS minification bug involving \u003ccode\u003e\u0026amp;\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4497\"\u003e#4497\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug where esbuild's CSS minifier incorrectly removed a \u003ccode\u003e\u0026amp;\u003c/code\u003e when it was unsafe to do so. Here is an example:\u003c/p\u003e\n\u003cpre lang=\"css\"\u003e\u003ccode\u003e/* Original code */\r\n.a .b {\r\n  \u0026amp; .b:not(\u0026amp; .c) {\r\n    color: red;\r\n  }\r\n}\r\n\u003cp\u003e/* Old output (with --minify) */\u003cbr /\u003e\n.a .b{.b:not(\u0026amp; .c){color:red}}\u003c/p\u003e\n\u003cp\u003e/* New output (with --minify) */\u003cbr /\u003e\n.a .b{\u0026amp; .b:not(\u0026amp; .c){color:red}}\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eThis should match \u003ccode\u003e\u0026lt;span class=\u0026quot;a\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;yes\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u003c/code\u003e but not \u003ccode\u003e\u0026lt;span class=\u0026quot;a\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;no\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u003c/code\u003e. The old output incorrectly matched both.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAvoid overwriting input files without \u003ccode\u003e--allow-overwrite\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4484\"\u003e#4484\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eFor example: \u003ccode\u003eesbuild input.js --outfile=input.js\u003c/code\u003e tells esbuild to overwrite \u003ccode\u003einput.js\u003c/code\u003e with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.\u003c/p\u003e\n\u003cp\u003eThis release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless \u003ccode\u003e--allow-overwrite\u003c/code\u003e is explicitly present. This is done by not writing out any files when a build error is encountered.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix incorrect code generated when using top-level await (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4498\"\u003e#4498\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003ePreviously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing \u003ccode\u003easync\u003c/code\u003e on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an \u003ccode\u003easync\u003c/code\u003e module wrapper.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix a minification bug with lowered logical assignment operators (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4508\"\u003e#4508\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Original code\r\nfunction foo() {\r\n  let x\r\n  bar(x ||= {})\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/evanw/esbuild/blob/main/CHANGELOG.md\"\u003eesbuild's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.28.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix tree shaking bug due to TypeScript import alias (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4507\"\u003e#4507\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific \u003ccode\u003eimport\u003c/code\u003e assignment and looks something like this:\u003c/p\u003e\n\u003cpre lang=\"ts\"\u003e\u003ccode\u003eimport Base from './dep.js';\nimport Alias = Base.SomeType;\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix CSS minification bug involving \u003ccode\u003e\u0026amp;\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4497\"\u003e#4497\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug where esbuild's CSS minifier incorrectly removed a \u003ccode\u003e\u0026amp;\u003c/code\u003e when it was unsafe to do so. Here is an example:\u003c/p\u003e\n\u003cpre lang=\"css\"\u003e\u003ccode\u003e/* Original code */\n.a .b {\n  \u0026amp; .b:not(\u0026amp; .c) {\n    color: red;\n  }\n}\n\u003cp\u003e/* Old output (with --minify) */\u003cbr /\u003e\n.a .b{.b:not(\u0026amp; .c){color:red}}\u003c/p\u003e\n\u003cp\u003e/* New output (with --minify) */\u003cbr /\u003e\n.a .b{\u0026amp; .b:not(\u0026amp; .c){color:red}}\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eThis should match \u003ccode\u003e\u0026lt;span class=\u0026quot;a\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;yes\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u003c/code\u003e but not \u003ccode\u003e\u0026lt;span class=\u0026quot;a\u0026quot;\u0026gt;\u0026lt;span class=\u0026quot;b\u0026quot;\u0026gt;no\u0026lt;/span\u0026gt;\u0026lt;/span\u0026gt;\u003c/code\u003e. The old output incorrectly matched both.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAvoid overwriting input files without \u003ccode\u003e--allow-overwrite\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4484\"\u003e#4484\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eFor example: \u003ccode\u003eesbuild input.js --outfile=input.js\u003c/code\u003e tells esbuild to overwrite \u003ccode\u003einput.js\u003c/code\u003e with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.\u003c/p\u003e\n\u003cp\u003eThis release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless \u003ccode\u003e--allow-overwrite\u003c/code\u003e is explicitly present. This is done by not writing out any files when a build error is encountered.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix incorrect code generated when using top-level await (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4498\"\u003e#4498\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003ePreviously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing \u003ccode\u003easync\u003c/code\u003e on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an \u003ccode\u003easync\u003c/code\u003e module wrapper.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix a minification bug with lowered logical assignment operators (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4508\"\u003e#4508\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Original code\nfunction foo() {\n  let x\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/609683d892977362a0f99026cb74b96263d728a9\"\u003e\u003ccode\u003e609683d\u003c/code\u003e\u003c/a\u003e publish 0.28.2 to npm\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/11b1fe48df6859393d9469f323b5ebd17baaf989\"\u003e\u003ccode\u003e11b1fe4\u003c/code\u003e\u003c/a\u003e add to release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/ab50d91559a27e54cd0a27a403389130ea10d97d\"\u003e\u003ccode\u003eab50d91\u003c/code\u003e\u003c/a\u003e css: fix green/blue channel swap in oklch gamut mapping (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4488\"\u003e#4488\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/04627b6cf99b4a7491bebb0268173a7c77a85030\"\u003e\u003ccode\u003e04627b6\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4498\"\u003e#4498\u003c/a\u003e: \u003ccode\u003easync\u003c/code\u003e TLA checks need a worklist\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/5c15177a308c7224604058a769c4abf0a66b0a36\"\u003e\u003ccode\u003e5c15177\u003c/code\u003e\u003c/a\u003e disable \u003ccode\u003egopls\u003c/code\u003e in the \u003ccode\u003ego\u003c/code\u003e folder\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/fc2ee9babc5a2e8ea7ec7c10dd5850b71f7cec7e\"\u003e\u003ccode\u003efc2ee9b\u003c/code\u003e\u003c/a\u003e css: adjust parser to allow \u003ccode\u003e--foo: {...}\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/209db54371e62ad1c50e12e56bb93c74c53b0408\"\u003e\u003ccode\u003e209db54\u003c/code\u003e\u003c/a\u003e release notes for css nesting bugfix\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/c625d31bf08a0647ec724bf76c7115f7aec55971\"\u003e\u003ccode\u003ec625d31\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4497\"\u003e#4497\u003c/a\u003e: preserve nested ampersands during minification (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4500\"\u003e#4500\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/...\n\n_Description has been truncated_","html_url":"https://github.com/hopekali04/ForexRateAlerter/pull/22","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/hopekali04%2FForexRateAlerter/issues/22","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/22/packages"}}]}