{"id":198,"name":"undici","ecosystem":"npm","repository_url":"https://github.com/nodejs/undici","issues_count":16184,"created_at":"2025-06-06T15:01:33.121Z","updated_at":"2025-06-06T15:01:33.121Z","purl":"pkg:npm/undici","metadata":{"id":2500533,"name":"undici","ecosystem":"npm","description":"An HTTP/1.1 client, written from scratch for Node.js","homepage":"https://undici.nodejs.org","licenses":"MIT","normalized_licenses":["MIT"],"repository_url":"https://github.com/nodejs/undici","keywords_array":["fetch","http","https","promise","request","curl","wget","xhr","whatwg"],"namespace":null,"versions_count":244,"first_release_published_at":"2018-07-26T17:26:12.354Z","latest_release_published_at":"2025-05-20T07:19:22.524Z","latest_release_number":"7.10.0","last_synced_at":"2025-05-20T07:20:16.302Z","created_at":"2022-04-10T02:40:57.212Z","updated_at":"2025-06-02T02:00:34.964Z","registry_url":"https://www.npmjs.com/package/undici","install_command":"npm install undici","documentation_url":null,"metadata":{"funding":null,"dist-tags":{"test":"5.24.0-test.6","next":"7.0.0-alpha.10","six":"6.21.2","five":"5.29.0","latest":"7.10.0"}},"repo_metadata":{"id":36969980,"uuid":"133092972","full_name":"nodejs/undici","owner":"nodejs","description":"An HTTP/1.1 client, written from scratch for Node.js","archived":false,"fork":false,"pushed_at":"2024-10-29T09:47:12.000Z","size":10130,"stargazers_count":6197,"open_issues_count":222,"forks_count":542,"subscribers_count":51,"default_branch":"main","last_synced_at":"2024-10-29T11:49:31.355Z","etag":null,"topics":["client","http","nodejs"],"latest_commit_sha":null,"homepage":"https://nodejs.github.io/undici","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/nodejs.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":"GOVERNANCE.md","roadmap":null,"authors":null,"dei":null}},"created_at":"2018-05-11T22:07:48.000Z","updated_at":"2024-10-29T08:47:18.000Z","dependencies_parsed_at":"2023-10-16T03:26:14.914Z","dependency_job_id":"f47ca4c0-4a14-4d56-8564-035b65a32fff","html_url":"https://github.com/nodejs/undici","commit_stats":{"total_commits":2760,"total_committers":273,"mean_commits":10.10989010989011,"dds":"0.47282608695652173","last_synced_commit":"fe44b9b36718ff2c171568fc4a239ecb8eba038d"},"previous_names":["mcollina/undici"],"tags_count":180,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/nodejs","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":222088852,"owners_count":16929035,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"nodejs","name":"Node.js","uuid":"9950313","kind":"organization","description":"","email":null,"website":"https://nodejs.org","location":null,"twitter":"nodejs","company":null,"icon_url":"https://avatars.githubusercontent.com/u/9950313?v=4","repositories_count":207,"last_synced_at":"2024-04-15T13:18:59.622Z","metadata":{"has_sponsors_listing":false},"html_url":"https://github.com/nodejs","funding_links":[],"total_stars":216497,"followers":11140,"following":0,"created_at":"2022-11-02T16:20:00.045Z","updated_at":"2024-04-15T13:20:17.388Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/nodejs","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/nodejs/repositories"},"tags":[{"name":"v6.13.0","sha":"65f768c72762b38e3d35a8a4934c0830c41b0f6c","kind":"commit","published_at":"2024-04-12T08:41:58.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.13.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.13.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.13.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.13.0/manifests"},{"name":"v6.12.0","sha":"7751d9bcd5bbba45b60c90183aeab450b60c0831","kind":"commit","published_at":"2024-04-08T09:46:22.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.12.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.12.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.12.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.12.0/manifests"},{"name":"v6.11.1","sha":"6df3c738d03dc4014a26640316bf699950d62024","kind":"commit","published_at":"2024-04-02T16:44:30.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.11.1","html_url":"https://github.com/nodejs/undici/releases/tag/v6.11.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.11.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.11.1/manifests"},{"name":"v5.28.4","sha":"fb983069071f52e0a7ea0e71078459c765aae172","kind":"commit","published_at":"2024-04-02T16:35:50.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.28.4","html_url":"https://github.com/nodejs/undici/releases/tag/v5.28.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.28.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.28.4/manifests"},{"name":"v6.11.0","sha":"ee5f892f3955eaca37730ed30349153ba203e9cd","kind":"commit","published_at":"2024-04-02T10:40:02.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.11.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.11.0/manifests"},{"name":"v6.10.2","sha":"7485cd9b4cf9a86cb76b1597df527eba15755bfc","kind":"tag","published_at":"2024-03-27T09:34:32.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.10.2","html_url":"https://github.com/nodejs/undici/releases/tag/v6.10.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.10.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.10.2/manifests"},{"name":"v6.10.1","sha":"dd3918fee4f90e02fb93ff1bc04e707144041938","kind":"commit","published_at":"2024-03-21T11:12:02.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.10.1","html_url":"https://github.com/nodejs/undici/releases/tag/v6.10.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.10.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.10.1/manifests"},{"name":"v6.10.0","sha":"e434060efc659e30865d711eafb71a6b01915533","kind":"commit","published_at":"2024-03-21T11:04:51.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.10.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.10.0/manifests"},{"name":"v6.9.0","sha":"3e59a2d7d82ba62b3fd11796f6479579f35a6871","kind":"commit","published_at":"2024-03-14T17:12:36.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.9.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.9.0/manifests"},{"name":"v6.8.0","sha":"f84ec8087e11a26ee3553a0c601f6a73373edae6","kind":"commit","published_at":"2024-03-13T08:44:06.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.8.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.8.0/manifests"},{"name":"v6.7.1","sha":"219da8b7b3fea7e38a7644b8bc35fe6fec97d66e","kind":"commit","published_at":"2024-03-08T08:48:42.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.7.1","html_url":"https://github.com/nodejs/undici/releases/tag/v6.7.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.7.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.7.1/manifests"},{"name":"v6.7.0","sha":"2316bae1b790517b9fbc8d066582410604ab733b","kind":"commit","published_at":"2024-03-03T17:08:17.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.7.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.7.0/manifests"},{"name":"v6.6.2","sha":"e48df9620edf1428bd457f481d47fa2c77f75322","kind":"commit","published_at":"2024-02-06T18:06:36.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.6.2","html_url":"https://github.com/nodejs/undici/releases/tag/v6.6.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.6.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.6.2/manifests"},{"name":"v6.6.1","sha":"d36b19eeaf89b0c02e309bb3bb780c1977b21feb","kind":"commit","published_at":"2024-02-05T11:26:34.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.6.1","html_url":"https://github.com/nodejs/undici/releases/tag/v6.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.6.1/manifests"},{"name":"v5.28.3","sha":"e71cb4c88faae5670a129fde5552266afc2dbc39","kind":"commit","published_at":"2024-02-05T11:25:23.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.28.3","html_url":"https://github.com/nodejs/undici/releases/tag/v5.28.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.28.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.28.3/manifests"},{"name":"v6.6.0","sha":"fa2d2d29a46412f8fb1f1a1ecf07b73e0db66a32","kind":"commit","published_at":"2024-02-01T09:35:25.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.6.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.6.0/manifests"},{"name":"v6.5.0","sha":"519b9e13543a594bcfa4d1954bf639c10cf3e824","kind":"commit","published_at":"2024-01-26T15:10:18.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.5.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.5.0/manifests"},{"name":"v6.4.0","sha":"9b8ee28b1080cebba211b84b6d89682d6fcb2df4","kind":"commit","published_at":"2024-01-19T15:00:17.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.4.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.4.0/manifests"},{"name":"v6.3.0","sha":"887d1cb2df84abdf7c57fb74342d3a51db681652","kind":"commit","published_at":"2024-01-08T14:56:10.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.3.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.3.0/manifests"},{"name":"v6.2.1","sha":"f51f917061aec737edfe635e52db5bccc6fc0ac6","kind":"commit","published_at":"2023-12-22T09:34:17.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.2.1","html_url":"https://github.com/nodejs/undici/releases/tag/v6.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.2.1/manifests"},{"name":"v6.2.0","sha":"0c4c4504852c71dac1a6eb8dfae0f2411b6f2fc6","kind":"commit","published_at":"2023-12-20T15:33:02.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.2.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.2.0/manifests"},{"name":"v6.1.0","sha":"250b89af0ae27b93aaacbb885e852636e2c78ce6","kind":"commit","published_at":"2023-12-20T14:00:32.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.1.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.1.0/manifests"},{"name":"v6.0.1","sha":"0c3c6f8474857497ad1d8ca3d2687a66589079d3","kind":"tag","published_at":"2023-12-06T08:20:55.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.0.1","html_url":"https://github.com/nodejs/undici/releases/tag/v6.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.0.1/manifests"},{"name":"v6.0.0","sha":"e218fc61eda46da8784e0cedcaa88cd7e84dee99","kind":"commit","published_at":"2023-12-05T08:46:41.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v6.0.0","html_url":"https://github.com/nodejs/undici/releases/tag/v6.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v6.0.0/manifests"},{"name":"v5.28.2","sha":"9a14e5f32a118fa93e769cc15ae8de9de552f2e4","kind":"commit","published_at":"2023-11-30T15:40:41.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.28.2","html_url":"https://github.com/nodejs/undici/releases/tag/v5.28.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.28.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.28.2/manifests"},{"name":"v5.28.1","sha":"286bb4463b05e01e809737214e8eb1c161b78240","kind":"commit","published_at":"2023-11-27T09:48:11.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.28.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.28.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.28.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.28.1/manifests"},{"name":"v5.28.0","sha":"66029d1b317c0cfe38543553055cc86c658d7635","kind":"commit","published_at":"2023-11-24T08:59:38.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.28.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.28.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.28.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.28.0/manifests"},{"name":"v5.27.2","sha":"1541173d7a728eaf88bcd87263cef2ea0d993e74","kind":"tag","published_at":"2023-11-03T20:35:33.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.27.2","html_url":"https://github.com/nodejs/undici/releases/tag/v5.27.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.27.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.27.2/manifests"},{"name":"v5.27.1","sha":"2aedba485b539335b7ade6977615f9f94173eab2","kind":"tag","published_at":"2023-11-03T16:53:37.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.27.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.27.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.27.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.27.1/manifests"},{"name":"v5.27.0","sha":"41c253d0c23fd1cf63b8033d8ab61c2cf13e8c6e","kind":"tag","published_at":"2023-10-26T11:47:25.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.27.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.27.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.27.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.27.0/manifests"},{"name":"v5.26.5","sha":"9197790ae0d015b40b75fd0c5cdb7420704b5272","kind":"commit","published_at":"2023-10-23T07:25:50.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.26.5","html_url":"https://github.com/nodejs/undici/releases/tag/v5.26.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.5/manifests"},{"name":"v5.26.4","sha":"dea70e27e4d14952eb7b96da021eb44d24d1159e","kind":"commit","published_at":"2023-10-19T08:45:52.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.26.4","html_url":"https://github.com/nodejs/undici/releases/tag/v5.26.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.4/manifests"},{"name":"v5.26.3","sha":"227b9bedf233f741b86dda4ae9d1c7ad69f5d75c","kind":"tag","published_at":"2023-10-11T19:12:15.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.26.3","html_url":"https://github.com/nodejs/undici/releases/tag/v5.26.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.3/manifests"},{"name":"v5.26.2","sha":"12a62187d45f332cf39dd405f7c52b759cf40cdd","kind":"commit","published_at":"2023-10-11T18:57:39.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.26.2","html_url":"https://github.com/nodejs/undici/releases/tag/v5.26.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.2/manifests"},{"name":"v5.26.1","sha":"c8c80b1115d668664d8cf3acec7535b0258c3079","kind":"tag","published_at":"2023-10-11T18:25:52.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.26.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.26.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.1/manifests"},{"name":"v5.26.0","sha":"4006aaf43ac8b30e16d6d3b89fa2e0df4b7eef33","kind":"commit","published_at":"2023-10-11T11:02:16.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.26.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.26.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.26.0/manifests"},{"name":"v5.23.4","sha":"5e654f351a9a813fed3e9feff4388b5c4fbda787","kind":"commit","published_at":"2023-10-03T17:23:45.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.23.4","html_url":"https://github.com/nodejs/undici/releases/tag/v5.23.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.23.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.23.4/manifests"},{"name":"v5.25.3","sha":"764915396f684168328544bb0778424c58e2d945","kind":"commit","published_at":"2023-10-01T14:52:28.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.25.3","html_url":"https://github.com/nodejs/undici/releases/tag/v5.25.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.25.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.25.3/manifests"},{"name":"v5.25.2","sha":"4013c4b8932e73728809e4106d5c9d9d40648031","kind":"commit","published_at":"2023-09-22T17:37:05.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.25.2","html_url":"https://github.com/nodejs/undici/releases/tag/v5.25.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.25.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.25.2/manifests"},{"name":"v5.25.1","sha":"c86279c9bcf62fe28d124b124b91eb364d478a25","kind":"commit","published_at":"2023-09-20T21:03:45.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.25.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.25.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.25.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.25.1/manifests"},{"name":"v5.25.0","sha":"985b3816708512bafefa1544def183cc6d1536be","kind":"commit","published_at":"2023-09-20T12:55:52.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.25.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.25.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.25.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.25.0/manifests"},{"name":"v5.24.0-test.2","sha":"9c3e7d7ef367ebde507a3111a4bef99d8571cd46","kind":"tag","published_at":"2023-09-19T17:18:16.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.24.0-test.2","html_url":"https://github.com/nodejs/undici/releases/tag/v5.24.0-test.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.24.0-test.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.24.0-test.2/manifests"},{"name":"v5.24.0","sha":"9fa8224c274d52f67cd82d4bb820e72627df1e9f","kind":"commit","published_at":"2023-09-08T14:09:23.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.24.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.24.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.24.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.24.0/manifests"},{"name":"v5.23.0","sha":"59abe3f50d9c41a7e32a068654905f0919c9be71","kind":"tag","published_at":"2023-08-03T08:32:22.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.23.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.23.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.23.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.23.0/manifests"},{"name":"v5.22.1","sha":"9d30456aa6f195b83ea4ba36ed0b51a951e6bd87","kind":"tag","published_at":"2023-05-11T07:49:03.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.22.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.22.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.22.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.22.1/manifests"},{"name":"v5.22.0","sha":"6870d5b4c58e976f99a16c0ec71051d4b7e2e628","kind":"tag","published_at":"2023-04-20T15:07:20.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.22.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.22.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.22.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.22.0/manifests"},{"name":"v5.21.2","sha":"b20405e54a7b69eca58cab70a43d8cdbab511468","kind":"tag","published_at":"2023-04-09T04:52:24.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.21.2","html_url":"https://github.com/nodejs/undici/releases/tag/v5.21.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.21.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.21.2/manifests"},{"name":"v5.21.1","sha":"2d9441733c231da8b70f31c39eb08a234a42e4bf","kind":"tag","published_at":"2023-04-08T16:16:23.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.21.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.21.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.21.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.21.1/manifests"},{"name":"v5.21.0","sha":"98b63b25aab030d4aa08be818adebead9ed77788","kind":"commit","published_at":"2023-03-13T11:22:06.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.21.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.21.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.21.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.21.0/manifests"},{"name":"v5.20.0","sha":"28b9dea3fdcc453e25b3d305d5f004d85330cff1","kind":"commit","published_at":"2023-02-18T08:59:19.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.20.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.20.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.20.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.20.0/manifests"},{"name":"v5.19.1","sha":"984d53bad97c98529424a7f3bef6be1d0e76d039","kind":"commit","published_at":"2023-02-13T11:26:57.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.19.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.19.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.19.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.19.1/manifests"},{"name":"v5.19.0","sha":"f5c89e5c87c7d702996b152c4ad86302b60c4181","kind":"commit","published_at":"2023-02-13T10:23:03.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.19.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.19.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.19.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.19.0/manifests"},{"name":"v5.18.0","sha":"9dceb21156f85de1e0757785dc1da4cbe6eb9853","kind":"tag","published_at":"2023-02-06T07:07:50.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.18.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.18.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.18.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.18.0/manifests"},{"name":"v5.17.1","sha":"ce6a53bcd3ba54b761a0f4bda350b8d0e4283d66","kind":"tag","published_at":"2023-02-04T11:48:04.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.17.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.17.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.17.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.17.1/manifests"},{"name":"v5.17.0","sha":"16b7a68be363c463cba00c85a9006ee938ec1d77","kind":"tag","published_at":"2023-02-04T11:11:39.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.17.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.17.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.17.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.17.0/manifests"},{"name":"v5.16.0","sha":"81b1521c21b5bbfcca06e8aacae4f7c47ac15e7a","kind":"tag","published_at":"2023-01-23T06:23:31.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.16.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.16.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.16.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.16.0/manifests"},{"name":"v5.15.2","sha":"9457c9719029945ef9ff36b71d58557443730942","kind":"tag","published_at":"2023-01-22T09:26:53.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.15.2","html_url":"https://github.com/nodejs/undici/releases/tag/v5.15.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.15.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.15.2/manifests"},{"name":"v5.15.1","sha":"9d5f23177408dc16d3d4cbb8cebf463081c54e16","kind":"tag","published_at":"2023-01-19T11:44:57.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.15.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.15.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.15.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.15.1/manifests"},{"name":"v5.15.0","sha":"8c90b01a0ed0470d0b635b6bce9d17990f811246","kind":"commit","published_at":"2023-01-11T12:15:09.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.15.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.15.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.15.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.15.0/manifests"},{"name":"v5.14.0","sha":"9f6c59299359e7c5166c753e8d691f9dfc05b714","kind":"tag","published_at":"2022-12-08T16:42:33.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.14.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.14.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.14.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.14.0/manifests"},{"name":"v5.13.0","sha":"b3447abca2464739c00dffda96a8513687985481","kind":"commit","published_at":"2022-11-25T11:03:43.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.13.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.13.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.13.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.13.0/manifests"},{"name":"v5.12.0","sha":"1a3707887c7366403a30a45e1d8335945d0f82c1","kind":"tag","published_at":"2022-10-27T09:57:30.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.12.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.12.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.12.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.12.0/manifests"},{"name":"v5.11.0","sha":"0964a83710467b994cc108d096e97f69dd54ac90","kind":"tag","published_at":"2022-10-03T15:42:22.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.11.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.11.0/manifests"},{"name":"v5.10.0","sha":"6a87bfb38b3f4a28be81d2cc44a80083a0e4f798","kind":"commit","published_at":"2022-08-23T21:14:35.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.10.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.10.0/manifests"},{"name":"v5.9.1","sha":"5890e16ddd2703151ce0be0a468e13d685b89f60","kind":"tag","published_at":"2022-08-17T15:11:35.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.9.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.9.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.9.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.9.1/manifests"},{"name":"v5.8.2","sha":"52d1ce56f7641d0c0d8359fc76537ebe15473e7e","kind":"commit","published_at":"2022-08-09T09:34:10.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.8.2","html_url":"https://github.com/nodejs/undici/releases/tag/v5.8.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.8.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.8.2/manifests"},{"name":"v5.8.1","sha":"e1e1638aedcb64ecdd199708a912a35677cbb530","kind":"tag","published_at":"2022-08-03T14:03:04.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.8.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.8.1/manifests"},{"name":"v5.8.0","sha":"26f60b7b6e612bb831133d7f85914963d1955011","kind":"commit","published_at":"2022-07-18T08:30:33.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.8.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.8.0/manifests"},{"name":"v5.7.0","sha":"c485884cd76287f9412904c9e49923591988a195","kind":"commit","published_at":"2022-07-11T14:27:27.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.7.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.7.0/manifests"},{"name":"v5.6.1","sha":"c1a0490f20760ce700b28ddcddd493758d3f54a1","kind":"tag","published_at":"2022-07-08T12:50:10.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.6.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.6.1/manifests"},{"name":"v5.6.0","sha":"e53242d08f31d08d557c76b0c6fbd36106850603","kind":"commit","published_at":"2022-07-01T07:36:41.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.6.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.6.0/manifests"},{"name":"v5.5.1","sha":"19563f76ad38a8b4b2b1bfc78957c384775686e3","kind":"commit","published_at":"2022-06-13T14:25:22.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.5.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.5.1/manifests"},{"name":"v5.5.0","sha":"2717d70b308e2216a3f8cf04bbbf8566f5254a6e","kind":"commit","published_at":"2022-06-13T10:27:40.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.5.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.5.0/manifests"},{"name":"v5.4.0","sha":"47119827b1a21bacc39426f8b14e3afed07bce8e","kind":"commit","published_at":"2022-05-31T09:01:15.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.4.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.4.0/manifests"},{"name":"v5.3.0","sha":"4684a1543d87e98b441959d731a3a13d20eaa17d","kind":"commit","published_at":"2022-05-24T13:49:38.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.3.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.3.0/manifests"},{"name":"v5.2.0","sha":"15c16313a34ece99d63a92a8556af9110caf4564","kind":"commit","published_at":"2022-05-11T14:42:27.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.2.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.2.0/manifests"},{"name":"v5.1.1","sha":"c458589ceb0010c9d341d0460ca3e5cff460a44f","kind":"tag","published_at":"2022-05-02T07:04:11.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.1.1","html_url":"https://github.com/nodejs/undici/releases/tag/v5.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.1.1/manifests"},{"name":"v5.1.0","sha":"088518a9d2720c47d94c08c77686e89af787cf3a","kind":"commit","published_at":"2022-05-01T15:18:28.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.1.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.1.0/manifests"},{"name":"v5.0.0","sha":"08839e450aa6dd1b0e2c019d6e5869cd5b966be1","kind":"commit","published_at":"2022-03-29T10:58:01.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v5.0.0","html_url":"https://github.com/nodejs/undici/releases/tag/v5.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v5.0.0/manifests"},{"name":"v4.16.0","sha":"724775aff71333267a6b363940299cdf478788dc","kind":"commit","published_at":"2022-03-18T15:00:58.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.16.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.16.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.16.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.16.0/manifests"},{"name":"v4.15.1","sha":"cedc7d26f64aaa0571d1af6eaf82c519a1bcc6da","kind":"commit","published_at":"2022-03-07T14:11:35.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.15.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.15.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.15.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.15.1/manifests"},{"name":"v4.15.0","sha":"8b10a4b8769bca6a1c77275ca2a6037377f6e6c9","kind":"commit","published_at":"2022-03-04T15:26:35.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.15.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.15.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.15.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.15.0/manifests"},{"name":"v4.14.1","sha":"db745e43dd19556f82a01f7c019032d282ffa7ef","kind":"tag","published_at":"2022-02-11T16:09:14.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.14.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.14.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.14.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.14.1/manifests"},{"name":"v4.14.0","sha":"ce929b7a6d34b253f7d894271d3c7e94bf89c230","kind":"tag","published_at":"2022-02-11T13:07:41.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.14.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.14.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.14.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.14.0/manifests"},{"name":"v4.13.0","sha":"c85bb047c6ef3613d9213ac7f2ac2eefe17a1a44","kind":"commit","published_at":"2022-01-30T11:12:59.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.13.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.13.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.13.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.13.0/manifests"},{"name":"v4.12.2","sha":"badfe773ff3bcc8f26996f43e40421c26221c145","kind":"tag","published_at":"2022-01-13T14:24:14.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.12.2","html_url":"https://github.com/nodejs/undici/releases/tag/v4.12.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.12.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.12.2/manifests"},{"name":"v4.12.1","sha":"44bd5b53c48c7f9f71ded47f297229c4b5d814cc","kind":"tag","published_at":"2021-12-22T10:44:06.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.12.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.12.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.12.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.12.1/manifests"},{"name":"v4.12.0","sha":"6871a115b20478ecb18e3554a779db2904e6a105","kind":"tag","published_at":"2021-12-14T07:46:42.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.12.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.12.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.12.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.12.0/manifests"},{"name":"v4.11.3","sha":"d1bd73088785b3c118a73163c99b65059ce4458a","kind":"tag","published_at":"2021-12-08T19:29:52.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.11.3","html_url":"https://github.com/nodejs/undici/releases/tag/v4.11.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.11.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.11.3/manifests"},{"name":"v4.11.2","sha":"8c744731685149b939e6b3d7c4c21202ba0992f9","kind":"tag","published_at":"2021-12-08T16:04:02.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.11.2","html_url":"https://github.com/nodejs/undici/releases/tag/v4.11.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.11.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.11.2/manifests"},{"name":"v4.11.1","sha":"ebea0f7084bb1efdb66c46409d1bfc87054b2870","kind":"tag","published_at":"2021-12-07T13:50:22.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.11.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.11.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.11.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.11.1/manifests"},{"name":"v4.11.0","sha":"d0ea33dd302c6a189f9c12c33e9bfcfdf52d498f","kind":"tag","published_at":"2021-12-03T08:35:15.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.11.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.11.0/manifests"},{"name":"v4.10.4","sha":"ae0420219d399722649e1ec6e4612b070835781a","kind":"tag","published_at":"2021-12-01T20:13:35.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.10.4","html_url":"https://github.com/nodejs/undici/releases/tag/v4.10.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.10.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.10.4/manifests"},{"name":"v4.10.3","sha":"039354bb408f358b749875ed659e60634edd7d7a","kind":"tag","published_at":"2021-11-24T09:38:24.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.10.3","html_url":"https://github.com/nodejs/undici/releases/tag/v4.10.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.10.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.10.3/manifests"},{"name":"v4.10.2","sha":"3f6b564b7d3023d506cad75b16207006b23956a8","kind":"tag","published_at":"2021-11-19T17:46:08.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.10.2","html_url":"https://github.com/nodejs/undici/releases/tag/v4.10.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.10.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.10.2/manifests"},{"name":"v4.10.1","sha":"463f529f8b3a031041ad721d1a56255b2dc47065","kind":"tag","published_at":"2021-11-19T09:32:30.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.10.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.10.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.10.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.10.1/manifests"},{"name":"v4.10.0","sha":"e659683899999ea16dfce295bab105790255e18e","kind":"tag","published_at":"2021-11-14T15:45:46.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.10.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.10.0/manifests"},{"name":"v4.9.5","sha":"eb54d18a783323e124e8a4121218384dae43d26e","kind":"commit","published_at":"2021-11-03T18:54:09.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.9.5","html_url":"https://github.com/nodejs/undici/releases/tag/v4.9.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.5/manifests"},{"name":"v4.9.4","sha":"e3f6d1d0fe2c642fe531fce45817d2fab86bfbcc","kind":"tag","published_at":"2021-11-03T17:53:44.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.9.4","html_url":"https://github.com/nodejs/undici/releases/tag/v4.9.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.4/manifests"},{"name":"v4.9.3","sha":"40dbf0367d46ccce1b3aab55dd93f10b1dd8e66f","kind":"tag","published_at":"2021-11-01T04:58:30.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.9.3","html_url":"https://github.com/nodejs/undici/releases/tag/v4.9.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.3/manifests"},{"name":"v4.9.2","sha":"904e0457d3a07731d8c74ca9e7ece29233e949bf","kind":"tag","published_at":"2021-10-29T10:06:39.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.9.2","html_url":"https://github.com/nodejs/undici/releases/tag/v4.9.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.2/manifests"},{"name":"v4.9.1","sha":"729dd6704560ac6f3544751fed22ad34d75aef8c","kind":"tag","published_at":"2021-10-28T07:40:28.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.9.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.9.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.1/manifests"},{"name":"v4.9.0","sha":"597976f48c1fa9c4d4a739593ec45ac6f291ad3f","kind":"tag","published_at":"2021-10-28T07:40:13.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.9.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.9.0/manifests"},{"name":"v4.8.2","sha":"7b03c91cefbb46cd9172db4b2758b34155b4f764","kind":"tag","published_at":"2021-10-27T10:22:50.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.8.2","html_url":"https://github.com/nodejs/undici/releases/tag/v4.8.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.8.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.8.2/manifests"},{"name":"v4.8.1","sha":"1e2321ab494cce6a7125964153a3a83001fd77c3","kind":"commit","published_at":"2021-10-20T08:39:51.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.8.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.8.1/manifests"},{"name":"v4.8.0","sha":"a821ba768ae105dc529e5e4578b0b9b09f729eb4","kind":"commit","published_at":"2021-10-18T09:56:41.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.8.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.8.0/manifests"},{"name":"v4.7.3","sha":"e402e2e5a185049a1a072065b3ca607157a97ba0","kind":"commit","published_at":"2021-10-15T12:29:19.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.7.3","html_url":"https://github.com/nodejs/undici/releases/tag/v4.7.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.7.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.7.3/manifests"},{"name":"v4.7.2","sha":"68a17943f4d6af5f27d36ab10471f5e8860a1ede","kind":"tag","published_at":"2021-10-13T12:16:43.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.7.2","html_url":"https://github.com/nodejs/undici/releases/tag/v4.7.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.7.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.7.2/manifests"},{"name":"v4.7.1","sha":"eeeb3853f843177658e3f47dd85e694fedd19e07","kind":"tag","published_at":"2021-10-07T11:44:22.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.7.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.7.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.7.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.7.1/manifests"},{"name":"v4.7.0","sha":"42cf1417e3931591a6064fcbbe5343a43c6b2cb5","kind":"commit","published_at":"2021-09-22T09:24:52.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.7.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.7.0/manifests"},{"name":"v4.6.0","sha":"1e1a6db94e95c1c79e953e8c64c6c8f389bf323a","kind":"tag","published_at":"2021-09-15T10:22:06.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.6.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.6.0/manifests"},{"name":"v4.5.1","sha":"3100a612fc7ae758b1dbd5f8dd92e64e4667336c","kind":"tag","published_at":"2021-08-28T14:38:43.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.5.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.5.1/manifests"},{"name":"v4.5.0","sha":"88403c00140c517c8cfd3590993c02b191fe844f","kind":"tag","published_at":"2021-08-26T08:45:40.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.5.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.5.0/manifests"},{"name":"v4.4.7","sha":"f2b0b672c49fb1855e9d787a4136caba8e11c934","kind":"tag","published_at":"2021-08-24T06:54:59.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.4.7","html_url":"https://github.com/nodejs/undici/releases/tag/v4.4.7","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.7/manifests"},{"name":"v4.4.6","sha":"c4678169ba7f5eedab58ae1c3bda70267f943f79","kind":"tag","published_at":"2021-08-20T14:02:21.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.4.6","html_url":"https://github.com/nodejs/undici/releases/tag/v4.4.6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.6/manifests"},{"name":"v4.4.5","sha":"6be77d614bbf8a2fa7a9d17ad2e86438157accb3","kind":"tag","published_at":"2021-08-19T13:16:20.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.4.5","html_url":"https://github.com/nodejs/undici/releases/tag/v4.4.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.5/manifests"},{"name":"v4.4.4","sha":"d0becbce9e4e3790e1a717a1367c4816f0335fe8","kind":"tag","published_at":"2021-08-17T13:40:58.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.4.4","html_url":"https://github.com/nodejs/undici/releases/tag/v4.4.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.4/manifests"},{"name":"v4.4.3","sha":"f00d444fb979949fc05316d112d6e92ef6b2aaa0","kind":"tag","published_at":"2021-08-17T11:53:42.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.4.3","html_url":"https://github.com/nodejs/undici/releases/tag/v4.4.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.3/manifests"},{"name":"v4.4.2","sha":"137da0e45a13b9109ab640937f9084e67e96f080","kind":"tag","published_at":"2021-08-13T17:13:03.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.4.2","html_url":"https://github.com/nodejs/undici/releases/tag/v4.4.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.2/manifests"},{"name":"v4.4.1","sha":"913f79c7b816afd6466dbe1927ea909f52ccfac3","kind":"tag","published_at":"2021-08-12T11:54:35.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.4.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.1/manifests"},{"name":"v4.4.0","sha":"bac066d80d96890a608b719c8823a8035aeab440","kind":"tag","published_at":"2021-08-12T11:48:38.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.4.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.4.0/manifests"},{"name":"v4.3.1","sha":"64fa1b89a3d54d9c7ea0dab2f7fb38ddcea61ee6","kind":"tag","published_at":"2021-07-31T16:24:15.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.3.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.3.1/manifests"},{"name":"v4.3.0","sha":"9f96dc6f8be6179314f4dae8c90b5b25a85b3165","kind":"commit","published_at":"2021-07-31T16:23:16.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.3.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.3.0/manifests"},{"name":"v4.2.2","sha":"02a9d13a902859f537b980fbc0ccd6a2b088d5f1","kind":"tag","published_at":"2021-07-22T18:09:32.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.2.2","html_url":"https://github.com/nodejs/undici/releases/tag/v4.2.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.2.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.2.2/manifests"},{"name":"v4.2.1","sha":"aebbb5df86d5584b03102cb9198aad8abae421f1","kind":"tag","published_at":"2021-07-19T13:15:13.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.2.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.2.1/manifests"},{"name":"v4.2.0","sha":"c7be4eabcc9274ed7ed375fa0de520db2cb2c1d5","kind":"tag","published_at":"2021-07-19T13:12:00.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.2.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.2.0/manifests"},{"name":"v4.1.1","sha":"494201af4d95a1d9dbf8727bf4847b858e9f4707","kind":"tag","published_at":"2021-07-12T07:51:45.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.1.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.1.1/manifests"},{"name":"v4.1.0","sha":"e705509ab22ab80aadf0fc1a394afff7dc014fdf","kind":"tag","published_at":"2021-06-29T17:58:29.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.1.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.1.0/manifests"},{"name":"v4.0.0","sha":"06ccb4f78b070e7471b97cac4c6a9e05a0825dbd","kind":"tag","published_at":"2021-06-16T08:26:41.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0/manifests"},{"name":"v4.0.0-rc.8","sha":"1a68acc427d0638e361cad71b6113ccbbea37cab","kind":"tag","published_at":"2021-06-16T07:14:57.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-rc.8","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-rc.8","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.8/manifests"},{"name":"v4.0.0-rc.7","sha":"abfc22b016b7214b03d0d8d6c37064f5cfa6a4b3","kind":"tag","published_at":"2021-06-08T07:49:53.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-rc.7","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-rc.7","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.7/manifests"},{"name":"v4.0.0-rc.6","sha":"8239409499c3a3727eda8c92719d7e4663ff0da1","kind":"tag","published_at":"2021-06-08T07:46:47.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-rc.6","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-rc.6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.6/manifests"},{"name":"v4.0.0-rc.5","sha":"622c41b1996ac9101868d55bfc2b99703ed02d92","kind":"tag","published_at":"2021-05-31T11:16:46.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-rc.5","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-rc.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.5/manifests"},{"name":"v4.0.0-rc.4","sha":"7d563c0297e23a1275fa263e47aa0d3ac6fbb23e","kind":"tag","published_at":"2021-05-12T07:21:02.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-rc.4","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-rc.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.4/manifests"},{"name":"v4.0.0-rc.3","sha":"677d6f9a5eb64ec0e3c346ebdf98b8b79d2b4913","kind":"tag","published_at":"2021-05-05T09:03:12.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-rc.3","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-rc.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.3/manifests"},{"name":"v4.0.0-rc.2","sha":"9b05bc127d9beeab05f8a888384208a8c5c598ee","kind":"commit","published_at":"2021-05-03T14:39:18.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-rc.2","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-rc.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.2/manifests"},{"name":"v4.0.0-rc.1","sha":"31e983bf14f97db21d24f3d1a12b84a765c93bda","kind":"tag","published_at":"2021-04-28T16:29:16.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-rc.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-rc.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-rc.1/manifests"},{"name":"v4.0.0-alpha.5","sha":"7bafbd2442df1dd4140c110b202d55ec1c8e2678","kind":"tag","published_at":"2021-04-27T16:41:12.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-alpha.5","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-alpha.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.5/manifests"},{"name":"v3.3.6","sha":"f744aed29a36f68d295207f5cb509c979029e588","kind":"commit","published_at":"2021-04-24T14:43:06.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v3.3.6","html_url":"https://github.com/nodejs/undici/releases/tag/v3.3.6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.6/manifests"},{"name":"v3.3.5","sha":"decdfc460b8317e34ffe2499e2ee81731eeb47c8","kind":"commit","published_at":"2021-04-21T08:18:24.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v3.3.5","html_url":"https://github.com/nodejs/undici/releases/tag/v3.3.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.5/manifests"},{"name":"v4.0.0-alpha.4","sha":"5d959626a467800729957a4957d9c918e01e2ed8","kind":"tag","published_at":"2021-04-16T16:22:11.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-alpha.4","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-alpha.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.4/manifests"},{"name":"v4.0.0-alpha.3","sha":"f354d36525f0b610b2f15f3ff15976c5f8ea24d2","kind":"tag","published_at":"2021-04-13T10:20:22.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-alpha.3","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-alpha.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.3/manifests"},{"name":"v4.0.0-alpha.2","sha":"18fefd58e98a829bf1122bb1c049018bedd930a9","kind":"tag","published_at":"2021-04-12T15:18:36.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-alpha.2","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-alpha.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.2/manifests"},{"name":"v4.0.0-alpha.1","sha":"a1727e0f939995e0adcbbde7cb5b6b024f59c6ea","kind":"tag","published_at":"2021-04-12T13:22:22.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-alpha.1","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-alpha.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.1/manifests"},{"name":"v4.0.0-alpha.0","sha":"022784138b4baf5e663ff92192e270dadc273f55","kind":"tag","published_at":"2021-04-11T19:35:14.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v4.0.0-alpha.0","html_url":"https://github.com/nodejs/undici/releases/tag/v4.0.0-alpha.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v4.0.0-alpha.0/manifests"},{"name":"v3.3.4","sha":"39eba7190985e0ee41124bb4a60ee8fd12710cb3","kind":"tag","published_at":"2021-04-08T12:09:41.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v3.3.4","html_url":"https://github.com/nodejs/undici/releases/tag/v3.3.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.4/manifests"},{"name":"v3.3.3","sha":"c99db2d68cb6706210012868db74e02e549a3d37","kind":"tag","published_at":"2021-02-13T16:03:01.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v3.3.3","html_url":"https://github.com/nodejs/undici/releases/tag/v3.3.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.3/manifests"},{"name":"v3.3.2","sha":"d523180d38fe95448ec9306e1ea9c79c6bbaf6e2","kind":"tag","published_at":"2021-02-13T15:58:35.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v3.3.2","html_url":"https://github.com/nodejs/undici/releases/tag/v3.3.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.2/manifests"},{"name":"v3.3.1","sha":"6680bd01ecda317d936d5a04b0581c30faaf90d2","kind":"tag","published_at":"2021-02-08T07:56:25.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v3.3.1","html_url":"https://github.com/nodejs/undici/releases/tag/v3.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.1/manifests"},{"name":"v3.3.0","sha":"6223377672415946ca11a7f559d02faf12284393","kind":"tag","published_at":"2021-02-03T09:33:50.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v3.3.0","html_url":"https://github.com/nodejs/undici/releases/tag/v3.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.3.0/manifests"},{"name":"v3.2.0","sha":"de381e13e79a059c4f79952adea35bfda9333f0f","kind":"tag","published_at":"2021-01-13T12:40:13.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v3.2.0","html_url":"https://github.com/nodejs/undici/releases/tag/v3.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.2.0/manifests"},{"name":"v3.1.0","sha":"b1a4a433b76aef3e9bd12099cf1e88c3df32891e","kind":"commit","published_at":"2021-01-12T09:51:32.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v3.1.0","html_url":"https://github.com/nodejs/undici/releases/tag/v3.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.1.0/manifests"},{"name":"v3.0.0","sha":"0e289aa8d4b68544f936a92594eb3d5dae750171","kind":"tag","published_at":"2020-12-17T22:39:20.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v3.0.0","html_url":"https://github.com/nodejs/undici/releases/tag/v3.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v3.0.0/manifests"},{"name":"v2.2.1","sha":"b253a3af007bc9d53ced69f81534154812804228","kind":"tag","published_at":"2020-12-08T06:22:44.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.2.1","html_url":"https://github.com/nodejs/undici/releases/tag/v2.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.2.1/manifests"},{"name":"v2.2.0","sha":"2e214a29e5625c206454c2bdae81ff7b30cedd7d","kind":"tag","published_at":"2020-11-12T11:58:56.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.2.0","html_url":"https://github.com/nodejs/undici/releases/tag/v2.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.2.0/manifests"},{"name":"v2.1.1","sha":"6b44f36d225b545ad327e0631c179cda8f4fa27f","kind":"tag","published_at":"2020-11-02T19:40:05.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.1.1","html_url":"https://github.com/nodejs/undici/releases/tag/v2.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.1.1/manifests"},{"name":"v2.1.0","sha":"472dbde2394efb964b3b866120fe59e242cfc677","kind":"commit","published_at":"2020-10-23T23:50:00.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.1.0","html_url":"https://github.com/nodejs/undici/releases/tag/v2.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.1.0/manifests"},{"name":"v2.0.7","sha":"e94a35581c14364f7d3e9f355eb21895287365bc","kind":"tag","published_at":"2020-10-09T08:49:40.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.0.7","html_url":"https://github.com/nodejs/undici/releases/tag/v2.0.7","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.7/manifests"},{"name":"v2.0.6","sha":"9e73b20177752b1281f93f30030c7425f2f46945","kind":"tag","published_at":"2020-10-07T19:55:14.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.0.6","html_url":"https://github.com/nodejs/undici/releases/tag/v2.0.6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.6/manifests"},{"name":"v2.0.5","sha":"f9f038750629a1f29d2500f6f90a064ceec3ef67","kind":"tag","published_at":"2020-09-24T21:28:26.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.0.5","html_url":"https://github.com/nodejs/undici/releases/tag/v2.0.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.5/manifests"},{"name":"v2.0.4","sha":"f87fa3251808d0f5ce8cd2c6f65444cfbd3425a5","kind":"tag","published_at":"2020-09-23T21:41:57.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.0.4","html_url":"https://github.com/nodejs/undici/releases/tag/v2.0.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.4/manifests"},{"name":"v2.0.3","sha":"4f68bf8678c2381612bbf2f6f41a93d62314274d","kind":"tag","published_at":"2020-09-23T21:37:51.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.0.3","html_url":"https://github.com/nodejs/undici/releases/tag/v2.0.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.3/manifests"},{"name":"v2.0.2","sha":"3ce6832f60951c0b69e1f0624f07e16144bcfcb9","kind":"tag","published_at":"2020-09-18T23:49:47.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.0.2","html_url":"https://github.com/nodejs/undici/releases/tag/v2.0.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.2/manifests"},{"name":"v2.0.1","sha":"71e482f233de06427e435411ea0e18ebf4dd3e5b","kind":"tag","published_at":"2020-09-12T11:28:06.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.0.1","html_url":"https://github.com/nodejs/undici/releases/tag/v2.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.1/manifests"},{"name":"v2.0.0","sha":"6e91fbf0a1475d2385abcf20b58e1d21f527c0a3","kind":"tag","published_at":"2020-09-05T15:27:07.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v2.0.0","html_url":"https://github.com/nodejs/undici/releases/tag/v2.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v2.0.0/manifests"},{"name":"v1.3.1","sha":"45ec01b23aaa74a653493d8e27d43fc8d9542bc8","kind":"tag","published_at":"2020-08-12T16:27:40.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.3.1","html_url":"https://github.com/nodejs/undici/releases/tag/v1.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.3.1/manifests"},{"name":"v1.3.0","sha":"c707c35a96adf1ec027d6cc8752eb5a5634a4374","kind":"tag","published_at":"2020-08-10T12:23:52.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.3.0","html_url":"https://github.com/nodejs/undici/releases/tag/v1.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.3.0/manifests"},{"name":"v1.2.6","sha":"d8dc40f77400f998817efb4654bc411d0779384c","kind":"commit","published_at":"2020-07-29T18:50:12.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.2.6","html_url":"https://github.com/nodejs/undici/releases/tag/v1.2.6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.6/manifests"},{"name":"v1.2.5","sha":"966f3e172a4b8390281782a64de1f69ad94e4b6e","kind":"tag","published_at":"2020-07-29T09:37:41.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.2.5","html_url":"https://github.com/nodejs/undici/releases/tag/v1.2.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.5/manifests"},{"name":"v1.2.4","sha":"ea1c9e92ec4efd1ffdd8cfff069e1f7101b5ba97","kind":"tag","published_at":"2020-07-29T08:50:59.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.2.4","html_url":"https://github.com/nodejs/undici/releases/tag/v1.2.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.4/manifests"},{"name":"v1.2.2","sha":"7e785f8b4d8c157dcc9b250e564ddae23607a2d3","kind":"tag","published_at":"2020-07-16T17:40:52.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.2.2","html_url":"https://github.com/nodejs/undici/releases/tag/v1.2.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.2/manifests"},{"name":"v1.2.1","sha":"d782e63495d8fe5bb4f3b49a1a0650b103c43df9","kind":"tag","published_at":"2020-07-14T13:28:43.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.2.1","html_url":"https://github.com/nodejs/undici/releases/tag/v1.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.1/manifests"},{"name":"v1.2.0","sha":"b7a350589ebb84e1a1e5d95210fa56c94864a52f","kind":"tag","published_at":"2020-07-14T12:30:00.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.2.0","html_url":"https://github.com/nodejs/undici/releases/tag/v1.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.2.0/manifests"},{"name":"v1.1.0","sha":"75de95ab227e0fc96c36b91e3112c7960d5c292e","kind":"tag","published_at":"2020-07-06T07:08:12.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.1.0","html_url":"https://github.com/nodejs/undici/releases/tag/v1.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.1.0/manifests"},{"name":"elete","sha":"cf8652fd3ba29f8d89b22f630b016a596ae13eca","kind":"tag","published_at":"2020-07-05T16:54:25.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/elete","html_url":"https://github.com/nodejs/undici/releases/tag/elete","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/elete","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/elete/manifests"},{"name":"delete","sha":"cf8652fd3ba29f8d89b22f630b016a596ae13eca","kind":"tag","published_at":"2020-07-05T16:54:25.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/delete","html_url":"https://github.com/nodejs/undici/releases/tag/delete","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/delete","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/delete/manifests"},{"name":"v1.0.3","sha":"df7bade8b8e06ef13936520d5126cbf93889a356","kind":"tag","published_at":"2020-06-15T12:51:08.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.0.3","html_url":"https://github.com/nodejs/undici/releases/tag/v1.0.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.0.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.0.3/manifests"},{"name":"v1.0.2","sha":"625881f4227b32d10a6d206e466f929b001923a0","kind":"tag","published_at":"2020-06-13T17:10:57.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.0.2","html_url":"https://github.com/nodejs/undici/releases/tag/v1.0.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.0.2/manifests"},{"name":"v1.0.1","sha":"55dc0aed7e90f1b9b97f42ad417fdf46ee1d99db","kind":"tag","published_at":"2020-06-06T20:40:48.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.0.1","html_url":"https://github.com/nodejs/undici/releases/tag/v1.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.0.1/manifests"},{"name":"v1.0.0","sha":"359dea825c73cf21d6ae16bb2075842b9f48bcd3","kind":"tag","published_at":"2020-06-04T16:23:34.000Z","download_url":"https://codeload.github.com/nodejs/undici/tar.gz/v1.0.0","html_url":"https://github.com/nodejs/undici/releases/tag/v1.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nodejs%2Fundici/tags/v1.0.0/manifests"}]},"repo_metadata_updated_at":"2024-10-29T19:51:19.853Z","dependent_packages_count":1956,"downloads":76040467,"downloads_period":"last-month","dependent_repos_count":98048,"rankings":{"downloads":0.04717544226634877,"dependent_repos_count":0.1008125237520001,"dependent_packages_count":0.0399197880582336,"stargazers_count":1.2981597470542043,"forks_count":1.7358262848531512,"docker_downloads_count":0.04588859038792834,"average":0.5446303960619777},"purl":"pkg:npm/undici","advisories":[{"uuid":"GSA_kwCzR0hTQS0zNzg3LTZwcnYtaDl3M84AA5Vg","url":"https://github.com/advisories/GHSA-3787-6prv-h9w3","title":"Undici proxy-authorization header not cleared on cross-origin redirect in fetch","description":"### Impact\n\nUndici already cleared Authorization headers on cross-origin redirects, but did not clear `Proxy-Authorization` headers. \n\n### Patches\n\nThis is patched in v5.28.3 and v6.6.1\n\n### Workarounds\n\nThere are no known workarounds.\n\n### References\n\n- https://fetch.spec.whatwg.org/#authentication-entries\n- https://github.com/nodejs/undici/security/advisories/GHSA-wqq4-5wpv-mx2g","origin":"UNSPECIFIED","severity":"LOW","published_at":"2024-02-16T16:02:52.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-3787-6prv-h9w3","https://github.com/nodejs/undici/commit/b9da3e40f1f096a06b4caedbb27c2568730434ef","https://github.com/nodejs/undici/commit/d3aa574b1259c1d8d329a0f0f495ee82882b1458","https://github.com/nodejs/undici/releases/tag/v5.28.3","https://github.com/nodejs/undici/releases/tag/v6.6.1","https://nvd.nist.gov/vuln/detail/CVE-2024-24758","https://security.netapp.com/advisory/ntap-20240419-0007","http://www.openwall.com/lists/oss-security/2024/03/11/1","https://github.com/advisories/GHSA-3787-6prv-h9w3"],"source_kind":"github","identifiers":["GHSA-3787-6prv-h9w3","CVE-2024-24758"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"6.6.1","vulnerable_version_range":"\u003e= 6.0.0, \u003c= 6.6.0"},{"first_patched_version":"5.28.3","vulnerable_version_range":"\u003c= 5.28.2"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2024-02-16T17:04:40.355Z","updated_at":"2025-06-02T01:09:42.713Z","epss_percentage":0.00042,"epss_percentile":0.12319},{"uuid":"GSA_kwCzR0hTQS01cjlnLXFoNm0tanhmZs4AAxq9","url":"https://github.com/advisories/GHSA-5r9g-qh6m-jxff","title":"CRLF Injection in Nodejs ‘undici’ via host","description":"### Impact\n\nundici library does not protect `host` HTTP header from CRLF injection vulnerabilities.\n\n### Patches\n\nThis issue was patched in Undici v5.19.1.\n\n### Workarounds\n\nSanitize the `headers.host` string before passing to undici.\n\n### References\n\nReported at https://hackerone.com/reports/1820955.\n\n### Credits\n\nThank you to Zhipeng Zhang ([@timon8](https://hackerone.com/timon8)) for reporting this vulnerability. ","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2023-02-16T20:46:30.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-5r9g-qh6m-jxff","https://nvd.nist.gov/vuln/detail/CVE-2023-23936","https://github.com/nodejs/undici/commit/a2eff05401358f6595138df963837c24348f2034","https://hackerone.com/reports/1820955","https://github.com/nodejs/undici/releases/tag/v5.19.1","https://github.com/advisories/GHSA-5r9g-qh6m-jxff"],"source_kind":"github","identifiers":["GHSA-5r9g-qh6m-jxff","CVE-2023-23936"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"5.19.1","vulnerable_version_range":"\u003e= 2.0.0, \u003c 5.19.1"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2023-02-16T21:03:05.031Z","updated_at":"2025-06-02T01:11:39.851Z","epss_percentage":0.0041,"epss_percentile":0.60516},{"uuid":"GSA_kwCzR0hTQS1yNmNoLW1xZjktcWM5d84AAxq-","url":"https://github.com/advisories/GHSA-r6ch-mqf9-qc9w","title":"Regular Expression Denial of Service in Headers","description":"### Impact\nThe `Headers.set()` and `Headers.append()` methods are vulnerable to Regular Expression Denial of Service (ReDoS) attacks when untrusted values are passed into the functions. This is due to the inefficient regular expression used to normalize the values in the `headerValueNormalize()` utility function.\n\n### Patches\n\nThis vulnerability was patched in v5.19.1.\n\n### Workarounds\nThere is no workaround. Please update to an unaffected version.\n\n### References\n\n* https://hackerone.com/bugs?report_id=1784449\n\n### Credits\n\nCarter Snook reported this vulnerability.\n","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2023-02-16T20:46:10.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-r6ch-mqf9-qc9w","https://nvd.nist.gov/vuln/detail/CVE-2023-24807","https://github.com/nodejs/undici/commit/f2324e549943f0b0937b09fb1c0c16cc7c93abdf","https://github.com/nodejs/undici/releases/tag/v5.19.1","https://hackerone.com/bugs?report_id=1784449","https://github.com/advisories/GHSA-r6ch-mqf9-qc9w"],"source_kind":"github","identifiers":["GHSA-r6ch-mqf9-qc9w","CVE-2023-24807"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"5.19.1","vulnerable_version_range":"\u003c 5.19.1"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2023-02-16T21:03:05.020Z","updated_at":"2023-02-16T20:46:56.000Z","epss_percentage":0.00248,"epss_percentile":0.48017},{"uuid":"GSA_kwCzR0hTQS1xNzY4LXg5bTYtbTlxcM4AAtkI","url":"https://github.com/advisories/GHSA-q768-x9m6-m9qp","title":"undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect","description":"### Impact\n\nAuthorization headers are already cleared on cross-origin redirect in\nhttps://github.com/nodejs/undici/blob/main/lib/handler/redirect.js#L189, based on https://github.com/nodejs/undici/issues/872.\n\nHowever, cookie headers which are sensitive headers and are official headers found in the spec, remain uncleared. There also has been active discussion of implementing a cookie store https://github.com/nodejs/undici/pull/1441, which suggests that there are active users using cookie headers in undici.\nAs such this may lead to accidental leakage of cookie to a 3rd-party site or a malicious attacker who can control the redirection target (ie. an open redirector) to leak the cookie to the 3rd party site.\n\n### Patches\n\nThis was patched in v5.8.0.\n\n### Workarounds\n\nBy default, this vulnerability is not exploitable.\nDo not enable redirections, i.e. `maxRedirections: 0` (the default). \n\n### References\n\nhttps://hackerone.com/reports/1635514\nhttps://curl.se/docs/CVE-2018-1000007.html\nhttps://curl.se/docs/CVE-2022-27776.html\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [undici repository](https://github.com/nodejs/undici/issues)\n* To make a report, follow the [SECURITY](https://github.com/nodejs/node/blob/HEAD/SECURITY.md) document\n","origin":"UNSPECIFIED","severity":"LOW","published_at":"2022-07-21T20:31:05.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-q768-x9m6-m9qp","https://nvd.nist.gov/vuln/detail/CVE-2022-31151","https://github.com/nodejs/undici/issues/872","https://github.com/nodejs/undici/pull/1441","https://github.com/nodejs/undici/commit/0a5bee9465e627be36bac88edf7d9bbc9626126d","https://github.com/nodejs/undici/blob/main/lib/handler/redirect.js#L189","https://github.com/nodejs/undici/releases/tag/v5.8.0","https://hackerone.com/reports/1635514","https://security.netapp.com/advisory/ntap-20220909-0006/","https://github.com/advisories/GHSA-q768-x9m6-m9qp"],"source_kind":"github","identifiers":["GHSA-q768-x9m6-m9qp","CVE-2022-31151"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"5.8.0","vulnerable_version_range":"\u003c 5.8.0"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2022-12-21T16:12:10.113Z","updated_at":"2025-06-02T01:12:09.616Z","epss_percentage":0.00122,"epss_percentile":0.32534},{"uuid":"GSA_kwCzR0hTQS1jNzZoLTJjY3AtNDk3Nc4ABDo4","url":"https://github.com/advisories/GHSA-c76h-2ccp-4975","title":"Use of Insufficiently Random Values in undici","description":"### Impact\n\n[Undici `fetch()` uses Math.random()](https://github.com/nodejs/undici/blob/8b06b8250907d92fead664b3368f1d2aa27c1f35/lib/web/fetch/body.js#L113) to choose the boundary for a multipart/form-data request. It is known that the output of Math.random() can be predicted if several of its generated values are known.\n\nIf there is a mechanism in an app that sends multipart requests to an attacker-controlled website, they can use this to leak the necessary values. Therefore, An attacker can tamper with the requests going to the backend APIs if certain conditions are met.\n\n### Patches\n\nThis is fixed in 5.28.5; 6.21.1; 7.2.3.\n\n### Workarounds\n\nDo not issue multipart requests to attacker controlled servers.\n\n### References\n\n* https://hackerone.com/reports/2913312\n* https://blog.securityevaluators.com/hacking-the-javascript-lottery-80cc437e3b7f\n","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-01-21T21:10:47.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-c76h-2ccp-4975","https://nvd.nist.gov/vuln/detail/CVE-2025-22150","https://github.com/nodejs/undici/commit/711e20772764c29f6622ddc937c63b6eefdf07d0","https://github.com/nodejs/undici/commit/c2d78cd19fe4f4c621424491e26ce299e65e934a","https://github.com/nodejs/undici/commit/c3acc6050b781b827d80c86cbbab34f14458d385","https://hackerone.com/reports/2913312","https://blog.securityevaluators.com/hacking-the-javascript-lottery-80cc437e3b7f","https://github.com/nodejs/undici/blob/8b06b8250907d92fead664b3368f1d2aa27c1f35/lib/web/fetch/body.js#L113","https://github.com/advisories/GHSA-c76h-2ccp-4975"],"source_kind":"github","identifiers":["GHSA-c76h-2ccp-4975","CVE-2025-22150"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"7.2.3","vulnerable_version_range":"\u003e= 7.0.0, \u003c 7.2.3"},{"first_patched_version":"6.21.1","vulnerable_version_range":"\u003e= 6.0.0, \u003c 6.21.1"},{"first_patched_version":"5.28.5","vulnerable_version_range":"\u003e= 4.5.0, \u003c 5.28.5"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2025-01-21T22:08:48.606Z","updated_at":"2025-06-02T01:08:19.587Z","epss_percentage":0.00037,"epss_percentile":0.10101},{"uuid":"GSA_kwCzR0hTQS13cXE0LTV3cHYtbXgyZ84AA2eY","url":"https://github.com/advisories/GHSA-wqq4-5wpv-mx2g","title":"Undici's cookie header not cleared on cross-origin redirect in fetch","description":"### Impact\n\nUndici clears Authorization headers on cross-origin redirects, but does not clear `Cookie` headers. By design, `cookie` headers are [forbidden request headers](https://fetch.spec.whatwg.org/#forbidden-request-header), disallowing them to be set in `RequestInit.headers` in browser environments. Since Undici handles headers more liberally than the specification, there was a disconnect from the assumptions the spec made, and Undici's implementation of fetch.\n\nAs such this may lead to accidental leakage of cookie to a 3rd-party site or a malicious attacker who can control the redirection target (ie. an open redirector) to leak the cookie to the 3rd party site.\n\n### Patches\n\nThis was patched in [e041de359221ebeae04c469e8aff4145764e6d76](https://github.com/nodejs/undici/commit/e041de359221ebeae04c469e8aff4145764e6d76), which is included in version 5.26.2.\n","origin":"UNSPECIFIED","severity":"LOW","published_at":"2023-10-16T14:05:37.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-q768-x9m6-m9qp","https://github.com/nodejs/undici/security/advisories/GHSA-wqq4-5wpv-mx2g","https://nvd.nist.gov/vuln/detail/CVE-2023-45143","https://github.com/nodejs/undici/commit/e041de359221ebeae04c469e8aff4145764e6d76","https://hackerone.com/reports/2166948","https://github.com/nodejs/undici/releases/tag/v5.26.2","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y","https://github.com/advisories/GHSA-wqq4-5wpv-mx2g"],"source_kind":"github","identifiers":["GHSA-wqq4-5wpv-mx2g","CVE-2023-45143"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"5.26.2","vulnerable_version_range":"\u003c 5.26.2"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2023-10-16T15:06:30.108Z","updated_at":"2025-06-02T01:10:30.589Z","epss_percentage":0.00181,"epss_percentile":0.40593},{"uuid":"GSA_kwCzR0hTQS0zZzkyLXc4YzUtNzNwcc4AA9rQ","url":"https://github.com/advisories/GHSA-3g92-w8c5-73pq","title":"Undici vulnerable to data leak when using response.arrayBuffer()","description":"### Impact\n\nDepending on network and process conditions of a `fetch()` request, `response.arrayBuffer()` might include portion of memory from the Node.js process.\n\n### Patches\n\nThis has been patched in v6.19.2.\n\n### Workarounds\n\nThere are no known workaround.\n\n### References\n\nhttps://github.com/nodejs/undici/issues/3337\nhttps://github.com/nodejs/undici/issues/3328\nhttps://github.com/nodejs/undici/pull/3338\nhttps://github.com/nodejs/undici/commit/f979ec3204ca489abf30e7d20e9fee9ea7711d36","origin":"UNSPECIFIED","severity":"LOW","published_at":"2024-07-09T13:32:30.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":2.0,"cvss_vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","references":["https://github.com/nodejs/undici/security/advisories/GHSA-3g92-w8c5-73pq","https://nvd.nist.gov/vuln/detail/CVE-2024-38372","https://github.com/nodejs/undici/issues/3328","https://github.com/nodejs/undici/issues/3337","https://github.com/nodejs/undici/pull/3338","https://github.com/nodejs/undici/commit/f979ec3204ca489abf30e7d20e9fee9ea7711d36","https://github.com/advisories/GHSA-3g92-w8c5-73pq"],"source_kind":"github","identifiers":["GHSA-3g92-w8c5-73pq","CVE-2024-38372"],"repository_url":"https://github.com/nodejs/undici","blast_radius":9.982877478560944,"packages":[{"versions":[{"first_patched_version":"6.19.2","vulnerable_version_range":"\u003e= 6.14.0, \u003c 6.19.2"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2024-07-09T14:05:41.758Z","updated_at":"2025-06-02T01:08:58.261Z","epss_percentage":0.0025,"epss_percentile":0.48568},{"uuid":"GSA_kwCzR0hTQS05ZjI0LWpxaG0tamZjd84AA5Vf","url":"https://github.com/advisories/GHSA-9f24-jqhm-jfcw","title":"fetch(url) leads to a memory leak in undici","description":"### Impact\n\nCalling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. \n\n### Patches\n\nPatched in v6.6.1\n\n### Workarounds\n\nMake sure to always consume the incoming body.\n","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2024-02-16T15:59:38.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-9f24-jqhm-jfcw","https://github.com/nodejs/undici/commit/87a48113f1f68f60aa09abb07276d7c35467c663","https://github.com/nodejs/undici/releases/tag/v6.6.1","https://nvd.nist.gov/vuln/detail/CVE-2024-24750","https://security.netapp.com/advisory/ntap-20240419-0006","https://github.com/advisories/GHSA-9f24-jqhm-jfcw"],"source_kind":"github","identifiers":["GHSA-9f24-jqhm-jfcw","CVE-2024-24750"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"6.6.1","vulnerable_version_range":"\u003e= 6.0.0, \u003c= 6.6.0"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2024-02-16T16:04:42.077Z","updated_at":"2024-12-17T20:04:25.000Z","epss_percentage":0.00465,"epss_percentile":0.63309},{"uuid":"GSA_kwCzR0hTQS1jeHJoLWo0anItcXdnM84ABH4x","url":"https://github.com/advisories/GHSA-cxrh-j4jr-qwg3","title":"undici Denial of Service attack via bad certificate data","description":"### Impact\n\nApplications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak. \n\n### Patches\n\nThis has been patched in https://github.com/nodejs/undici/pull/4088.\n\n### Workarounds\n\nIf a webhook fails, avoid keep calling it repeatedly.\n\n### References\n\nReported as: https://github.com/nodejs/undici/issues/3895","origin":"UNSPECIFIED","severity":"LOW","published_at":"2025-05-15T14:15:06.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-cxrh-j4jr-qwg3","https://github.com/nodejs/undici/issues/3895","https://github.com/nodejs/undici/pull/4088","https://nvd.nist.gov/vuln/detail/CVE-2025-47279","https://github.com/advisories/GHSA-cxrh-j4jr-qwg3"],"source_kind":"github","identifiers":["GHSA-cxrh-j4jr-qwg3","CVE-2025-47279"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"7.5.0","vulnerable_version_range":"\u003e= 7.0.0, \u003c 7.5.0"},{"first_patched_version":"6.21.2","vulnerable_version_range":"\u003e= 6.0.0, \u003c 6.21.2"},{"first_patched_version":"5.29.0","vulnerable_version_range":"\u003c 5.29.0"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2025-05-15T15:09:47.466Z","updated_at":"2025-05-16T02:07:01.000Z","epss_percentage":0.00032,"epss_percentile":0.07905},{"uuid":"GSA_kwCzR0hTQS1tNHY4LXdxdnItcDlmN84AA6o1","url":"https://github.com/advisories/GHSA-m4v8-wqvr-p9f7","title":"Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline","description":"### Impact\n\nUndici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`.\n\n### Patches\n\nThis has been patched in https://github.com/nodejs/undici/commit/6805746680d27a5369d7fb67bc05f95a28247d75.\nFixes has been released in v5.28.4 and v6.11.1.\n\n### Workarounds\n\nuse `fetch()` or disable `maxRedirections`.\n\n### References\n\nLinzi Shang reported this.\n\n* https://hackerone.com/reports/2408074\n* https://github.com/nodejs/undici/security/advisories/GHSA-3787-6prv-h9w3","origin":"UNSPECIFIED","severity":"LOW","published_at":"2024-04-04T14:20:39.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-m4v8-wqvr-p9f7","https://github.com/nodejs/undici/commit/64e3402da4e032e68de46acb52800c9a06aaea3f","https://github.com/nodejs/undici/commit/6805746680d27a5369d7fb67bc05f95a28247d75","https://hackerone.com/reports/2408074","https://nvd.nist.gov/vuln/detail/CVE-2024-30260","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HQVHWAS6WDXXIU7F72XI55VZ2LTZUB33","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NC3V3HFZ5MOJRZDY5ZELL6REIRSPFROJ","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P6Q4RGETHVYVHDIQGTJGU5AV6NJEI67E","https://github.com/advisories/GHSA-m4v8-wqvr-p9f7"],"source_kind":"github","identifiers":["GHSA-m4v8-wqvr-p9f7","CVE-2024-30260"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"6.11.1","vulnerable_version_range":"\u003e= 6.0.0, \u003c 6.11.1"},{"first_patched_version":"5.28.4","vulnerable_version_range":"\u003c 5.28.4"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2024-04-04T15:04:57.956Z","updated_at":"2025-06-02T01:09:31.180Z","epss_percentage":0.00131,"epss_percentile":0.34016},{"uuid":"GSA_kwCzR0hTQS05cXhyLXFqNTQtaDY3Ms4AA6o2","url":"https://github.com/advisories/GHSA-9qxr-qj54-h672","title":"Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect","description":"### Impact\n\nIf an attacker can alter the `integrity` option passed to `fetch()`, they can let `fetch()` accept requests as valid even if they have been tampered.\n\n### Patches\n\nFixed in https://github.com/nodejs/undici/commit/d542b8cd39ec1ba303f038ea26098c3f355974f3.\nFixes has been released in v5.28.4 and v6.11.1.\n\n\n### Workarounds\n\nEnsure that `integrity` cannot be tampered with.\n\n### References\n\nhttps://hackerone.com/reports/2377760\n","origin":"UNSPECIFIED","severity":"LOW","published_at":"2024-04-04T14:20:54.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-9qxr-qj54-h672","https://github.com/nodejs/undici/commit/2b39440bd9ded841c93dd72138f3b1763ae26055","https://github.com/nodejs/undici/commit/d542b8cd39ec1ba303f038ea26098c3f355974f3","https://hackerone.com/reports/2377760","https://nvd.nist.gov/vuln/detail/CVE-2024-30261","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HQVHWAS6WDXXIU7F72XI55VZ2LTZUB33","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P6Q4RGETHVYVHDIQGTJGU5AV6NJEI67E","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NC3V3HFZ5MOJRZDY5ZELL6REIRSPFROJ","https://github.com/advisories/GHSA-9qxr-qj54-h672"],"source_kind":"github","identifiers":["GHSA-9qxr-qj54-h672","CVE-2024-30261"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"6.11.1","vulnerable_version_range":"\u003e= 6.0.0, \u003c 6.11.1"},{"first_patched_version":"5.28.4","vulnerable_version_range":"\u003c 5.28.4"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2024-04-04T15:04:57.928Z","updated_at":"2025-06-02T01:09:31.152Z","epss_percentage":0.00353,"epss_percentile":0.57048},{"uuid":"GSA_kwCzR0hTQS1mNzcyLTY2ZzgtcTVoM84AAuFo","url":"https://github.com/advisories/GHSA-f772-66g8-q5h3","title":"Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type","description":"### Impact\n\n`=\u003c undici@5.8.0` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header.\n\nExample:\n\n```\nimport { request } from 'undici'\n\nconst unsanitizedContentTypeInput =  'application/json\\r\\n\\r\\nGET /foo2 HTTP/1.1'\n\nawait request('http://localhost:3000, {\n    method: 'GET',\n    headers: {\n      'content-type': unsanitizedContentTypeInput\n    },\n})\n```\n\nThe above snippet will perform two requests in a single `request` API call:\n\n1) `http://localhost:3000/`\n2) `http://localhost:3000/foo2`\n\n### Patches\n\nThis issue was patched in Undici v5.8.1\n\n### Workarounds\n\nSanitize input when sending content-type headers using user input.\n\n## For more information\nIf you have any questions or comments about this advisory:\n\n- Open an issue in [undici repository](https://github.com/nodejs/undici/issues)\n- To make a report, follow the [SECURITY](https://github.com/nodejs/node/blob/HEAD/SECURITY.md) document","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-08-18T19:02:56.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-f772-66g8-q5h3","https://nvd.nist.gov/vuln/detail/CVE-2022-35948","https://github.com/nodejs/undici/commit/66165d604fd0aee70a93ed5c44ad4cc2df395f80","https://github.com/nodejs/undici/releases/tag/v5.8.2","https://github.com/advisories/GHSA-f772-66g8-q5h3"],"source_kind":"github","identifiers":["GHSA-f772-66g8-q5h3","CVE-2022-35948"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"5.8.2","vulnerable_version_range":"\u003c= 5.8.1"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2022-12-21T16:12:00.990Z","updated_at":"2025-06-02T01:12:06.888Z","epss_percentage":0.00094,"epss_percentile":0.2778},{"uuid":"GSA_kwCzR0hTQS04cXI0LXhndzYtd21yM84AAuFj","url":"https://github.com/advisories/GHSA-8qr4-xgw6-wmr3","title":"`undici.request` vulnerable to SSRF using absolute URL on `pathname`","description":"### Impact\n\n`undici` is vulnerable to SSRF (Server-side Request Forgery) when an application takes in **user input** into the `path/pathname` option of `undici.request`.\n\nIf a user specifies a URL such as `http://127.0.0.1` or `//127.0.0.1`\n\n```js\nconst undici = require(\"undici\")\nundici.request({origin: \"http://example.com\", pathname: \"//127.0.0.1\"})\n```\n\nInstead of processing the request as `http://example.org//127.0.0.1` (or `http://example.org/http://127.0.0.1` when `http://127.0.0.1 is used`), it actually processes the request as `http://127.0.0.1/` and sends it to `http://127.0.0.1`.\n\nIf a developer passes in user input into `path` parameter of `undici.request`, it can result in an _SSRF_ as they will assume that the hostname cannot change, when in actual fact it can change because the specified path parameter is combined with the base URL.\n\n### Patches\n\nThis issue was fixed in `undici@5.8.1`.\n\n### Workarounds\n\nThe best workaround is to validate user input before passing it to the `undici.request` call.\n\n## For more information\nIf you have any questions or comments about this advisory:\n\n- Open an issue in [undici repository](https://github.com/nodejs/undici/issues)\n- To make a report, follow the [SECURITY](https://github.com/nodejs/node/blob/HEAD/SECURITY.md) document\n","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-08-18T18:59:46.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-8qr4-xgw6-wmr3","https://nvd.nist.gov/vuln/detail/CVE-2022-35949","https://github.com/nodejs/undici/commit/124f7ebf705366b2e1844dff721928d270f87895","https://github.com/nodejs/undici/releases/tag/v5.8.2","https://github.com/advisories/GHSA-8qr4-xgw6-wmr3"],"source_kind":"github","identifiers":["GHSA-8qr4-xgw6-wmr3","CVE-2022-35949"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"5.8.2","vulnerable_version_range":"\u003c= 5.8.1"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2022-12-21T16:12:01.023Z","updated_at":"2025-06-02T01:12:06.960Z","epss_percentage":0.00146,"epss_percentile":0.36286},{"uuid":"GSA_kwCzR0hTQS0zY3ZyLTgyMnItcnFjY84AAtkH","url":"https://github.com/advisories/GHSA-3cvr-822r-rqcc","title":"undici before v5.8.0 vulnerable to CRLF injection in request headers","description":"### Impact\n\nIt is possible to inject CRLF sequences into request headers in Undici.\n\n```js\nconst undici = require('undici')\n\nconst response = undici.request(\"http://127.0.0.1:1000\", {\n  headers: {'a': \"\\r\\nb\"}\n})\n```\n\nThe same applies to `path` and `method`\n\n### Patches\n\nUpdate to v5.8.0\n\n### Workarounds\n\nSanitize all HTTP headers from untrusted sources to eliminate `\\r\\n`.\n\n### References\n\nhttps://hackerone.com/reports/409943\nhttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12116\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* Open an issue in [undici repository](https://github.com/nodejs/undici/issues)\n* To make a report, follow the [SECURITY](https://github.com/nodejs/node/blob/HEAD/SECURITY.md) document\n","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-07-21T20:30:10.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-3cvr-822r-rqcc","https://nvd.nist.gov/vuln/detail/CVE-2022-31150","https://github.com/nodejs/undici/commit/a29a151d0140d095742d21a004023d024fe93259","https://hackerone.com/reports/409943","https://github.com/nodejs/undici/releases/tag/v5.8.0","https://security.netapp.com/advisory/ntap-20220915-0002/","https://github.com/advisories/GHSA-3cvr-822r-rqcc"],"source_kind":"github","identifiers":["GHSA-3cvr-822r-rqcc","CVE-2022-31150"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"5.8.0","vulnerable_version_range":"\u003c 5.8.0"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2022-12-21T16:12:10.121Z","updated_at":"2025-06-02T01:12:09.639Z","epss_percentage":0.00147,"epss_percentile":0.36337},{"uuid":"GSA_kwCzR0hTQS1wZ3c3LXd4N3ctMnczM84AArtC","url":"https://github.com/advisories/GHSA-pgw7-wx7w-2w33","title":"ProxyAgent vulnerable to MITM","description":"### Description\n\n`Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request \u0026 response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and if the proxy's URL is HTTP then it also means that nominally HTTPS requests are actually sent via plain-text HTTP between Undici and the proxy server.\n\n### Impact\n\nThis affects all use of HTTPS via HTTP proxy using **`Undici.ProxyAgent`**  with Undici or Node's global `fetch`. In this case, it removes all HTTPS security from all requests sent using Undici's `ProxyAgent`, allowing trivial MitM attacks by anybody on the network path between the client and the target server (local network users, your ISP, the proxy, the target server's ISP, etc).\nThis less seriously affects HTTPS via HTTPS proxies. When you send HTTPS via a proxy to a remote server, the proxy can freely view or modify all HTTPS traffic unexpectedly (but only the proxy). \n\n### Patches\n\nThis issue was patched in Undici v5.5.1.\n\n### Workarounds\n\nAt the time of writing, the only workaround is to not use `ProxyAgent` as a dispatcher for TLS Connections.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-06-17T01:02:29.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/nodejs/undici/security/advisories/GHSA-pgw7-wx7w-2w33","https://nvd.nist.gov/vuln/detail/CVE-2022-32210","https://hackerone.com/reports/1583680","https://github.com/advisories/GHSA-pgw7-wx7w-2w33"],"source_kind":"github","identifiers":["GHSA-pgw7-wx7w-2w33","CVE-2022-32210"],"repository_url":"https://github.com/nodejs/undici","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"5.5.1","vulnerable_version_range":"\u003e= 4.8.2, \u003c= 5.5.0"}],"ecosystem":"npm","package_name":"undici"}],"created_at":"2022-12-21T16:12:19.082Z","updated_at":"2025-06-02T01:12:18.131Z","epss_percentage":0.00131,"epss_percentile":0.34149}],"docker_usage_url":"https://docker.ecosyste.ms/usage/npm/undici","docker_dependents_count":1787,"docker_downloads_count":2620660081,"usage_url":"https://repos.ecosyste.ms/usage/npm/undici","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/npm/undici/dependencies","status":null,"funding_links":[],"critical":true,"versions_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/undici/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/undici/version_numbers","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/undici/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/undici/related_packages","maintainers":[{"uuid":"ronag","login":"ronag","name":null,"email":"ronagy@icloud.com","url":null,"packages_count":38,"html_url":"https://www.npmjs.com/~ronag","role":null,"created_at":"2022-11-14T02:52:35.896Z","updated_at":"2022-11-14T02:52:35.896Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/ronag/packages"},{"uuid":"matteo.collina","login":"matteo.collina","name":null,"email":"hello@matteocollina.com","url":null,"packages_count":604,"html_url":"https://www.npmjs.com/~matteo.collina","role":null,"created_at":"2022-11-14T02:52:35.691Z","updated_at":"2022-11-14T02:52:35.691Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/matteo.collina/packages"},{"uuid":"ethan_arrowood","login":"ethan_arrowood","name":null,"email":"ethan@arrowood.dev","url":null,"packages_count":34,"html_url":"https://www.npmjs.com/~ethan_arrowood","role":null,"created_at":"2022-11-14T02:52:35.968Z","updated_at":"2022-11-14T02:52:35.968Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/ethan_arrowood/packages"}],"registry":{"name":"npmjs.org","url":"https://registry.npmjs.org","ecosystem":"npm","default":true,"packages_count":5005320,"maintainers_count":1012640,"namespaces_count":295318,"keywords_count":699769,"github":"npm","metadata":{"funded_packages_count":150180},"icon_url":"https://github.com/npm.png","created_at":"2022-04-04T15:19:23.081Z","updated_at":"2025-06-05T05:52:15.849Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/namespaces"}},"unique_repositories_count":10267,"unique_repositories_count_past_30_days":264,"recent_issues":[{"uuid":"5431803498","node_id":"PR_kwDOSZtW-88AAAABDPDJLg","number":4,"state":"closed","title":"Bump the npm_and_yarn group across 3 directories with 25 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-12T06:49:28.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-12T06:48:50.000Z","updated_at":"2026-09-12T06:49:30.000Z","time_to_close":38,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"npm_and_yarn","update_count":25,"packages":[{"name":"qs","old_version":"6.14.2","new_version":"6.16.0","repository_url":"https://github.com/ljharb/qs"},{"name":"axios","old_version":"1.15.0","new_version":"1.20.0","repository_url":"https://github.com/axios/axios"},{"name":"maplibre-gl","old_version":"4.7.1","new_version":"6.9.0","repository_url":"https://github.com/maplibre/maplibre-gl-js"},{"name":"mysql2","old_version":"3.16.2","new_version":"3.23.1","repository_url":"https://github.com/sidorares/node-mysql2"},{"name":"postcss","old_version":"8.5.15","new_version":"8.5.28","repository_url":"https://github.com/postcss/postcss"},{"name":"sharp","old_version":"0.34.5","new_version":"0.35.4","repository_url":"https://github.com/lovell/sharp"},{"name":"systeminformation","old_version":"5.31.6","new_version":"5.31.7","repository_url":"https://github.com/sebhildebrandt/systeminformation"},{"name":"tar","old_version":"7.5.11","new_version":"7.5.22","repository_url":"https://github.com/isaacs/node-tar"},{"name":"vite","old_version":"6.4.2","new_version":"6.4.3","repository_url":"https://github.com/vitejs/vite"},{"name":"@adonisjs/bodyparser","old_version":"10.1.3","new_version":"10.1.5","repository_url":"https://github.com/adonisjs/bodyparser"},{"name":"@babel/core","old_version":"7.29.0","new_version":"7.29.7","repository_url":"https://github.com/babel/babel"},{"name":"brace-expansion","old_version":"1.1.12","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"@faker-js/faker","old_version":"9.9.0","new_version":"10.6.0","repository_url":"https://github.com/faker-js/faker"},{"name":"@grpc/grpc-js","old_version":"1.14.3","new_version":"1.14.4","repository_url":"https://github.com/grpc/grpc-node"},{"name":"@humanfs/node","old_version":"0.16.7","new_version":"0.16.8","repository_url":"https://github.com/humanwhocodes/humanfs"},{"name":"baseline-browser-mapping","old_version":"2.9.19","new_version":"2.11.22","repository_url":"https://github.com/web-platform-dx/baseline-browser-mapping"},{"name":"browserslist","old_version":"4.28.1","new_version":"4.28.9","repository_url":"https://github.com/browserslist/browserslist"},{"name":"undici","old_version":"6.24.1","new_version":"6.28.1","repository_url":"https://github.com/nodejs/undici"},{"name":"undici","old_version":"7.24.3","new_version":"7.29.1","repository_url":"https://github.com/nodejs/undici"},{"name":"fflate","old_version":"0.8.2","new_version":"0.8.3","repository_url":"https://github.com/101arrowz/fflate"},{"name":"ip-address","old_version":"10.1.0","new_version":"10.7.0","repository_url":"https://github.com/beaugunderson/ip-address"},{"name":"js-yaml","old_version":"4.1.1","new_version":"4.3.2","repository_url":"https://github.com/nodeca/js-yaml"},{"name":"protobufjs","old_version":"7.5.5","new_version":"7.6.6","repository_url":"https://github.com/protobufjs/protobuf.js"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 1 update in the /evez-ecosystem/evezart-repos/spectrumscan-api directory: [body-parser](https://github.com/expressjs/body-parser).\nBumps the npm_and_yarn group with 1 update in the /evez-ecosystem/evezart-repos/quantumseal-api directory: [body-parser](https://github.com/expressjs/body-parser).\nBumps the npm_and_yarn group with 22 updates in the /evez-ecosystem/evezart-repos/project-nomad-evez/admin directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [qs](https://github.com/ljharb/qs) | `6.14.2` | `6.16.0` |\n| [axios](https://github.com/axios/axios) | `1.15.0` | `1.20.0` |\n| [maplibre-gl](https://github.com/maplibre/maplibre-gl-js) | `4.7.1` | `6.9.0` |\n| [mysql2](https://github.com/sidorares/node-mysql2) | `3.16.2` | `3.23.1` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.15` | `8.5.28` |\n| [sharp](https://github.com/lovell/sharp) | `0.34.5` | `0.35.4` |\n| [systeminformation](https://github.com/sebhildebrandt/systeminformation) | `5.31.6` | `5.31.7` |\n| [tar](https://github.com/isaacs/node-tar) | `7.5.11` | `7.5.22` |\n| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `6.4.2` | `6.4.3` |\n| [@adonisjs/bodyparser](https://github.com/adonisjs/bodyparser) | `10.1.3` | `10.1.5` |\n| [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) | `7.29.0` | `7.29.7` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.12` | `1.1.18` |\n| [@faker-js/faker](https://github.com/faker-js/faker) | `9.9.0` | `10.6.0` |\n| [@grpc/grpc-js](https://github.com/grpc/grpc-node) | `1.14.3` | `1.14.4` |\n| [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node) | `0.16.7` | `0.16.8` |\n| [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) | `2.9.19` | `2.11.22` |\n| [browserslist](https://github.com/browserslist/browserslist) | `4.28.1` | `4.28.9` |\n| [undici](https://github.com/nodejs/undici) | `6.24.1` | `6.28.1` |\n| [undici](https://github.com/nodejs/undici) | `7.24.3` | `7.29.1` |\n| [fflate](https://github.com/101arrowz/fflate) | `0.8.2` | `0.8.3` |\n| [ip-address](https://github.com/beaugunderson/ip-address) | `10.1.0` | `10.7.0` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.1` | `4.3.2` |\n| [protobufjs](https://github.com/protobufjs/protobuf.js) | `7.5.5` | `7.6.6` |\n\n\nUpdates `body-parser` from 1.20.5 to 1.20.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/body-parser/releases\"\u003ebody-parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.20.8\u003c/h2\u003e\n\u003ch2\u003eImportant\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eSame code base as \u003ca href=\"https://github.com/expressjs/body-parser/releases/tag/1.20.7\"\u003e1.20.7\u003c/a\u003e. This was created to test the new release process.\u003c/strong\u003e\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eci: backport npm-publish workflow from master by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/769\"\u003eexpressjs/body-parser#769\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e1.20.8 by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/770\"\u003eexpressjs/body-parser#770\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.7...1.20.8\"\u003ehttps://github.com/expressjs/body-parser/compare/1.20.7...1.20.8\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.20.7\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocs: include security fix in 1.20.6 changes by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/747\"\u003eexpressjs/body-parser#747\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edeps: qs@~6.16.0 by \u003ca href=\"https://github.com/krzysdz\"\u003e\u003ccode\u003e@​krzysdz\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/761\"\u003eexpressjs/body-parser#761\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e1.20.7 by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/767\"\u003eexpressjs/body-parser#767\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.6...1.20.7\"\u003ehttps://github.com/expressjs/body-parser/compare/1.20.6...1.20.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.20.6\u003c/h2\u003e\n\u003ch2\u003eImportant: Security\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity fix for \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2025-13466\"\u003eCVE-2026-12590\u003c/a\u003e (\u003ca href=\"https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6\"\u003eGHSA-v422-hmwv-36x6\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: improve limit option validation by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/741\"\u003eexpressjs/body-parser#741\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.5...1.20.6\"\u003ehttps://github.com/expressjs/body-parser/compare/1.20.5...1.20.6\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/body-parser/blob/1.20.8/HISTORY.md\"\u003ebody-parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e1.20.8\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eSame code base as 1.20.7. This was created to test the new release process.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.20.7\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003edeps: qs@~6.16.0\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.20.6\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity fix for \u003ca href=\"https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6\"\u003eGHSA-v422-hmwv-36x6\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: improve \u003ccode\u003elimit\u003c/code\u003e option validation (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/698\"\u003e#698\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003eInvalid \u003ccode\u003elimit\u003c/code\u003e values (e.g. unparseable strings or \u003ccode\u003eNaN\u003c/code\u003e) now throw instead of being silently ignored, which previously disabled size limit enforcement\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003enull\u003c/code\u003e and \u003ccode\u003eundefined\u003c/code\u003e fall back to the default 100kb limit\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/5c08c2008eac79abddb8abfa5095491d02958d56\"\u003e\u003ccode\u003e5c08c20\u003c/code\u003e\u003c/a\u003e 1.20.8 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/770\"\u003e#770\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/0cea4f42a40996eafac441d0e71084afbe1407d4\"\u003e\u003ccode\u003e0cea4f4\u003c/code\u003e\u003c/a\u003e ci: backport npm-publish workflow from master (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/769\"\u003e#769\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/0f0f0d7f96fc7444407aef85a6d1fa363279e654\"\u003e\u003ccode\u003e0f0f0d7\u003c/code\u003e\u003c/a\u003e 1.20.7 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/767\"\u003e#767\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/355eb04ade7c27f57f93a0e90e26ed6f121becc5\"\u003e\u003ccode\u003e355eb04\u003c/code\u003e\u003c/a\u003e deps: qs@~6.16.0 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/761\"\u003e#761\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/8be369a5f8b0f4070ebb7a0ae9aca12db9d8f947\"\u003e\u003ccode\u003e8be369a\u003c/code\u003e\u003c/a\u003e docs: include security fix in 1.20.6 changes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/5cc4fb8867c93a3aa4455927e38858c9ab89ff43\"\u003e\u003ccode\u003e5cc4fb8\u003c/code\u003e\u003c/a\u003e 1.20.6 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/746\"\u003e#746\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/3492672eee593d5c158f239b6e9115498a5dbeac\"\u003e\u003ccode\u003e3492672\u003c/code\u003e\u003c/a\u003e fix: improve limit option validation (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/741\"\u003e#741\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.5...1.20.8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for body-parser since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `body-parser` from 1.20.5 to 1.20.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/body-parser/releases\"\u003ebody-parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.20.8\u003c/h2\u003e\n\u003ch2\u003eImportant\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eSame code base as \u003ca href=\"https://github.com/expressjs/body-parser/releases/tag/1.20.7\"\u003e1.20.7\u003c/a\u003e. This was created to test the new release process.\u003c/strong\u003e\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eci: backport npm-publish workflow from master by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/769\"\u003eexpressjs/body-parser#769\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e1.20.8 by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/770\"\u003eexpressjs/body-parser#770\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.7...1.20.8\"\u003ehttps://github.com/expressjs/body-parser/compare/1.20.7...1.20.8\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.20.7\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocs: include security fix in 1.20.6 changes by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/747\"\u003eexpressjs/body-parser#747\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edeps: qs@~6.16.0 by \u003ca href=\"https://github.com/krzysdz\"\u003e\u003ccode\u003e@​krzysdz\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/761\"\u003eexpressjs/body-parser#761\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e1.20.7 by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/767\"\u003eexpressjs/body-parser#767\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.6...1.20.7\"\u003ehttps://github.com/expressjs/body-parser/compare/1.20.6...1.20.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.20.6\u003c/h2\u003e\n\u003ch2\u003eImportant: Security\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity fix for \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2025-13466\"\u003eCVE-2026-12590\u003c/a\u003e (\u003ca href=\"https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6\"\u003eGHSA-v422-hmwv-36x6\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: improve limit option validation by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/741\"\u003eexpressjs/body-parser#741\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.5...1.20.6\"\u003ehttps://github.com/expressjs/body-parser/compare/1.20.5...1.20.6\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/body-parser/blob/1.20.8/HISTORY.md\"\u003ebody-parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e1.20.8\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eSame code base as 1.20.7. This was created to test the new release process.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.20.7\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003edeps: qs@~6.16.0\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.20.6\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity fix for \u003ca href=\"https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6\"\u003eGHSA-v422-hmwv-36x6\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: improve \u003ccode\u003elimit\u003c/code\u003e option validation (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/698\"\u003e#698\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003eInvalid \u003ccode\u003elimit\u003c/code\u003e values (e.g. unparseable strings or \u003ccode\u003eNaN\u003c/code\u003e) now throw instead of being silently ignored, which previously disabled size limit enforcement\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003enull\u003c/code\u003e and \u003ccode\u003eundefined\u003c/code\u003e fall back to the default 100kb limit\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/5c08c2008eac79abddb8abfa5095491d02958d56\"\u003e\u003ccode\u003e5c08c20\u003c/code\u003e\u003c/a\u003e 1.20.8 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/770\"\u003e#770\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/0cea4f42a40996eafac441d0e71084afbe1407d4\"\u003e\u003ccode\u003e0cea4f4\u003c/code\u003e\u003c/a\u003e ci: backport npm-publish workflow from master (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/769\"\u003e#769\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/0f0f0d7f96fc7444407aef85a6d1fa363279e654\"\u003e\u003ccode\u003e0f0f0d7\u003c/code\u003e\u003c/a\u003e 1.20.7 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/767\"\u003e#767\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/355eb04ade7c27f57f93a0e90e26ed6f121becc5\"\u003e\u003ccode\u003e355eb04\u003c/code\u003e\u003c/a\u003e deps: qs@~6.16.0 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/761\"\u003e#761\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/8be369a5f8b0f4070ebb7a0ae9aca12db9d8f947\"\u003e\u003ccode\u003e8be369a\u003c/code\u003e\u003c/a\u003e docs: include security fix in 1.20.6 changes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/5cc4fb8867c93a3aa4455927e38858c9ab89ff43\"\u003e\u003ccode\u003e5cc4fb8\u003c/code\u003e\u003c/a\u003e 1.20.6 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/746\"\u003e#746\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/3492672eee593d5c158f239b6e9115498a5dbeac\"\u003e\u003ccode\u003e3492672\u003c/code\u003e\u003c/a\u003e fix: improve limit option validation (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/741\"\u003e#741\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.5...1.20.8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for body-parser since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `qs` from 6.14.2 to 6.16.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ljharb/qs/blob/main/CHANGELOG.md\"\u003eqs's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003cstrong\u003e6.16.0\u003c/strong\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[New] \u003ccode\u003estringify\u003c/code\u003e: add a \u003ccode\u003edepth\u003c/code\u003e option to bound recursion depth (default \u003ccode\u003eInfinity\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003e[Fix] stringify: serialize Date values when a filter is provided\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: enforce \u003ccode\u003earrayLimit\u003c/code\u003e on comma groups under \u003ccode\u003e[]=\u003c/code\u003e when \u003ccode\u003ethrowOnLimitExceeded\u003c/code\u003e is set\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: flatten a collection appended to an overflowed array (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/571\"\u003e#571\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eutils\u003c/code\u003e: \u003ccode\u003eisBuffer\u003c/code\u003e: do not invoke a non-callable \u003ccode\u003econstructor.isBuffer\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003estringify\u003c/code\u003e: do not let \u003ccode\u003eallowEmptyArrays\u003c/code\u003e skip cycle detection (or drop own keys) on an empty array with own properties\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003estringify\u003c/code\u003e: encode dots in a top-level key with a primitive value when encodeDotInKeys is set (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/562\"\u003e#562\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Docs] threat model: clarify \u003ccode\u003estringify\u003c/code\u003e deep-nesting DoS is caller-bounded\u003c/li\u003e\n\u003cli\u003e[Docs] clarify \u003ccode\u003earrayLimit\u003c/code\u003e is a representation threshold, not an element-count cap\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003eparse\u003c/code\u003e: remove a test that pinned \u003ccode\u003e[]=\u003c/code\u003e comma groups escaping \u003ccode\u003earrayLimit\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003estringify\u003c/code\u003e: pin current \u003ccode\u003eencodeDotInKeys\u003c/code\u003e separator-dot behavior\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003eevalmd\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003cstrong\u003e6.15.3\u003c/strong\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: enforce \u003ccode\u003ethrowOnLimitExceeded\u003c/code\u003e for cumulative array growth via \u003ccode\u003ecombine\u003c/code\u003e/\u003ccode\u003emerge\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eutils\u003c/code\u003e: respect encoding of surrogate pairs across chunks (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/559\"\u003e#559\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Robustness] \u003ccode\u003eparse\u003c/code\u003e: throw the \u003ccode\u003earrayLimit\u003c/code\u003e error before splitting oversized comma values\u003c/li\u003e\n\u003cli\u003e[Robustness] \u003ccode\u003eutils.merge\u003c/code\u003e / \u003ccode\u003eutils.assign\u003c/code\u003e: avoid invoking \u003ccode\u003e__proto__\u003c/code\u003e setter when copying own properties\u003c/li\u003e\n\u003cli\u003e[Robustness] \u003ccode\u003eutils\u003c/code\u003e: enforce \u003ccode\u003earrayLimit\u003c/code\u003e consistently across \u003ccode\u003emerge\u003c/code\u003e's array paths\u003c/li\u003e\n\u003cli\u003e[Perf] \u003ccode\u003eutils\u003c/code\u003e: make \u003ccode\u003ecompact\u003c/code\u003e O(n) via a side-channel visited-set instead of \u003ccode\u003eArray.indexOf\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Deps] update \u003ccode\u003eside-channel\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003emock-property\u003c/code\u003e, \u003ccode\u003etape\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003eparse\u003c/code\u003e: characterize current lenient handling of unbalanced bracket keys (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/558\"\u003e#558\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003cstrong\u003e6.15.2\u003c/strong\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] \u003ccode\u003estringify\u003c/code\u003e: skip null/undefined entries in \u003ccode\u003earrayFormat: 'comma'\u003c/code\u003e + \u003ccode\u003eencodeValuesOnly\u003c/code\u003e instead of crashing in \u003ccode\u003eencoder\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003estringify\u003c/code\u003e: use configured \u003ccode\u003edelimiter\u003c/code\u003e after \u003ccode\u003echarsetSentinel\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/555\"\u003e#555\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003estringify\u003c/code\u003e: apply \u003ccode\u003eformatter\u003c/code\u003e to encoded key under \u003ccode\u003estrictNullHandling\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/554\"\u003e#554\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003estringify\u003c/code\u003e: skip null/undefined filter-array entries instead of crashing in \u003ccode\u003eencoder\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/551\"\u003e#551\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: handle nested bracket groups and add regression tests (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/530\"\u003e#530\u003c/a\u003e); changes output for some unbalanced bracket keys (see \u003ca href=\"https://redirect.github.com/ljharb/qs/issues/558\"\u003e#558\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[readme] fix grammar (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/550\"\u003e#550\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] add regression tests for keys containing percent-encoded bracket text\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003cstrong\u003e6.15.1\u003c/strong\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: \u003ccode\u003eparameterLimit: Infinity\u003c/code\u003e with \u003ccode\u003ethrowOnLimitExceeded: true\u003c/code\u003e silently drops all parameters\u003c/li\u003e\n\u003cli\u003e[Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eiconv-lite\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] increase coverage\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003cstrong\u003e6.15.0\u003c/strong\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[New] \u003ccode\u003eparse\u003c/code\u003e: add \u003ccode\u003estrictMerge\u003c/code\u003e option to wrap object/primitive conflicts in an array (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/425\"\u003e#425\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/ljharb/qs/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eduplicates\u003c/code\u003e option should not apply to bracket notation keys (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/514\"\u003e#514\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/qs/commit/bb9379e01fad04c601478acd6152143cb20c984b\"\u003e\u003ccode\u003ebb9379e\u003c/code\u003e\u003c/a\u003e v6.16.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/qs/commit/62fd25480b0b0d9c0a667ee67e13608a363f5d0e\"\u003e\u003ccode\u003e62fd254\u003c/code\u003e\u003c/a\u003e [Fix] stringify: serialize Date values when a filter is provided\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/qs/commit/8859c37470e11b42b547b275e4e9bd0bc8cc5464\"\u003e\u003ccode\u003e8859c37\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003eparse\u003c/code\u003e: enforce \u003ccode\u003earrayLimit\u003c/code\u003e on comma groups under \u003ccode\u003e[]=\u003c/code\u003e when `throwOn...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/qs/commit/8079adc7e7cf84b8289898d1b18877160de67d40\"\u003e\u003ccode\u003e8079adc\u003c/code\u003e\u003c/a\u003e [Tests] \u003ccode\u003eparse\u003c/code\u003e: remove a test that pinned \u003ccode\u003e[]=\u003c/code\u003e comma groups escaping `array...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/qs/commit/d56f48ca137b1bf6385da749b1044246ae142f19\"\u003e\u003ccode\u003ed56f48c\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003eparse\u003c/code\u003e: flatten a collection appended to an overflowed array\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/qs/commit/e83d321ffafb38cf210683ac31714fce6ce1c6c6\"\u003e\u003ccode\u003ee83d321\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003eutils\u003c/code\u003e: \u003ccode\u003eisBuffer\u003c/code\u003e: do not invoke a non-callable \u003ccode\u003econstructor.isBuffer\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/qs/commit/7e87a07c2c62301dd8fc2e099ac38227bc96c74c\"\u003e\u003ccode\u003e7e87a07\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/qs/commit/9a76af21604a4ece315e58ba251b93cf0fd944f2\"\u003e\u003ccode\u003e9a76af2\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003eevalmd\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/qs/commit/3a890d4ecd3deb72a45d90be36f4f8c5970467c7\"\u003e\u003ccode\u003e3a890d4\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003eevalmd\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/qs/commit/b433a9b1633e1c3348aa53c513589a5bfe47f113\"\u003e\u003ccode\u003eb433a9b\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003estringify\u003c/code\u003e: do not let \u003ccode\u003eallowEmptyArrays\u003c/code\u003e skip cycle detection (or dro...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ljharb/qs/compare/v6.14.2...v6.16.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `axios` from 1.15.0 to 1.20.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/axios/axios/releases\"\u003eaxios's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.20.0 — August 19, 2026\u003c/h2\u003e\n\u003cp\u003eThis release hardens runtime option handling, adds RFC 9110 status-code aliases, fixes Node.js and XHR reliability issues, and refreshes project tooling and documentation.\u003c/p\u003e\n\u003ch2\u003e⚠️ Breaking Changes \u0026amp; Deprecations\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHTTP Status Naming: Added ContentTooLarge (413) and UnprocessableContent (422), while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11082\"\u003e#11082\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRuntime Option Handling: Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects. This also clarifies Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection; see the PR for documented compatibility effects. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11141\"\u003e#11141\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eInterceptor Lifecycle: Prevented unbounded handler-array growth by trimming trailing ejected interceptors without changing iteration semantics, and kept interceptor operations safe when the public handlers field is nullish. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11087\"\u003e#11087\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11118\"\u003e#11118\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequest Error Preservation: Prevented custom Error.prepareStackTrace implementations that return non-string values from replacing the original request failure with an unrelated TypeError. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11109\"\u003e#11109\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eXHR Reliability: Navigation-canceled requests now reject with ECONNABORTED instead of resolving with status 0, while successful downloads flush their final progress callback during the live loadend dispatch. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11094\"\u003e#11094\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11121\"\u003e#11121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNode.js Socket Memory: Removed request-context retention from per-socket error listeners, preventing completed response data from being pinned for the lifetime of pooled keep-alive sockets. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11091\"\u003e#11091\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCore Methods and HTTP Errors: Prevented structural method-header buckets from leaking into outgoing headers, standardized invalid DNS lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE, and corrected the timeoutErrorMessage merge strategy. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11096\"\u003e#11096\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔧 Maintenance \u0026amp; Chores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDependencies: Updated fast-uri, postcss, js-yaml, mocha, development-tooling groups, and GitHub Actions dependencies. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11092\"\u003e#11092\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11098\"\u003e#11098\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11099\"\u003e#11099\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11106\"\u003e#11106\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11107\"\u003e#11107\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11122\"\u003e#11122\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11123\"\u003e#11123\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11126\"\u003e#11126\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11127\"\u003e#11127\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11133\"\u003e#11133\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11140\"\u003e#11140\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11143\"\u003e#11143\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11144\"\u003e#11144\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDocumentation: Applied the v1.19.0 documentation updates, added the missing fs import to the README stream example, introduced localized global search, and repaired the interceptor test link. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11101\"\u003e#11101\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11113\"\u003e#11113\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11097\"\u003e#11097\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11119\"\u003e#11119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSponsorship: Updated sponsorship links and data and added ScrapingBee as a sponsor. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11124\"\u003e#11124\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11136\"\u003e#11136\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11137\"\u003e#11137\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCI and Release: Switched ESM smoke tests to locked dependencies and synchronized package and runtime version metadata for v1.20.0. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11128\"\u003e#11128\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11152\"\u003e#11152\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🌟 New Contributors\u003c/h2\u003e\n\u003cp\u003eWe are thrilled to welcome our new contributors. Thank you for helping improve axios:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yens1\"\u003e\u003ccode\u003e@​yens1\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11109\"\u003e#11109\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Sasireddy001\"\u003e\u003ccode\u003e@​Sasireddy001\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11113\"\u003e#11113\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ari-token-security\"\u003e\u003ccode\u003e@​ari-token-security\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11094\"\u003e#11094\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timothyokooboh\"\u003e\u003ccode\u003e@​timothyokooboh\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11097\"\u003e#11097\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gi9439041-png\"\u003e\u003ccode\u003e@​gi9439041-png\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11119\"\u003e#11119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Hashim1999164\"\u003e\u003ccode\u003e@​Hashim1999164\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11082\"\u003e#11082\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/v-dev-cl\"\u003e\u003ccode\u003e@​v-dev-cl\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11091\"\u003e#11091\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0h1tb\"\u003e\u003ccode\u003e@​r0h1tb\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11118\"\u003e#11118\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ostapondo\"\u003e\u003ccode\u003e@​ostapondo\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11121\"\u003e#11121\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFull Changelog (\u003ca href=\"https://github.com/axios/axios/compare/v1.19.0...v1.20.0\"\u003ehttps://github.com/axios/axios/compare/v1.19.0...v1.20.0\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003ev1.19.0 - July 22, 2026\u003c/h2\u003e\n\u003cp\u003eThis release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMultipart Form Data: Raised the form-data dependency floor to ^4.0.6, preventing fresh installations from resolving versions affected by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (\u003ca href=\"https://github.com/advisories/GHSA-hmw2-7cc7-3qxx\"\u003ehttps://github.com/advisories/GHSA-hmw2-7cc7-3qxx\u003c/a\u003e). (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11028\"\u003e#11028\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/axios/axios/blob/v1.x/CHANGELOG.md\"\u003eaxios's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog\u003c/h1\u003e\n\u003ch2\u003ev1.19.0 — July 22, 2026\u003c/h2\u003e\n\u003cp\u003eThis release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMultipart Form Data: Raised the form-data dependency floor to ^4.0.6, preventing fresh installations from resolving versions affected by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (\u003ca href=\"https://github.com/advisories/GHSA-hmw2-7cc7-3qxx\"\u003ehttps://github.com/advisories/GHSA-hmw2-7cc7-3qxx\u003c/a\u003e). (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11028\"\u003e#11028\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚀 New Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eConfiguration Extensibility: Preserved own-enumerable symbol-keyed fields through mergeConfig and added a generic params type across public TypeScript declarations, responses, errors,\nadapters, and serializers. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11043\"\u003e#11043\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11081\"\u003e#11081\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHeader Parameter Parsing: Added the opt-in AxiosHeaders.parseParameters() parser for quote-aware, RFC-style HTTP parameter parsing while preserving legacy parsing behavior. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11051\"\u003e#11051\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHTTP Status Codes: Added the missing Cloudflare 520 WebServerReturnsAnUnknownError status and matching ESM/CJS declarations. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11067\"\u003e#11067\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eForm Data Conversion: Limited formDataToJSON path splitting to dot and bracket notation, preserving literal punctuation in keys, and removed browser-facing Buffer.from usage from toFormData to avoid unnecessary polyfills. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11006\"\u003e#11006\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11018\"\u003e#11018\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eProxy Bypass: Canonicalized IPv4 shorthand, octal, and hexadecimal forms during NO_PROXY matching and honored * entries within comma- or space-separated bypass lists. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11029\"\u003e#11029\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11053\"\u003e#11053\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eCancellation: Propagated already-aborted input signals immediately when composing abort signals. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11035\"\u003e#11035\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eHeader Handling: Preserved empty first values for duplicate singleton headers and made AxiosHeaders#getSetCookie() consistently return arrays for present values. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11036\"\u003e#11036\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11037\"\u003e#11037\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eURL Handling: Included normalized, safely redacted offending URLs in malformed-protocol errors and removed repeated trailing slashes when combining base URLs. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11008\"\u003e#11008\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11038\"\u003e#11038\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eProgress Events: Clamped malformed negative progress values to zero and ensured final Node.js download progress events are delivered before streamed responses close. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11039\"\u003e#11039\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11040\"\u003e#11040\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eError and JSON Serialization: Serialized Set values as arrays in JSON-compatible snapshots and synthesized useful AxiosError messages from otherwise-empty AggregateError instances. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11044\"\u003e#11044\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11059\"\u003e#11059\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eContent-Length Enforcement: Corrected base64 data: URL size estimation so maxContentLength is enforced consistently by the HTTP and Fetch adapters. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11061\"\u003e#11061\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSynchronous Interceptors: Prevented requests from being dispatched after synchronous request interceptors fail unless their paired rejection handler resolves successfully. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11071\"\u003e#11071\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔧 Maintenance \u0026amp; Chores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDependencies: Updated development and test tooling, the docs fixture's Axios version, and GitHub Actions integrations including Checkout, Setup Node, Setup Deno, and Zizmor. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11031\"\u003e#11031\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11055\"\u003e#11055\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11056\"\u003e#11056\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11058\"\u003e#11058\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11079\"\u003e#11079\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11080\"\u003e#11080\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11088\"\u003e#11088\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11089\"\u003e#11089\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11090\"\u003e#11090\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBuild Outputs: Limited sourcemap generation to published minified bundles, removing broken map references from non-minified builds. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11054\"\u003e#11054\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eForm Data Internals: Centralized FormData header handling and made the Node.js adapter tolerate getHeaders() returning undefined under the content-only policy. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11062\"\u003e#11062\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeveloper Experience: Ignored common local AI-tooling directories and fixed a constant-reassignment crash when the development sandbox serves its root path. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11032\"\u003e#11032\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11073\"\u003e#11073\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDocumentation: Updated sponsor information, clarified that baseURL is not a path-security boundary, scoped provenance claims to attested releases, and corrected the configuration-defaults documentation. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11041\"\u003e#11041\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11068\"\u003e#11068\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11076\"\u003e#11076\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11078\"\u003e#11078\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePublishing: Simplified v1 publishing to use the npm version bundled with Node.js 26 and updated package metadata for the 1.19.0 release. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11083\"\u003e#11083\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11095\"\u003e#11095\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🌟 New Contributors\u003c/h2\u003e\n\u003cp\u003eWe are thrilled to welcome our new contributors. Thank you for helping improve Axios:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/afonsojramos\"\u003e\u003ccode\u003e@​afonsojramos\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11028\"\u003e#11028\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11006\"\u003e#11006\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yassertawfik4\"\u003e\u003ccode\u003e@​yassertawfik4\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11024\"\u003e#11024\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AnandSundar\"\u003e\u003ccode\u003e@​AnandSundar\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11029\"\u003e#11029\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lin-hongkuan\"\u003e\u003ccode\u003e@​lin-hongkuan\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11035\"\u003e#11035\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Wali007-lab\"\u003e\u003ccode\u003e@​Wali007-lab\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11054\"\u003e#11054\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/magicdawn\"\u003e\u003ccode\u003e@​magicdawn\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11043\"\u003e#11043\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/84a9f3b9a4f3244b8c8e818f557d64c7b964fb25\"\u003e\u003ccode\u003e84a9f3b\u003c/code\u003e\u003c/a\u003e chore(release): prepare release 1.20.0 (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11152\"\u003e#11152\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/e6824eec5fcf9da467a9792724396badc490c469\"\u003e\u003ccode\u003ee6824ee\u003c/code\u003e\u003c/a\u003e fix: core methodList, HTTP adapter errors, and add tests (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11096\"\u003e#11096\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/d8a919fd81403d59058c0e9dbefc540407dee83f\"\u003e\u003ccode\u003ed8a919f\u003c/code\u003e\u003c/a\u003e fix(xhr): flush final progress during the live loadend dispatch (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11121\"\u003e#11121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/2d2a21af8a433089474a2149781799c93acbcf3c\"\u003e\u003ccode\u003e2d2a21a\u003c/code\u003e\u003c/a\u003e fix(interceptors): tolerate nullish handlers in syncHandlerEntries (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11118\"\u003e#11118\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a\"\u003e\u003ccode\u003ed19040b\u003c/code\u003e\u003c/a\u003e fix: harden runtime option handling (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11141\"\u003e#11141\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/e0a02dd16671deabe2b809334d4c2ebede29a233\"\u003e\u003ccode\u003ee0a02dd\u003c/code\u003e\u003c/a\u003e chore(deps): bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 in the github-...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/d10cb3aa3cda1d78721ddf96be590478df26cd81\"\u003e\u003ccode\u003ed10cb3a\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump the development_dependencies group with 4 updates (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11143\"\u003e#11143\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/2c94646eb7cb7ab9dcb2aefdb04ab1b040c28e16\"\u003e\u003ccode\u003e2c94646\u003c/code\u003e\u003c/a\u003e chore(deps): bump js-yaml and mocha in /tests/smoke/cjs (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11133\"\u003e#11133\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/76c12bce5a4fe9a45bef9a5bf2baaf599d7d382e\"\u003e\u003ccode\u003e76c12bc\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump js-yaml from 4.3.0 to 4.3.1 (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11140\"\u003e#11140\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/ba98559a7f5a18e531b5762387e5957bd281af3d\"\u003e\u003ccode\u003eba98559\u003c/code\u003e\u003c/a\u003e docs: add ScrapingBee sponsor (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11137\"\u003e#11137\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/axios/axios/compare/v1.15.0...v1.20.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `maplibre-gl` from 4.7.1 to 6.9.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/maplibre/maplibre-gl-js/releases\"\u003emaplibre-gl's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.9.0\u003c/h2\u003e\n\u003ch3\u003e✨ Features and improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImproved support for drawing the letters of Devanagari, Khmer, Burmese and the other complex scripts and also draws Arabic and Hebrew labels correctly without loading a right-to-left text plugin, which deprecates \u003ccode\u003esetRTLTextPlugin\u003c/code\u003e and \u003ccode\u003egetRTLTextPluginStatus\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8343\"\u003e#8343\u003c/a\u003e) (by \u003ca href=\"https://github.com/HarelM\"\u003e\u003ccode\u003e@​HarelM\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRead sprite and image pixels back through an \u003ccode\u003eOffscreenCanvas\u003c/code\u003e where available, removing a main-thread stall of tens of milliseconds on GPU-accelerated browsers when a sprite loads (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8339\"\u003e#8339\u003c/a\u003e) (by \u003ca href=\"https://github.com/cherenkov\"\u003e\u003ccode\u003e@​cherenkov\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSkip clipping masks for layers hidden at the current zoom and stop re-binding dynamic buffers on cached vertex array binds, removing redundant WebGL calls every frame (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8369\"\u003e#8369\u003c/a\u003e) (by \u003ca href=\"https://github.com/johncarmack1984\"\u003e\u003ccode\u003e@​johncarmack1984\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRe-render at most one stale terrain drape per frame and keep drapes that differ only by zoom while the map moves, so a finger lift over terrain no longer re-renders every tile at once (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8368\"\u003e#8368\u003c/a\u003e) (by \u003ca href=\"https://github.com/johncarmack1984\"\u003e\u003ccode\u003e@​johncarmack1984\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🐞 Bug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003esetStyle()\u003c/code\u003e throwing while terrain is still loading because an intermediate render tried to compile a terrain shader before the replacement style initialized its projection (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/6824\"\u003e#6824\u003c/a\u003e) (by \u003ca href=\"https://github.com/miakh\"\u003e\u003ccode\u003e@​miakh\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix queued GeoJSON \u003ccode\u003eupdateData\u003c/code\u003e property removals throwing after geometry-only updates or retaining previously updated values (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8372\"\u003e#8372\u003c/a\u003e) (by \u003ca href=\"https://github.com/jokrasno\"\u003e\u003ccode\u003e@​jokrasno\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eTreat camera options passed as \u003ccode\u003eundefined\u003c/code\u003e as not given in \u003ccode\u003ejumpTo\u003c/code\u003e, \u003ccode\u003eeaseTo\u003c/code\u003e and \u003ccode\u003eflyTo\u003c/code\u003e; they were coerced to NaN (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8373\"\u003e#8373\u003c/a\u003e) (by \u003ca href=\"https://github.com/vlumi\"\u003e\u003ccode\u003e@​vlumi\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix a \u003ccode\u003eNot implemented.\u003c/code\u003e error that broke panning and zooming when the projection was changed while the camera was moving, on maps with terrain enabled or a \u003ccode\u003etransformCameraUpdate\u003c/code\u003e callback (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8351\"\u003e#8351\u003c/a\u003e) (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix a map created inside a hidden container staying at the \u003ccode\u003e400x300\u003c/code\u003e fallback size when the container is shown before the resize observer's first notification is delivered (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8277\"\u003e#8277\u003c/a\u003e) (by \u003ca href=\"https://github.com/spliffone\"\u003e\u003ccode\u003e@​spliffone\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eMercatorTransform\u003c/code\u003e throwing when it is resized to a zero width, and skip the matrix calculation of every projection while the transform has a zero width or height (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8374\"\u003e#8374\u003c/a\u003e) (by \u003ca href=\"https://github.com/avosa\"\u003e\u003ccode\u003e@​avosa\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix every style update opening a redundant sky and light transition, which kept \u003ccode\u003eidle\u003c/code\u003e from firing for the transition duration after the map was otherwise done, and could ease the sky and the light on a different curve from the layers (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8348\"\u003e#8348\u003c/a\u003e) (by \u003ca href=\"https://github.com/cherenkov\"\u003e\u003ccode\u003e@​cherenkov\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix DOM sanitization for iframe and srcdoc (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8396\"\u003e#8396\u003c/a\u003e) (by \u003ca href=\"https://github.com/HarelM\"\u003e\u003ccode\u003e@​HarelM\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.8.0\u003c/h2\u003e\n\u003ch3\u003e✨ Features and improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003emap.getStyleUrl()\u003c/code\u003e, which returns the URL the style was loaded from, or \u003ccode\u003enull\u003c/code\u003e when the style was given as an object (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/7109\"\u003e#7109\u003c/a\u003e) (by \u003ca href=\"https://github.com/bradymadden97\"\u003e\u003ccode\u003e@​bradymadden97\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/giswqs\"\u003e\u003ccode\u003e@​giswqs\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSample terrain render-to-texture output through mipmaps with trilinear filtering, so draped layers stop shimmering and aliasing at high pitch (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8328\"\u003e#8328\u003c/a\u003e, continues \u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/7673\"\u003e#7673\u003c/a\u003e) (by \u003ca href=\"https://github.com/AveryanAlex\"\u003e\u003ccode\u003e@​AveryanAlex\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBuild the \u003ccode\u003eIntl.Segmenter\u003c/code\u003e instances used for text shaping on first use instead of at import, shaving several milliseconds off loading MapLibre on the main thread (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8337\"\u003e#8337\u003c/a\u003e) (by \u003ca href=\"https://github.com/cherenkov\"\u003e\u003ccode\u003e@​cherenkov\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eLink shader programs before reading their compile status, so the driver can overlap the compiles and the main thread waits less on shader compilation (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8338\"\u003e#8338\u003c/a\u003e) (by \u003ca href=\"https://github.com/cherenkov\"\u003e\u003ccode\u003e@​cherenkov\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBuild the default \u003ccode\u003eMarker\u003c/code\u003e pin once and clone it per marker, so creating many default markers takes roughly half the constructor time (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8340\"\u003e#8340\u003c/a\u003e) (by \u003ca href=\"https://github.com/cherenkov\"\u003e\u003ccode\u003e@​cherenkov\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd SDF rendering support for fill patterns, using \u003ccode\u003efill-color\u003c/code\u003e as the foreground color (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/7747\"\u003e#7747\u003c/a\u003e) (by \u003ca href=\"https://github.com/bradymadden97\"\u003e\u003ccode\u003e@​bradymadden97\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/deniial00\"\u003e\u003ccode\u003e@​deniial00\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eWarn once when the canvas is clamped to \u003ccode\u003emaxCanvasSize\u003c/code\u003e, which previously lowered the rendered resolution silently (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8200\"\u003e#8200\u003c/a\u003e) (by \u003ca href=\"https://github.com/str0kes\"\u003e\u003ccode\u003e@​str0kes\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🐞 Bug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix a marker's popup jumping to another world copy when the marker is moved across the antimeridian on a zoomed-out map (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/5655\"\u003e#5655\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8326\"\u003e#8326\u003c/a\u003e, continues \u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/5956\"\u003e#5956\u003c/a\u003e) (by \u003ca href=\"https://github.com/yuiseki\"\u003e\u003ccode\u003e@​yuiseki\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix terrain drape textures not being refreshed after zoom changes, causing stale rendering at the new zoom level (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8251\"\u003e#8251\u003c/a\u003e) (by \u003ca href=\"https://github.com/patte\"\u003e\u003ccode\u003e@​patte\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix a gap between the sky and the ground at high pitch while globe transitions to mercator (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/7382\"\u003e#7382\u003c/a\u003e) (by \u003ca href=\"https://github.com/birkskyum\"\u003e\u003ccode\u003e@​birkskyum\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eTreat an empty tile response (e.g. HTTP 204) as no data: raster-DEM tiles now load without elevation instead of failing with a \u003ccode\u003edem dimension mismatch\u003c/code\u003e error, and empty raster tiles render as transparent (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/1551\"\u003e#1551\u003c/a\u003e) (by \u003ca href=\"https://github.com/clement-igonet\"\u003e\u003ccode\u003e@​clement-igonet\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eValidate the \u003ccode\u003ebefore\u003c/code\u003e layer in \u003ccode\u003emap.moveLayer\u003c/code\u003e before reordering, so passing the id of a layer that does not exist leaves the layer order untouched instead of dropping the moved layer out of it (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8301\"\u003e#8301\u003c/a\u003e) (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix visible seams between hillshade tiles when using linear interpolation. (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8302\"\u003e#8302\u003c/a\u003e) (by \u003ca href=\"https://github.com/Turbo87\"\u003e\u003ccode\u003e@​Turbo87\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix the map freezing when a render task throws an error (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/6093\"\u003e#6093\u003c/a\u003e) (by \u003ca href=\"https://github.com/UberMouse\"\u003e\u003ccode\u003e@​UberMouse\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003egetCameraAltitude()\u003c/code\u003e returning \u003ccode\u003eNaN\u003c/code\u003e under \u003ccode\u003eglobe\u003c/code\u003e and \u003ccode\u003evertical-perspective\u003c/code\u003e, which disabled marker terrain occlusion and the camera terrain check; the altitude now follows the sphere (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/6584\"\u003e#6584\u003c/a\u003e) (by \u003ca href=\"https://github.com/bigmistqke\"\u003e\u003ccode\u003e@​bigmistqke\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/patte\"\u003e\u003ccode\u003e@​patte\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDraw an elevated symbol on globe when the symbol itself is in view but the ground under it is behind the horizon; occlusion now follows the line of sight to the elevated point (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8253\"\u003e#8253\u003c/a\u003e) (by \u003ca href=\"https://github.com/clement-igonet\"\u003e\u003ccode\u003e@​clement-igonet\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003esetTiles\u003c/code\u003e producing stale tile URLs when \u003ccode\u003eloadTile\u003c/code\u003e runs in the same frame (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8323\"\u003e#8323\u003c/a\u003e) (by \u003ca href=\"https://github.com/johncarmack1984\"\u003e\u003ccode\u003e@​johncarmack1984\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/nostrorom\"\u003e\u003ccode\u003e@​nostrorom\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eKeep the tile under an elevated symbol from being culled near the horizon, so a symbol with a large \u003ccode\u003esymbol-height-offset\u003c/code\u003e stays visible until it is behind the planet (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8316\"\u003e#8316\u003c/a\u003e) (by \u003ca href=\"https://github.com/clement-igonet\"\u003e\u003ccode\u003e@​clement-igonet\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.7.0\u003c/h2\u003e\n\u003ch3\u003e✨ Features and improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport the style specification's \u003ccode\u003efont-faces\u003c/code\u003e property, with \u003ccode\u003emap.setFontFaces\u003c/code\u003e and \u003ccode\u003emap.getFontFaces\u003c/code\u003e and improve complex script languages such as Devanagari, Khmer, Burmese and Hebrew (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8237\"\u003e#8237\u003c/a\u003e)  (by \u003ca href=\"https://github.com/HarelM\"\u003e\u003ccode\u003e@​HarelM\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/maplibre/maplibre-gl-js/blob/main/CHANGELOG.md\"\u003emaplibre-gl's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e6.9.0\u003c/h2\u003e\n\u003ch3\u003e✨ Features and improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImproved support for drawing the letters of Devanagari, Khmer, Burmese and the other complex scripts and also draws Arabic and Hebrew labels correctly without loading a right-to-left text plugin, which deprecates \u003ccode\u003esetRTLTextPlugin\u003c/code\u003e and \u003ccode\u003egetRTLTextPluginStatus\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8343\"\u003e#8343\u003c/a\u003e) (by \u003ca href=\"https://github.com/HarelM\"\u003e\u003ccode\u003e@​HarelM\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRead sprite and image pixels back through an \u003ccode\u003eOffscreenCanvas\u003c/code\u003e where available, removing a main-thread stall of tens of milliseconds on GPU-accelerated browsers when a sprite loads (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8339\"\u003e#8339\u003c/a\u003e) (by \u003ca href=\"https://github.com/cherenkov\"\u003e\u003ccode\u003e@​cherenkov\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSkip clipping masks for layers hidden at the current zoom and stop re-binding dynamic buffers on cached vertex array binds, removing redundant WebGL calls every frame (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8369\"\u003e#8369\u003c/a\u003e) (by \u003ca href=\"https://github.com/johncarmack1984\"\u003e\u003ccode\u003e@​johncarmack1984\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRe-render at most one stale terrain drape per frame and keep drapes that differ only by zoom while the map moves, so a finger lift over terrain no longer re-renders every tile at once (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8368\"\u003e#8368\u003c/a\u003e) (by \u003ca href=\"https://github.com/johncarmack1984\"\u003e\u003ccode\u003e@​johncarmack1984\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🐞 Bug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003esetStyle()\u003c/code\u003e throwing while terrain is still loading because an intermediate render tried to compile a terrain shader before the replacement style initialized its projection (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/6824\"\u003e#6824\u003c/a\u003e) (by \u003ca href=\"https://github.com/miakh\"\u003e\u003ccode\u003e@​miakh\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix queued GeoJSON \u003ccode\u003eupdateData\u003c/code\u003e property removals throwing after geometry-only updates or retaining previously updated values (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8372\"\u003e#8372\u003c/a\u003e) (by \u003ca href=\"https://github.com/jokrasno\"\u003e\u003ccode\u003e@​jokrasno\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eTreat camera options passed as \u003ccode\u003eundefined\u003c/code\u003e as not given in \u003ccode\u003ejumpTo\u003c/code\u003e, \u003ccode\u003eeaseTo\u003c/code\u003e and \u003ccode\u003eflyTo\u003c/code\u003e; they were coerced to NaN (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8373\"\u003e#8373\u003c/a\u003e) (by \u003ca href=\"https://github.com/vlumi\"\u003e\u003ccode\u003e@​vlumi\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix a \u003ccode\u003eNot implemented.\u003c/code\u003e error that broke panning and zooming when the projection was changed while the camera was moving, on maps with terrain enabled or a \u003ccode\u003etransformCameraUpdate\u003c/code\u003e callback (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8351\"\u003e#8351\u003c/a\u003e) (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix a map created inside a hidden container staying at the \u003ccode\u003e400x300\u003c/code\u003e fallback size when the container is shown before the resize observer's first notification is delivered (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8277\"\u003e#8277\u003c/a\u003e) (by \u003ca href=\"https://github.com/spliffone\"\u003e\u003ccode\u003e@​spliffone\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eMercatorTransform\u003c/code\u003e throwing when it is resized to a zero width, and skip the matrix calculation of every projection while the transform has a zero width or height (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8374\"\u003e#8374\u003c/a\u003e) (by \u003ca href=\"https://github.com/avosa\"\u003e\u003ccode\u003e@​avosa\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix every style update opening a redundant sky and light transition, which kept \u003ccode\u003eidle\u003c/code\u003e from firing for the transition duration after the map was otherwise done, and could ease the sky and the light on a different curve from the layers (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8348\"\u003e#8348\u003c/a\u003e) (by \u003ca href=\"https://github.com/cherenkov\"\u003e\u003ccode\u003e@​cherenkov\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix DOM sanitization for iframe and srcdoc (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8396\"\u003e#8396\u003c/a\u003e) (by \u003ca href=\"https://github.com/HarelM\"\u003e\u003ccode\u003e@​HarelM\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e6.8.0\u003c/h2\u003e\n\u003ch3\u003e✨ Features and improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003emap.getStyleUrl()\u003c/code\u003e, which returns the URL the style was loaded from, or \u003ccode\u003enull\u003c/code\u003e when the style was given as an object (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/7109\"\u003e#7109\u003c/a\u003e) (by \u003ca href=\"https://github.com/bradymadden97\"\u003e\u003ccode\u003e@​bradymadden97\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/giswqs\"\u003e\u003ccode\u003e@​giswqs\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSample terrain render-to-texture output through mipmaps with trilinear filtering, so draped layers stop shimmering and aliasing at high pitch (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8328\"\u003e#8328\u003c/a\u003e, continues \u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/7673\"\u003e#7673\u003c/a\u003e) (by \u003ca href=\"https://github.com/AveryanAlex\"\u003e\u003ccode\u003e@​AveryanAlex\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBuild the \u003ccode\u003eIntl.Segmenter\u003c/code\u003e instances used for text shaping on first use instead of at import, shaving several milliseconds off loading MapLibre on the main thread (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8337\"\u003e#8337\u003c/a\u003e) (by \u003ca href=\"https://github.com/cherenkov\"\u003e\u003ccode\u003e@​cherenkov\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eLink shader programs before reading their compile status, so the driver can overlap the compiles and the main thread waits less on shader compilation (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8338\"\u003e#8338\u003c/a\u003e) (by \u003ca href=\"https://github.com/cherenkov\"\u003e\u003ccode\u003e@​cherenkov\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBuild the default \u003ccode\u003eMarker\u003c/code\u003e pin once and clone it per marker, so creating many default markers takes roughly half the constructor time (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8340\"\u003e#8340\u003c/a\u003e) (by \u003ca href=\"https://github.com/cherenkov\"\u003e\u003ccode\u003e@​cherenkov\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd SDF rendering support for fill patterns, using \u003ccode\u003efill-color\u003c/code\u003e as the foreground color (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/7747\"\u003e#7747\u003c/a\u003e) (by \u003ca href=\"https://github.com/bradymadden97\"\u003e\u003ccode\u003e@​bradymadden97\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/deniial00\"\u003e\u003ccode\u003e@​deniial00\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eWarn once when the canvas is clamped to \u003ccode\u003emaxCanvasSize\u003c/code\u003e, which previously lowered the rendered resolution silently (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8200\"\u003e#8200\u003c/a\u003e) (by \u003ca href=\"https://github.com/str0kes\"\u003e\u003ccode\u003e@​str0kes\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🐞 Bug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix a marker's popup jumping to another world copy when the marker is moved across the antimeridian on a zoomed-out map (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/5655\"\u003e#5655\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8326\"\u003e#8326\u003c/a\u003e, continues \u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/5956\"\u003e#5956\u003c/a\u003e) (by \u003ca href=\"https://github.com/yuiseki\"\u003e\u003ccode\u003e@​yuiseki\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix terrain drape textures not being refreshed after zoom changes, causing stale rendering at the new zoom level (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8251\"\u003e#8251\u003c/a\u003e) (by \u003ca href=\"https://github.com/patte\"\u003e\u003ccode\u003e@​patte\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix a gap between the sky and the ground at high pitch while globe transitions to mercator (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/7382\"\u003e#7382\u003c/a\u003e) (by \u003ca href=\"https://github.com/birkskyum\"\u003e\u003ccode\u003e@​birkskyum\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eTreat an empty tile response (e.g. HTTP 204) as no data: raster-DEM tiles now load without elevation instead of failing with a \u003ccode\u003edem dimension mismatch\u003c/code\u003e error, and empty raster tiles render as transparent (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/1551\"\u003e#1551\u003c/a\u003e) (by \u003ca href=\"https://github.com/clement-igonet\"\u003e\u003ccode\u003e@​clement-igonet\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRead the map container's dimensions before mutating it in \u003ccode\u003eMap#_setupContainer\u003c/code\u003e, avoiding a forced synchronous layout reflow on every map initialization (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8307\"\u003e#8307\u003c/a\u003e) (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eValidate the \u003ccode\u003ebefore\u003c/code\u003e layer in \u003ccode\u003emap.moveLayer\u003c/code\u003e before reordering, so passing the id of a layer that does not exist leaves the layer order untouched instead of dropping the moved layer out of it (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8301\"\u003e#8301\u003c/a\u003e) (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix visible seams between hillshade tiles when using linear interpolation. (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8302\"\u003e#8302\u003c/a\u003e) (by \u003ca href=\"https://github.com/Turbo87\"\u003e\u003ccode\u003e@​Turbo87\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix the map freezing when a render task throws an error (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/6093\"\u003e#6093\u003c/a\u003e) (by \u003ca href=\"https://github.com/UberMouse\"\u003e\u003ccode\u003e@​UberMouse\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003egetCameraAltitude()\u003c/code\u003e returning \u003ccode\u003eNaN\u003c/code\u003e under \u003ccode\u003eglobe\u003c/code\u003e and \u003ccode\u003evertical-perspective\u003c/code\u003e, which disabled marker terrain occlusion and the camera terrain check; the altitude now follows the sphere (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/6584\"\u003e#6584\u003c/a\u003e) (by \u003ca href=\"https://github.com/bigmistqke\"\u003e\u003ccode\u003e@​bigmistqke\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/patte\"\u003e\u003ccode\u003e@​patte\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDraw an elevated symbol on globe when the symbol itself is in view but the ground under it is behind the horizon; occlusion now follows the line of sight to the elevated point (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8253\"\u003e#8253\u003c/a\u003e) (by \u003ca href=\"https://github.com/clement-igonet\"\u003e\u003ccode\u003e@​clement-igonet\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003esetTiles\u003c/code\u003e producing stale tile URLs when \u003ccode\u003eloadTile\u003c/code\u003e runs in the same frame (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8323\"\u003e#8323\u003c/a\u003e) (by \u003ca href=\"https://github.com/johncarmack1984\"\u003e\u003ccode\u003e@​johncarmack1984\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/nostrorom\"\u003e\u003ccode\u003e@​nostrorom\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eKeep the tile under an elevated symbol from being culled near the horizon, so a symbol with a large \u003ccode\u003esymbol-height-offset\u003c/code\u003e stays visible until it is behind the planet (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8316\"\u003e#8316\u003c/a\u003e) (by \u003ca href=\"https://github.com/clement-igonet\"\u003e\u003ccode\u003e@​clement-igonet\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e6.7.0\u003c/h2\u003e\n\u003ch3\u003e✨ Features and improvements\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maplibre/maplibre-gl-js/commit/f985318d1fa7e01d8b7e32a719aaf91efcb348d4\"\u003e\u003ccode\u003ef985318\u003c/code\u003e\u003c/a\u003e Bump js version to 6.9.0 (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8398\"\u003e#8398\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maplibre/maplibre-gl-js/commit/b51d10a7b0bff4ffe4480b9e26b4ebe57461b928\"\u003e\u003ccode\u003eb51d10a\u003c/code\u003e\u003c/a\u003e improve sanitization (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8396\"\u003e#8396\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maplibre/maplibre-gl-js/commit/36034010e11c5cf9a9d1f10bcb4b5306dab14ba1\"\u003e\u003ccode\u003e3603401\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump cssnano from 9.0.2 to 9.0.3 (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8390\"\u003e#8390\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maplibre/maplibre-gl-js/commit/3e3c447168f00dd82485fa5b27b6e7d90d6f705e\"\u003e\u003ccode\u003e3e3c447\u003c/code\u003e\u003c/a\u003e chore(deps): bump \u003ccode\u003e@​maplibre/maplibre-gl-style-spec\u003c/code\u003e from 26.4.1 to 26.4.2 (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8391\"\u003e#8391\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maplibre/maplibre-gl-js/commit/ea9f7df5e374a65401ddf388a54158d0b59b2e97\"\u003e\u003ccode\u003eea9f7df\u003c/code\u003e\u003c/a\u003e chore(deps): bump zensical/zensical from 0.0.59 to 0.0.60 (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8392\"\u003e#8392\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maplibre/maplibre-gl-js/commit/ce10d220875eac604ee5c646e9b17680d7e182ed\"\u003e\u003ccode\u003ece10d22\u003c/code\u003e\u003c/a\u003e feat: add bidi support and deprecate RTL plugin (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8343\"\u003e#8343\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maplibre/maplibre-gl-js/commit/86901c5b7f638c201928e3e7ccea08200718ff3e\"\u003e\u003ccode\u003e86901c5\u003c/code\u003e\u003c/a\u003e fix: stop re-opening sky and light transitions on every style update (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8350\"\u003e#8350\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maplibre/maplibre-gl-js/commit/54dfab1e186e72fc43bc319cab97c5427f80a0f3\"\u003e\u003ccode\u003e54dfab1\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump \u003ccode\u003e@​types/node\u003c/code\u003e from 26.4.0 to 26.4.1 (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8352\"\u003e#8352\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maplibre/maplibre-gl-js/commit/209e34203b2ac001d022334471182a1d06c5b2b0\"\u003e\u003ccode\u003e209e342\u003c/code\u003e\u003c/a\u003e perf: skip hidden layers before their clipping masks and drop the dynamic buf...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maplibre/maplibre-gl-js/commit/71a12d8c37a052eec276f3ad93ae8cc5b8a92f15\"\u003e\u003ccode\u003e71a12d8\u003c/code\u003e\u003c/a\u003e fix: skip terrain drawing until replacement projection is ready (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8258\"\u003e#8258\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/maplibre/maplibre-gl-js/compare/v4.7.1...v6.9.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for maplibre-gl since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `mysql2` from 3.16.2 to 3.23.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/sidorares/node-mysql2/releases\"\u003emysql2's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.23.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/sidorares/node-mysql2/compare/v3.23.0...v3.23.1\"\u003e3.23.1\u003c/a\u003e (2026-07-19)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003esecurity:\u003c/strong\u003e fix unb...\n\n_Description has been truncated_\n\n\u003c!-- This is an auto-generated description by cubic. --\u003e\n---\n## Summary by cubic\nUpdates 25 npm dependencies across three projects: `project-nomad-evez/admin`, `quantumseal-api`, and `spectrumscan-api`. Includes security fixes and major version bumps that may require code changes.\n\n**Breaking changes**\n- `maplibre-gl` jumps from 4.7.1 to 6.9.0; review API changes and the deprecation of `setRTLTextPlugin`.\n- `@adonisjs/auth`, `@adonisjs/lucid`, and `@adonisjs/session` move to new major versions; check for breaking changes.\n- `axios` deprecates `PayloadTooLarge` and `UnprocessableEntity` aliases in favor of new status-code names.\n\n**Security fixes**\n- `body-parser` updated to 1.20.8 to address CVE-2026-12590.\n\n\u003csup\u003eWritten for commit d674c7e55e26876327e54b4df0520c06125529db. Summary will update on new commits.\u003c/sup\u003e\n\n\u003ca href=\"https://cubic.dev/pr/EvezArt/evez-ai/pull/4?utm_source=github\" target=\"_blank\" rel=\"noopener noreferrer\" data-no-image-dialog=\"true\"\u003e\u003cpicture\u003e\u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-light.svg\"\u003e\u003cimg alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003c/picture\u003e\u003c/a\u003e\n\n\u003c!-- End of auto-generated description by cubic. --\u003e\n\n","html_url":"https://github.com/EvezArt/evez-ai/pull/4","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/EvezArt%2Fevez-ai/issues/4","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/4/packages"},{"uuid":"5431254857","node_id":"PR_kwDOOgwg5c8AAAABDOnHxQ","number":1170,"state":"open","title":"build(deps-dev): Bump undici from 8.10.0 to 8.10.2 in the evals group across 1 directory","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-12T04:58:10.000Z","updated_at":"2026-09-12T05:06:06.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps-dev): Bump","packages":[{"name":"undici","old_version":"8.10.0","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"}],"path":"the evals group across 1 directory","ecosystem":"npm"},"body":"Bumps the evals group with 1 update in the / directory: [undici](https://github.com/nodejs/undici).\n\nUpdates `undici` from 8.10.0 to 8.10.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm\"\u003eGHSA-vp8m-p9jh-q5pm\u003c/a\u003e: cache and deduplication interceptors could use caller-controlled request metadata instead of the authoritative dispatcher origin, enabling cross-origin cache poisoning and data disclosure. Undici now derives interceptor identities from the dispatcher origin and bypasses origin-dependent interceptors when no authoritative origin exists. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/caf6194d3dae989b731ed87ab85f182befe5eb80\"\u003ecaf6194d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e8f5868fb\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e66e12816\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6\"\u003e4411a238\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/662d0ea671fe64139e79533c913fce412765e1d7\"\u003e662d0ea6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003ecb75bbb3\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e7aac7f12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003ee905b5b8\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e2be07bf9\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e6d583124\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e0160a719\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps-dev): bump undici from 6.27.0 to 6.28.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5653\"\u003enodejs/undici#5653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump jest from 30.4.2 to 30.5.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5750\"\u003enodejs/undici#5750\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/analyze from 4.37.3 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5752\"\u003enodejs/undici#5752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5754\"\u003enodejs/undici#5754\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(h2): cover stream reset with NGHTTP2_INTERNAL_ERROR by \u003ca href=\"https://github.com/zeexzeex\"\u003e\u003ccode\u003e@​zeexzeex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5725\"\u003enodejs/undici#5725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): reject invalid resumed responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5724\"\u003enodejs/undici#5724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: make stale-while-revalidate cache update test deterministic by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5722\"\u003enodejs/undici#5722\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid unbounded recursion in Set-Cookie attribute parser by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5757\"\u003enodejs/undici#5757\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: honor SOCKS5 connection timeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5733\"\u003enodejs/undici#5733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(eventsource): validate Last-Event-ID on reconnect by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5746\"\u003enodejs/undici#5746\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid duplicate release attempts by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5745\"\u003enodejs/undici#5745\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(cache): refetch when 304 adds vary fields by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5732\"\u003enodejs/undici#5732\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etypes: expose PendingInterceptor and PendingInterceptorsFormatter on the MockAgent namespace by \u003ca href=\"https://github.com/RaphaelFakhri\"\u003e\u003ccode\u003e@​RaphaelFakhri\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5721\"\u003enodejs/undici#5721\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(codeql): align CodeQL action versions to v4.37.9 by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5759\"\u003enodejs/undici#5759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5760\"\u003enodejs/undici#5760\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(proxy-agent): guard Proxy-Authorization in iterable header containers by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5758\"\u003enodejs/undici#5758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: name the parameters these two blocks describe by \u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): fail the connection on a non-200 h2 extended CONNECT response by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(node-fetch): re-enable the set-cookie header combining test by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5730\"\u003enodejs/undici#5730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward rawHeaders writes through RetryController by \u003ca href=\"https://github.com/official-burak\"\u003e\u003ccode\u003e@​official-burak\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5727\"\u003enodejs/undici#5727\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5738\"\u003enodejs/undici#5738\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/5e541e0b9df7563e5766bbd469fbfe383d9ae6ca\"\u003e\u003ccode\u003e5e541e0\u003c/code\u003e\u003c/a\u003e Bumped v8.10.2 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5771\"\u003e#5771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/eb04cc39954e63e9b46bdf824e6efad9fff2e7b5\"\u003e\u003ccode\u003eeb04cc3\u003c/code\u003e\u003c/a\u003e fix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5738\"\u003e#5738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003e\u003ccode\u003ee905b5b\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e\u003ccode\u003e0160a71\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e\u003ccode\u003e66e1281\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e\u003ccode\u003e7aac7f1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003e\u003ccode\u003ecb75bbb\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e\u003ccode\u003e6d58312\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e\u003ccode\u003e8f5868f\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e\u003ccode\u003e2be07bf\u003c/code\u003e\u003c/a\u003e fix(cache): reject unsafe method response caching\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v8.10.0...v8.10.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n","html_url":"https://github.com/adamjmurray/producer-pal/pull/1170","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/adamjmurray%2Fproducer-pal/issues/1170","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1170/packages"},{"uuid":"5430679006","node_id":"PR_kwDORo9bUM8AAAABDOKuSw","number":136,"state":"open","title":"chore(deps): bump the web group across 1 directory with 14 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-12T02:35:48.000Z","updated_at":"2026-09-12T02:35:57.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"web","update_count":14,"packages":[{"name":"@aws-sdk/client-s3","old_version":"3.1108.0","new_version":"3.1128.0","repository_url":"https://github.com/aws/aws-sdk-js-v3"},{"name":"@google/genai","old_version":"2.16.0","new_version":"2.21.0","repository_url":"https://github.com/googleapis/js-genai"},{"name":"@next/third-parties","old_version":"16.3.0","new_version":"16.3.4","repository_url":"https://github.com/vercel/next.js"},{"name":"@supabase/ssr","old_version":"0.12.4","new_version":"0.12.7","repository_url":"https://github.com/supabase/ssr"},{"name":"lucide-react","old_version":"1.31.0","new_version":"1.43.0","repository_url":"https://github.com/lucide-icons/lucide"},{"name":"next","old_version":"16.3.0","new_version":"16.3.4","repository_url":"https://github.com/vercel/next.js"},{"name":"resend","old_version":"6.19.0","new_version":"6.26.0","repository_url":"https://github.com/resend/resend-node"},{"name":"undici","old_version":"8.10.0","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"},{"name":"@types/node","old_version":"26.2.0","new_version":"26.5.0","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"@types/react-dom","old_version":"19.2.4","new_version":"19.2.7","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"postcss","old_version":"8.5.26","new_version":"8.5.28","repository_url":"https://github.com/postcss/postcss"},{"name":"supercluster","old_version":"9.0.0","new_version":"9.1.0","repository_url":"https://github.com/mapbox/supercluster"}],"path":null,"ecosystem":"npm"},"body":"Bumps the web group with 12 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) | `3.1108.0` | `3.1128.0` |\n| [@google/genai](https://github.com/googleapis/js-genai) | `2.16.0` | `2.21.0` |\n| [@next/third-parties](https://github.com/vercel/next.js/tree/HEAD/packages/third-parties) | `16.3.0` | `16.3.4` |\n| [@supabase/ssr](https://github.com/supabase/ssr) | `0.12.4` | `0.12.7` |\n| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.31.0` | `1.43.0` |\n| [next](https://github.com/vercel/next.js) | `16.3.0` | `16.3.4` |\n| [resend](https://github.com/resend/resend-node) | `6.19.0` | `6.26.0` |\n| [undici](https://github.com/nodejs/undici) | `8.10.0` | `8.10.2` |\n| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.2.0` | `26.5.0` |\n| [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom) | `19.2.4` | `19.2.7` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.26` | `8.5.28` |\n| [supercluster](https://github.com/mapbox/supercluster) | `9.0.0` | `9.1.0` |\n\n\nUpdates `@aws-sdk/client-s3` from 3.1108.0 to 3.1128.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/aws/aws-sdk-js-v3/releases\"\u003e@​aws-sdk/client-s3's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1128.0\u003c/h2\u003e\n\u003ch4\u003e3.1128.0(2026-09-08)\u003c/h4\u003e\n\u003ch5\u003eNew Features\u003c/h5\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eclients:\u003c/strong\u003e  update client endpoints as of 2026-09-08 (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/bdcc40a79ef0a6acbca6db93dd9561731b12a55a\"\u003ebdcc40a7\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-ec2:\u003c/strong\u003e  Adds the InterfaceTypes field to NetworkCardInfo in the DescribeInstanceTypes response. This field identifies the network interface types supported by each network card. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/9336e689cde8ef1f4501c7739a445328ce2ef52d\"\u003e9336e689\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-appflow:\u003c/strong\u003e  Amazon AppFlow now supports key pair (RSA private key) authentication for the Snowflake connector. You can provide a privateKey in SnowflakeConnectorProfileCredentials, and password is no longer required. This is a non-breaking, additive change available via the AWS SDK and CLI. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/ec8753ad6f2305daca3d8679a8438dceaee9b4b9\"\u003eec8753ad\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-sagemaker:\u003c/strong\u003e  Add support for InstancePreferences list for multiple instance type input support on SageMaker Training and Processing (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/45153f6cf19c4a8bc1c567ff1e7323b0c27caba4\"\u003e45153f6c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-cloudtrail:\u003c/strong\u003e  Adds support for the RecursiveLogging trail setting, which suppresses recursive events generated when CloudTrail delivers logs to a trail's destinations. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/62a43c78602be4b20d64a11380ee03163c32ae60\"\u003e62a43c78\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-s3:\u003c/strong\u003e  Adds support for Amazon S3 Object Lock variable retention.  Existing S3 APIs that support S3 Object Lock parameters now support two new parameters EventHold and EventHoldDuration at the object level, and DefaultEventHoldDuration at the bucket level. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/8b5898753d091cf7647df0a65418430e5c0ce55f\"\u003e8b589875\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-s3-control:\u003c/strong\u003e  Adds support for Amazon S3 Object Lock variable retention.  Existing S3 APIs that support S3 Object Lock parameters now support two new parameters EventHold and EventHoldDuration at the object level, and DefaultEventHoldDuration at the bucket level. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/5765b68b0ef990f91ae49d0eae48e1958991498a\"\u003e5765b68b\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-omics:\u003c/strong\u003e  Added support for session policies in AWS HealthOmics Workflows, allowing customers to scope down IAM permissions for individual workflow runs without modifying the service role. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/ad55dcd6e323df20f9add4d38e0f3b70eca8348e\"\u003ead55dcd6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-connect:\u003c/strong\u003e  Releasing workload types feature. A proper launch announcement or details will follow up. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/63ded7ae8188e0b48d0d76258964a9027b57c453\"\u003e63ded7ae\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-pinpoint-sms-voice-v2:\u003c/strong\u003e  This feature will allow customers to specify an area-code when requesting a 10DLC number. Why it matters- Customers can now select a number that matches where their business is located. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/7aac3447f181a72b79ab473d97e0797962fed13d\"\u003e7aac3447\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-mgn:\u003c/strong\u003e  This release adds support for configuring the EBS volume initialization rate and delete on termination behavior in launch configuration template (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/bb780670c3305dc44168aa18cfea57262c24287c\"\u003ebb780670\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch5\u003eBug Fixes\u003c/h5\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003elib-storage:\u003c/strong\u003e  fix symlink stream sizing and abort on part-count mismatch (\u003ca href=\"https://redirect.github.com/aws/aws-sdk-js-v3/pull/8300\"\u003e#8300\u003c/a\u003e) (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/aa58831cf57d789884e4163dcba19fb22a71851f\"\u003eaa58831c\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003eFor list of updated packages, view \u003cstrong\u003eupdated-packages.md\u003c/strong\u003e in \u003cstrong\u003eassets-3.1128.0.zip\u003c/strong\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1127.0\u003c/h2\u003e\n\u003ch4\u003e3.1127.0(2026-09-04)\u003c/h4\u003e\n\u003ch5\u003eNew Features\u003c/h5\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eclient-mediatailor:\u003c/strong\u003e  Elemental MediaTailor now supports two new Monetization Functions lifecycle hooks, Post Ads Response and Pre Manifest Insertion, and a VAST Request function type that calls a VAST or VMAP ad server. This release also adds Yield Optimization with demand from Amazon Publisher Services. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/c238a693cf4e9e9fa4bd5ad76f83caa35279ad46\"\u003ec238a693\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-service-quotas:\u003c/strong\u003e  Service Quotas adds the AdjustableAtLevel property to QuotaContext, indicating whether a quota is adjustable at the account or resource level. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/f56bdf2c0e9581a97b246204dd95b7be1028a6f9\"\u003ef56bdf2c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-bedrock:\u003c/strong\u003e  New AWS REVIEW mode as supported data retention mode for Bedrock models (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/cbd9ea9a4262cb007ed74da234d52e8feef0402f\"\u003ecbd9ea9a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-ec2:\u003c/strong\u003e  Adds support for ValidateSecurityGroupQuotasForInterface, an API that specifically authorized AWS services use to validate security group rule quotas before creating an elastic network interface. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/f51c3b3e30327dd6fa45a9b8398422c7078d905d\"\u003ef51c3b3e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003eFor list of updated packages, view \u003cstrong\u003eupdated-packages.md\u003c/strong\u003e in \u003cstrong\u003eassets-3.1127.0.zip\u003c/strong\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1126.0\u003c/h2\u003e\n\u003ch4\u003e3.1126.0(2026-09-03)\u003c/h4\u003e\n\u003ch5\u003eDocumentation Changes\u003c/h5\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eclient-sfn:\u003c/strong\u003e  Updates Step Functions API documentation around CloudTrail, Execution name reuse and sort order of ListExecutions API (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/8dda8b4b9e90ec0cca551759885ca524b8d65a91\"\u003e8dda8b4b\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-elastic-load-balancing-v2:\u003c/strong\u003e  This release adds support for sending TCP resets for Gateway Load Balancer when a flow's idle timeout expires, or when a target becomes unhealthy or is deregistered. This adds updates the CLI documentation. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/a16f16596740e5b7ee6032c4fc95fdd3a08a46e2\"\u003ea16f1659\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch5\u003eNew Features\u003c/h5\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md\"\u003e@​aws-sdk/client-s3's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/compare/v3.1127.0...v3.1128.0\"\u003e3.1128.0\u003c/a\u003e (2026-09-08)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eclient-s3:\u003c/strong\u003e Adds support for Amazon S3 Object Lock variable retention.  Existing S3 APIs that support S3 Object Lock parameters now support two new parameters EventHold and EventHoldDuration at the object level, and DefaultEventHoldDuration at the bucket level. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/8b5898753d091cf7647df0a65418430e5c0ce55f\"\u003e8b58987\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/compare/v3.1126.0...v3.1127.0\"\u003e3.1127.0\u003c/a\u003e (2026-09-04)\u003c/h1\u003e\n\u003cp\u003e\u003cstrong\u003eNote:\u003c/strong\u003e Version bump only for package \u003ccode\u003e@​aws-sdk/client-s3\u003c/code\u003e\u003c/p\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/compare/v3.1125.0...v3.1126.0\"\u003e3.1126.0\u003c/a\u003e (2026-09-03)\u003c/h1\u003e\n\u003cp\u003e\u003cstrong\u003eNote:\u003c/strong\u003e Version bump only for package \u003ccode\u003e@​aws-sdk/client-s3\u003c/code\u003e\u003c/p\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/compare/v3.1124.0...v3.1125.0\"\u003e3.1125.0\u003c/a\u003e (2026-09-02)\u003c/h1\u003e\n\u003cp\u003e\u003cstrong\u003eNote:\u003c/strong\u003e Version bump only for package \u003ccode\u003e@​aws-sdk/client-s3\u003c/code\u003e\u003c/p\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/compare/v3.1123.0...v3.1124.0\"\u003e3.1124.0\u003c/a\u003e (2026-09-01)\u003c/h1\u003e\n\u003cp\u003e\u003cstrong\u003eNote:\u003c/strong\u003e Version bump only for package \u003ccode\u003e@​aws-sdk/client-s3\u003c/code\u003e\u003c/p\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/compare/v3.1122.0...v3.1123.0\"\u003e3.1123.0\u003c/a\u003e (2026-08-31)\u003c/h1\u003e\n\u003cp\u003e\u003cstrong\u003eNote:\u003c/strong\u003e Version bump only for package \u003ccode\u003e@​aws-sdk/client-s3\u003c/code\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/523fff6052428fafb61b8842773c1c142d4c5f74\"\u003e\u003ccode\u003e523fff6\u003c/code\u003e\u003c/a\u003e Publish v3.1128.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/8b5898753d091cf7647df0a65418430e5c0ce55f\"\u003e\u003ccode\u003e8b58987\u003c/code\u003e\u003c/a\u003e feat(client-s3): Adds support for Amazon S3 Object Lock variable retention.  ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/8893344796b14a92844d9a08973bcdc2da89a3eb\"\u003e\u003ccode\u003e8893344\u003c/code\u003e\u003c/a\u003e Publish v3.1127.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/7131e7467d87d0a255fa1c42f6bb0dd12a84835e\"\u003e\u003ccode\u003e7131e74\u003c/code\u003e\u003c/a\u003e Publish v3.1126.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/678282b614156c0085a279c49226c2725a88bf3e\"\u003e\u003ccode\u003e678282b\u003c/code\u003e\u003c/a\u003e Publish v3.1125.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/e80cab3d6831ad16c976bd65ba28a3467e1163e6\"\u003e\u003ccode\u003ee80cab3\u003c/code\u003e\u003c/a\u003e Publish v3.1124.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/49a1557a8f25447d8dbe714d2ac2cfbb482d2c1d\"\u003e\u003ccode\u003e49a1557\u003c/code\u003e\u003c/a\u003e Publish v3.1123.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/e1cf460a1e4707e137931804e3e7b71a8392f227\"\u003e\u003ccode\u003ee1cf460\u003c/code\u003e\u003c/a\u003e Publish v3.1122.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/e53a25aafbdd772c90d26471dc271e383f1daf71\"\u003e\u003ccode\u003ee53a25a\u003c/code\u003e\u003c/a\u003e Publish v3.1121.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/d6be6f8dd3ee8d43fd70dfb5b52a977ce251c720\"\u003e\u003ccode\u003ed6be6f8\u003c/code\u003e\u003c/a\u003e Publish v3.1120.0\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commits/v3.1128.0/clients/client-s3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@google/genai` from 2.16.0 to 2.21.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/googleapis/js-genai/releases\"\u003e@​google/genai's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.21.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/googleapis/js-genai/compare/v2.20.0...v2.21.0\"\u003e2.21.0\u003c/a\u003e (2026-09-02)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Gemini 3.8 Flash model to SDKs and update Flash model descriptions (\u003ca href=\"https://github.com/googleapis/js-genai/commit/4a969feeb938d05faa8389a476a268c1649a7695\"\u003e4a969fe\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.20.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/googleapis/js-genai/compare/v2.19.0...v2.20.0\"\u003e2.20.0\u003c/a\u003e (2026-08-31)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for the audio/webm MIME type. (\u003ca href=\"https://github.com/googleapis/js-genai/commit/b0e3c5f54bbddd875eaa88c699f1b85d5a55918f\"\u003eb0e3c5f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd translation_config SDK support for GEAP. (\u003ca href=\"https://github.com/googleapis/js-genai/commit/3e1d923ef914812c1d209aa2e5461a717d03a081\"\u003e3e1d923\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd Video Understanding support to the Interactions API (\u003ca href=\"https://github.com/googleapis/js-genai/commit/6ddbeba6c3836378f58351e6885f5141aab0c1e7\"\u003e6ddbeba\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDon't set redundant Content-Length on file upload requests (\u003ca href=\"https://github.com/googleapis/js-genai/commit/2f5cc7a00852608a46ffa3bd8cab5d02783810d6\"\u003e2f5cc7a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDon't set redundant Content-Length on file upload requests (\u003ca href=\"https://github.com/googleapis/js-genai/commit/2f5cc7a00852608a46ffa3bd8cab5d02783810d6\"\u003e2f5cc7a\u003c/a\u003e), refs \u003ca href=\"https://redirect.github.com/googleapis/js-genai/issues/1718\"\u003e#1718\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eexpose ProcessingCallStep and ProcessingResultStep in Interactions SDK (\u003ca href=\"https://github.com/googleapis/js-genai/commit/b6f8db553449199ebba1678dbb0936300e982990\"\u003eb6f8db5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eQuote setupComplete key in LiveClientMessage (\u003ca href=\"https://github.com/googleapis/js-genai/commit/4467fafb08948863889f7e87917d311ed39c0884\"\u003e4467faf\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.19.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/googleapis/js-genai/compare/v2.18.0...v2.19.0\"\u003e2.19.0\u003c/a\u003e (2026-08-25)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd AudioTranscriptionConfigMode (\u003ca href=\"https://github.com/googleapis/js-genai/commit/c0a37de9102c1054c2bf9fa2cd3d8b6a4c41fd42\"\u003ec0a37de\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd environment files support and scotty file download helper (\u003ca href=\"https://github.com/googleapis/js-genai/commit/0d6ee9d8e2690e541d12b72205272bba0c33b209\"\u003e0d6ee9d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd TYPE_JPEG2000 to VideoContent.MimeType enum (\u003ca href=\"https://github.com/googleapis/js-genai/commit/41da2043cce07211f793647d57d119e04ff2ef48\"\u003e41da204\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance Improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eKeep the Buffer in the Node tokenizer platform, ~2x faster model parse (\u003ca href=\"https://github.com/googleapis/js-genai/commit/11d804a88fc0ce260d6e4ab80ced4e54d34201ed\"\u003e11d804a\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.18.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/googleapis/js-genai/compare/v2.17.1...v2.18.0\"\u003e2.18.0\u003c/a\u003e (2026-08-19)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003emode\u003c/code\u003e enum (\u003ccode\u003eVERBATIM\u003c/code\u003e, \u003ccode\u003eSMART\u003c/code\u003e) to \u003ccode\u003eAudioTranscriptionConfig\u003c/code\u003e and \u003ccode\u003eTranscriptionConfig\u003c/code\u003e. (\u003ca href=\"https://github.com/googleapis/js-genai/commit/4c5208baa923cecea897b7b4fdc9de5e49555709\"\u003e4c5208b\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd enable_data_retention to ToolParallelAiSearch, Add step_count to ReinforcementTuningHyperParameters, Add BidiGenerateContentSetup (\u003ca href=\"https://github.com/googleapis/js-genai/commit/f52c20858c1bf6c7892192bc41cfc027d30b57ab\"\u003ef52c208\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd IDLE state to live connection status enum and mark REQUIRES_ACTION as deprecated. (\u003ca href=\"https://github.com/googleapis/js-genai/commit/2f110f23372cf2ea52452fe57ddf3a4e30833857\"\u003e2f110f2\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/googleapis/js-genai/blob/main/CHANGELOG.md\"\u003e@​google/genai's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/googleapis/js-genai/compare/v2.20.0...v2.21.0\"\u003e2.21.0\u003c/a\u003e (2026-09-02)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Gemini 3.8 Flash model to SDKs and update Flash model descriptions (\u003ca href=\"https://github.com/googleapis/js-genai/commit/4a969feeb938d05faa8389a476a268c1649a7695\"\u003e4a969fe\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/googleapis/js-genai/compare/v2.19.0...v2.20.0\"\u003e2.20.0\u003c/a\u003e (2026-08-31)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for the audio/webm MIME type. (\u003ca href=\"https://github.com/googleapis/js-genai/commit/b0e3c5f54bbddd875eaa88c699f1b85d5a55918f\"\u003eb0e3c5f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd translation_config SDK support for GEAP. (\u003ca href=\"https://github.com/googleapis/js-genai/commit/3e1d923ef914812c1d209aa2e5461a717d03a081\"\u003e3e1d923\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd Video Understanding support to the Interactions API (\u003ca href=\"https://github.com/googleapis/js-genai/commit/6ddbeba6c3836378f58351e6885f5141aab0c1e7\"\u003e6ddbeba\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDon't set redundant Content-Length on file upload requests (\u003ca href=\"https://github.com/googleapis/js-genai/commit/2f5cc7a00852608a46ffa3bd8cab5d02783810d6\"\u003e2f5cc7a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDon't set redundant Content-Length on file upload requests (\u003ca href=\"https://github.com/googleapis/js-genai/commit/2f5cc7a00852608a46ffa3bd8cab5d02783810d6\"\u003e2f5cc7a\u003c/a\u003e), refs \u003ca href=\"https://redirect.github.com/googleapis/js-genai/issues/1718\"\u003e#1718\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eexpose ProcessingCallStep and ProcessingResultStep in Interactions SDK (\u003ca href=\"https://github.com/googleapis/js-genai/commit/b6f8db553449199ebba1678dbb0936300e982990\"\u003eb6f8db5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eQuote setupComplete key in LiveClientMessage (\u003ca href=\"https://github.com/googleapis/js-genai/commit/4467fafb08948863889f7e87917d311ed39c0884\"\u003e4467faf\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/googleapis/js-genai/compare/v2.18.0...v2.19.0\"\u003e2.19.0\u003c/a\u003e (2026-08-25)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd AudioTranscriptionConfigMode (\u003ca href=\"https://github.com/googleapis/js-genai/commit/c0a37de9102c1054c2bf9fa2cd3d8b6a4c41fd42\"\u003ec0a37de\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd environment files support and scotty file download helper (\u003ca href=\"https://github.com/googleapis/js-genai/commit/0d6ee9d8e2690e541d12b72205272bba0c33b209\"\u003e0d6ee9d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd TYPE_JPEG2000 to VideoContent.MimeType enum (\u003ca href=\"https://github.com/googleapis/js-genai/commit/41da2043cce07211f793647d57d119e04ff2ef48\"\u003e41da204\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance Improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eKeep the Buffer in the Node tokenizer platform, ~2x faster model parse (\u003ca href=\"https://github.com/googleapis/js-genai/commit/11d804a88fc0ce260d6e4ab80ced4e54d34201ed\"\u003e11d804a\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/googleapis/js-genai/compare/v2.17.1...v2.18.0\"\u003e2.18.0\u003c/a\u003e (2026-08-19)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003emode\u003c/code\u003e enum (\u003ccode\u003eVERBATIM\u003c/code\u003e, \u003ccode\u003eSMART\u003c/code\u003e) to \u003ccode\u003eAudioTranscriptionConfig\u003c/code\u003e and \u003ccode\u003eTranscriptionConfig\u003c/code\u003e. (\u003ca href=\"https://github.com/googleapis/js-genai/commit/4c5208baa923cecea897b7b4fdc9de5e49555709\"\u003e4c5208b\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd enable_data_retention to ToolParallelAiSearch, Add step_count to ReinforcementTuningHyperParameters, Add BidiGenerateContentSetup (\u003ca href=\"https://github.com/googleapis/js-genai/commit/f52c20858c1bf6c7892192bc41cfc027d30b57ab\"\u003ef52c208\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd IDLE state to live connection status enum and mark REQUIRES_ACTION as deprecated. (\u003ca href=\"https://github.com/googleapis/js-genai/commit/2f110f23372cf2ea52452fe57ddf3a4e30833857\"\u003e2f110f2\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd video resolution and extension task parameters (\u003ca href=\"https://github.com/googleapis/js-genai/commit/39b2a2dea4c5ff75c1754581b213b9d480504e7d\"\u003e39b2a2d\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/googleapis/js-genai/commit/27af8977598edb68ffccadcd34fae967205a8740\"\u003e\u003ccode\u003e27af897\u003c/code\u003e\u003c/a\u003e chore(main): release 2.21.0 (\u003ca href=\"https://redirect.github.com/googleapis/js-genai/issues/1915\"\u003e#1915\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/googleapis/js-genai/commit/4a969feeb938d05faa8389a476a268c1649a7695\"\u003e\u003ccode\u003e4a969fe\u003c/code\u003e\u003c/a\u003e feat: Add Gemini 3.8 Flash model to SDKs and update Flash model descriptions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/googleapis/js-genai/commit/8233d412bd6900f38a83fac42909bfe135db0c2e\"\u003e\u003ccode\u003e8233d41\u003c/code\u003e\u003c/a\u003e chore: docs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/googleapis/js-genai/commit/7fe15a613e675f1f016fc34d5b5d685ef6105c69\"\u003e\u003ccode\u003e7fe15a6\u003c/code\u003e\u003c/a\u003e chore(main): release 2.20.0 (\u003ca href=\"https://redirect.github.com/googleapis/js-genai/issues/1899\"\u003e#1899\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/googleapis/js-genai/commit/b0e3c5f54bbddd875eaa88c699f1b85d5a55918f\"\u003e\u003ccode\u003eb0e3c5f\u003c/code\u003e\u003c/a\u003e feat: Add support for the audio/webm MIME type.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/googleapis/js-genai/commit/3e1d923ef914812c1d209aa2e5461a717d03a081\"\u003e\u003ccode\u003e3e1d923\u003c/code\u003e\u003c/a\u003e feat: Add translation_config SDK support for GEAP.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/googleapis/js-genai/commit/b6f8db553449199ebba1678dbb0936300e982990\"\u003e\u003ccode\u003eb6f8db5\u003c/code\u003e\u003c/a\u003e fix: expose ProcessingCallStep and ProcessingResultStep in Interactions SDK\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/googleapis/js-genai/commit/4467fafb08948863889f7e87917d311ed39c0884\"\u003e\u003ccode\u003e4467faf\u003c/code\u003e\u003c/a\u003e fix: Quote setupComplete key in LiveClientMessage\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/googleapis/js-genai/commit/6ddbeba6c3836378f58351e6885f5141aab0c1e7\"\u003e\u003ccode\u003e6ddbeba\u003c/code\u003e\u003c/a\u003e feat: add Video Understanding support to the Interactions API\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/googleapis/js-genai/commit/6a44ab0b5b98d816d594df6219eaf23fef584d5a\"\u003e\u003ccode\u003e6a44ab0\u003c/code\u003e\u003c/a\u003e chore: keep config as the last method parameter\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/googleapis/js-genai/compare/v2.16.0...v2.21.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@next/third-parties` from 16.3.0 to 16.3.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003e@​next/third-parties's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.4\u003c/h2\u003e\n\u003cp\u003eFollow-up release to \u003ca href=\"https://github.com/vercel/next.js/releases/tag/v16.3.3\"\u003ev16.3.3\u003c/a\u003e re-enabling AVIF Image Optimization (\u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97949\"\u003e#97949\u003c/a\u003e).\u003c/p\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003etestmode: Fix infinite recursion in testmode passthrough fetch (\u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/third-parties/issues/97691\"\u003e#97691\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix build error when aliasing typescript to \u003ccode\u003e@​typescript/typescript6\u003c/code\u003e (\u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/third-parties/issues/97997\"\u003e#97997\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix unset crossOrigin in Turbopack manifests (\u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/third-parties/issues/97930\"\u003e#97930\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.3\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eCritical:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36\"\u003eUnauthenticated Remote Code Execution on windows-hosted servers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4\"\u003eUnauthenticated Remote Code Execution in Image Optimization API when AVIF files are used\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.2\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Scope app-entry export validation to files inside the app directory (\u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/third-parties/issues/97357\"\u003e#97357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[backport] Fix catch-all index page being served for every other slug (\u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/third-parties/issues/97416\"\u003e#97416\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: don't trace embedded WASM loader helpers (\u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/third-parties/issues/97353\"\u003e#97353\u003c/a\u003e) (\u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/third-parties/issues/97463\"\u003e#97463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: retain conditions when replacing resolve request keys (\u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/third-parties/issues/97453\"\u003e#97453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Fix Turbopack worker chunk loading with asset prefix (\u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/third-parties/issues/97419\"\u003e#97419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (\u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/third-parties/issues/97603\"\u003e#97603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/lubieowoce\"\u003e\u003ccode\u003e@​lubieowoce\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[16.x] Turbopack: don't strip async-module runtime from shared runtime chunks by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96653\"\u003evercel/next.js#96653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] [turbopack] Add \u003ccode\u003eturbopack_ecmascript\u003c/code\u003e and \u003ccode\u003eturbopack_wasm\u003c/code\u003e's embeded FS to \u003ccode\u003einternal_assets_conditions\u003c/code\u003e by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96655\"\u003evercel/next.js#96655\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] [turbopack] Collapse nested promises in the analyzer by \u003ca href=\"https://github.com/sampoder\"\u003e\u003ccode\u003e@​sampoder\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96675\"\u003evercel/next.js#96675\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] fix(next/image): preserve image response after optimization by \u003ca href=\"https://github.com/styfle\"\u003e\u003ccode\u003e@​styfle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96733\"\u003evercel/next.js#96733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.3.x] Default deploy e2e tests to the repo next version by \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96900\"\u003evercel/next.js#96900\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Bump \u003ccode\u003e@​swc/helpers\u003c/code\u003e by \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96885\"\u003evercel/next.js#96885\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [turbopack] Raise registration calls in hoisted modules to the top by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97308\"\u003evercel/next.js#97308\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Fix missing styled-jsx styles in Pages Router SSR on adapter builds by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97302\"\u003evercel/next.js#97302\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [turbopack] Fix HMR for dynamic imports evaluated from layouts by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97317\"\u003evercel/next.js#97317\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Restore the live \u003ccode\u003eheaders()\u003c/code\u003e view of the incoming request by \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97311\"\u003evercel/next.js#97311\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/299180d3315c7ebd7b199d2b1a265b5986c5fc7d\"\u003e\u003ccode\u003e299180d\u003c/code\u003e\u003c/a\u003e v16.3.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/a9a1cb7859f178f830ad3773b303130c21b19586\"\u003e\u003ccode\u003ea9a1cb7\u003c/code\u003e\u003c/a\u003e v16.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/d0ac8828c2fe6026dd7d700488bfd8289711fde6\"\u003e\u003ccode\u003ed0ac882\u003c/code\u003e\u003c/a\u003e v16.3.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/3d32eb870fb4c7009d580a31e2de81a626562270\"\u003e\u003ccode\u003e3d32eb8\u003c/code\u003e\u003c/a\u003e v16.3.1\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/vercel/next.js/commits/v16.3.4/packages/third-parties\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@supabase/ssr` from 0.12.4 to 0.12.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/supabase/ssr/releases\"\u003e@​supabase/ssr's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.12.7\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/supabase/ssr/compare/v0.12.6...v0.12.7\"\u003e0.12.7\u003c/a\u003e (2026-09-08)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eapply non-browser defaults when cookies only sets encode (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/294\"\u003e#294\u003c/a\u003e) (\u003ca href=\"https://github.com/supabase/ssr/commit/9d6e2a54f5e7f205388218f7fe732b8622d3ebd8\"\u003e9d6e2a5\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.12.7-rc.162\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore: add workflow for autoclosing stale issues by \u003ca href=\"https://github.com/mandarini\"\u003e\u003ccode\u003e@​mandarini\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/292\"\u003esupabase/ssr#292\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: apply non-browser defaults when cookies only sets encode by \u003ca href=\"https://github.com/PhuocOng\"\u003e\u003ccode\u003e@​PhuocOng\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/294\"\u003esupabase/ssr#294\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/supabase/ssr/compare/v0.12.6...v0.12.7-rc.162\"\u003ehttps://github.com/supabase/ssr/compare/v0.12.6...v0.12.7-rc.162\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev0.12.6\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/supabase/ssr/compare/v0.12.5...v0.12.6\"\u003e0.12.6\u003c/a\u003e (2026-09-04)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eavoid duplicate cache headers per server client (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/283\"\u003e#283\u003c/a\u003e) (\u003ca href=\"https://github.com/supabase/ssr/commit/af750e259b7fab43b9cbc0c19873384a666a7a47\"\u003eaf750e2\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.12.6-rc.158\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore: update \u003ccode\u003e@​supabase/supabase-js\u003c/code\u003e to v2.114.0 by \u003ca href=\"https://github.com/supabase-libs-pr-manager\"\u003e\u003ccode\u003e@​supabase-libs-pr-manager\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/289\"\u003esupabase/ssr#289\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/deploy-pages from 5.0.0 to 5.0.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/290\"\u003esupabase/ssr#290\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid duplicate cache headers per server client by \u003ca href=\"https://github.com/dhruvxvaishnav\"\u003e\u003ccode\u003e@​dhruvxvaishnav\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/283\"\u003esupabase/ssr#283\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: fix typos in tsdoc and design doc by \u003ca href=\"https://github.com/PhuocOng\"\u003e\u003ccode\u003e@​PhuocOng\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/288\"\u003esupabase/ssr#288\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/dhruvxvaishnav\"\u003e\u003ccode\u003e@​dhruvxvaishnav\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/283\"\u003esupabase/ssr#283\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PhuocOng\"\u003e\u003ccode\u003e@​PhuocOng\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/288\"\u003esupabase/ssr#288\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/supabase/ssr/compare/v0.12.5...v0.12.6-rc.158\"\u003ehttps://github.com/supabase/ssr/compare/v0.12.5...v0.12.6-rc.158\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev0.12.5\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/supabase/ssr/compare/v0.12.4...v0.12.5\"\u003e0.12.5\u003c/a\u003e (2026-08-24)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ewarn when auth.storage is ignored by createBrowserClient/createServerClient (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/284\"\u003e#284\u003c/a\u003e) (\u003ca href=\"https://github.com/supabase/ssr/commit/c1700f277f7f03b13e20ff11abeea633816d5238\"\u003ec1700f2\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/supabase/ssr/issues/142\"\u003e#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.12.5-rc.154\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocs: add React Router middleware example by \u003ca href=\"https://github.com/sornapudisuresh\"\u003e\u003ccode\u003e@​sornapudisuresh\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/274\"\u003esupabase/ssr#274\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump pnpm/action-setup from 6.0.9 to 6.0.10 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/280\"\u003esupabase/ssr#280\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump postcss from 8.5.15 to 8.5.25 in the npm_and_yarn group across 1 directory by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/281\"\u003esupabase/ssr#281\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/supabase/ssr/blob/main/CHANGELOG.md\"\u003e@​supabase/ssr's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/supabase/ssr/compare/v0.12.6...v0.12.7\"\u003e0.12.7\u003c/a\u003e (2026-09-08)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eapply non-browser defaults when cookies only sets encode (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/294\"\u003e#294\u003c/a\u003e) (\u003ca href=\"https://github.com/supabase/ssr/commit/9d6e2a54f5e7f205388218f7fe732b8622d3ebd8\"\u003e9d6e2a5\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/supabase/ssr/compare/v0.12.5...v0.12.6\"\u003e0.12.6\u003c/a\u003e (2026-09-04)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eavoid duplicate cache headers per server client (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/283\"\u003e#283\u003c/a\u003e) (\u003ca href=\"https://github.com/supabase/ssr/commit/af750e259b7fab43b9cbc0c19873384a666a7a47\"\u003eaf750e2\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/supabase/ssr/compare/v0.12.4...v0.12.5\"\u003e0.12.5\u003c/a\u003e (2026-08-24)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ewarn when auth.storage is ignored by createBrowserClient/createServerClient (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/284\"\u003e#284\u003c/a\u003e) (\u003ca href=\"https://github.com/supabase/ssr/commit/c1700f277f7f03b13e20ff11abeea633816d5238\"\u003ec1700f2\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/supabase/ssr/issues/142\"\u003e#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/ssr/commit/9b28f495a358393046851b926551b706d7e4d267\"\u003e\u003ccode\u003e9b28f49\u003c/code\u003e\u003c/a\u003e chore(main): release 0.12.7 (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/295\"\u003e#295\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/ssr/commit/9d6e2a54f5e7f205388218f7fe732b8622d3ebd8\"\u003e\u003ccode\u003e9d6e2a5\u003c/code\u003e\u003c/a\u003e fix: apply non-browser defaults when cookies only sets encode (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/294\"\u003e#294\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/ssr/commit/4ed9f65274760607c5af5126cfa01210e0185ce1\"\u003e\u003ccode\u003e4ed9f65\u003c/code\u003e\u003c/a\u003e chore: add workflow for autoclosing stale issues (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/292\"\u003e#292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/ssr/commit/71c33a7e8c62c7776d30c8f3cd94b8f6771ce0f0\"\u003e\u003ccode\u003e71c33a7\u003c/code\u003e\u003c/a\u003e chore(main): release 0.12.6 (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/291\"\u003e#291\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/ssr/commit/c7c7e68551d286671dc2b85bce6bbe40e24eae12\"\u003e\u003ccode\u003ec7c7e68\u003c/code\u003e\u003c/a\u003e docs: fix typos in tsdoc and design doc (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/288\"\u003e#288\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/ssr/commit/af750e259b7fab43b9cbc0c19873384a666a7a47\"\u003e\u003ccode\u003eaf750e2\u003c/code\u003e\u003c/a\u003e fix: avoid duplicate cache headers per server client (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/283\"\u003e#283\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/ssr/commit/905c7c3672f356d53beafeefd974209d4a5e0a65\"\u003e\u003ccode\u003e905c7c3\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/deploy-pages from 5.0.0 to 5.0.1 (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/290\"\u003e#290\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/ssr/commit/9e2564d780030f1d682e7d28c1eaf88f46c6496a\"\u003e\u003ccode\u003e9e2564d\u003c/code\u003e\u003c/a\u003e chore: update \u003ccode\u003e@​supabase/supabase-js\u003c/code\u003e to v2.114.0 (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/289\"\u003e#289\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/ssr/commit/c5310fdec2786743e56644ed4fc3861991b82124\"\u003e\u003ccode\u003ec5310fd\u003c/code\u003e\u003c/a\u003e chore(main): release 0.12.5 (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/286\"\u003e#286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/ssr/commit/c1700f277f7f03b13e20ff11abeea633816d5238\"\u003e\u003ccode\u003ec1700f2\u003c/code\u003e\u003c/a\u003e fix: warn when auth.storage is ignored by createBrowserClient/createServerCli...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/supabase/ssr/compare/v0.12.4...v0.12.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@supabase/supabase-js` from 2.112.3 to 2.116.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/supabase/supabase-js/releases\"\u003e@​supabase/supabase-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.116.0\u003c/h2\u003e\n\u003ch2\u003e2.116.0 (2026-09-07)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eauth:\u003c/strong\u003e add MFA recovery codes API (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2676\"\u003e#2676\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003estorage:\u003c/strong\u003e add bucket lifecycle configuration (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2659\"\u003e#2659\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003estorage:\u003c/strong\u003e topk 10k support (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2667\"\u003e#2667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003estorage:\u003c/strong\u003e add versionId support to create URL methods (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2678\"\u003e#2678\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eauth:\u003c/strong\u003e silence commit-guard-discarded refresh in initial session (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2668\"\u003e#2668\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003estorage:\u003c/strong\u003e drop legacy prefix from lifecycles (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2674\"\u003e#2674\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003esupabase:\u003c/strong\u003e warn when schema is passed outside db options (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2663\"\u003e#2663\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efadymak\u003c/li\u003e\n\u003cli\u003eFerhat Elmas\u003c/li\u003e\n\u003cli\u003eKaterina Skroumpelou \u003ca href=\"https://github.com/mandarini\"\u003e\u003ccode\u003e@​mandarini\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTyler Hillery\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.116.0-canary.3\u003c/h2\u003e\n\u003ch2\u003e2.116.0-canary.3 (2026-09-07)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eauth:\u003c/strong\u003e add MFA recovery codes API (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2676\"\u003e#2676\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003estorage:\u003c/strong\u003e add versionId support to create URL methods (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2678\"\u003e#2678\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efadymak\u003c/li\u003e\n\u003cli\u003eKaterina Skroumpelou\u003c/li\u003e\n\u003cli\u003eTyler Hillery\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.116.0-canary.2\u003c/h2\u003e\n\u003ch2\u003e2.116.0-canary.2 (2026-09-07)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003estorage:\u003c/strong\u003e topk 10k support (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2667\"\u003e#2667\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003estorage:\u003c/strong\u003e drop legacy prefix from lifecycles (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2674\"\u003e#2674\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/supabase/supabase-js/blob/master/packages/core/supabase-js/CHANGELOG.md\"\u003e@​supabase/supabase-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.116.0 (2026-09-07)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eauth:\u003c/strong\u003e add MFA recovery codes API (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2676\"\u003e#2676\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003esupabase:\u003c/strong\u003e warn when schema is passed outside db options (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2663\"\u003e#2663\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efadymak\u003c/li\u003e\n\u003cli\u003eKaterina Skroumpelou \u003ca href=\"https://github.com/mandarini\"\u003e\u003ccode\u003e@​mandarini\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.115.0 (2026-09-03)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003epostgrest:\u003c/strong\u003e add getOpenApiSpec() (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2651\"\u003e#2651\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eKaterina Skroumpelou \u003ca href=\"https://github.com/mandarini\"\u003e\u003ccode\u003e@​mandarini\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.114.0 (2026-09-02)\u003c/h2\u003e\n\u003cp\u003eThis was a version bump only for \u003ccode\u003e@​supabase/supabase-js\u003c/code\u003e to align it with other projects, there were no code changes.\u003c/p\u003e\n\u003ch2\u003e2.113.0 (2026-09-02)\u003c/h2\u003e\n\u003cp\u003eThis was a version bump only for \u003ccode\u003e@​supabase/supabase-js\u003c/code\u003e to align it with other projects, there were no code changes.\u003c/p\u003e\n\u003ch2\u003e2.112.4 (2026-08-24)\u003c/h2\u003e\n\u003cp\u003eThis was a version bump only for \u003ccode\u003e@​supabase/supabase-js\u003c/code\u003e to align it with other projects, there were no code changes.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/supabase-js/commit/5aedaab92566149dc728ce0480b032841dddd463\"\u003e\u003ccode\u003e5aedaab\u003c/code\u003e\u003c/a\u003e feat(auth): add MFA recovery codes API (\u003ca href=\"https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js/issues/2676\"\u003e#2676\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/supabase-js/commit/e4f675a96addf3e767c38f7e8c8759754f10f490\"\u003e\u003ccode\u003ee4f675a\u003c/code\u003e\u003c/a\u003e fix(supabase): warn when schema is passed outside db options (\u003ca href=\"https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js/issues/2663\"\u003e#2663\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/supabase-js/commit/dbe76791e9eab34d1b91ec0ebdb9f11fc770b4eb\"\u003e\u003ccode\u003edbe7679\u003c/code\u003e\u003c/a\u003e chore(release): version 2.115.0 changelogs (\u003ca href=\"https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js/issues/2664\"\u003e#2664\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/supabase-js/commit/3eb61931b0d81728eece27b43df962e7336b0ed5\"\u003e\u003ccode\u003e3eb6193\u003c/code\u003e\u003c/a\u003e docs(supabase): clarify db.schema needs the second generic (\u003ca href=\"https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js/issues/2662\"\u003e#2662\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/supabase-js/commit/92fb8ba0cbfc50c3f550b0768210e98d26f2b1d5\"\u003e\u003ccode\u003e92fb8ba\u003c/code\u003e\u003c/a\u003e feat(postgrest): add getOpenApiSpec() (\u003ca href=\"https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js/issues/2651\"\u003e#2651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/supabase-js/commit/aef432bc806fbbe90dde71ec9b75e3cc6d702a31\"\u003e\u003ccode\u003eaef432b\u003c/code\u003e\u003c/a\u003e chore(release): version 2.114.0 changelogs (\u003ca href=\"https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js/issues/2653\"\u003e#2653\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/supabase-js/commit/67b07b075220806f8f7355995db646bd6d0a85db\"\u003e\u003ccode\u003e67b07b0\u003c/code\u003e\u003c/a\u003e chore(release): version 2.113.0 changelogs (\u003ca href=\"https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js/issues/2650\"\u003e#2650\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/supabase-js/commit/062ae5e6f5e06c08284d7392316389dc7a935baf\"\u003e\u003ccode\u003e062ae5e\u003c/code\u003e\u003c/a\u003e chore(release): version 2.112.4 changelogs (\u003ca href=\"https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js/issues/2628\"\u003e#2628\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/supabase-js/commit/c7397c19cb6cb8b1562be27cb0a09ed0e240276a\"\u003e\u003ccode\u003ec7397c1\u003c/code\u003e\u003c/a\u003e chore(supabase): bump supabase cli to 2.113.0 (\u003ca href=\"https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js/issues/2606\"\u003e#2606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/supabase-js/commit/bbc167cbef7fb841d44c53fb3c45e1d19aa3ece3\"\u003e\u003ccode\u003ebbc167c\u003c/code\u003e\u003c/a\u003e chore(release): version 2.112.3 changelogs (\u003ca href=\"https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js/issues/2608\"\u003e#2608\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/supabase/supabase-js/commits/v2.116.0/packages/core/supabase-js\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `lucide-react` from 1.31.0 to 1.43.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lucide-icons/lucide/releases\"\u003elucide-react's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 1.43.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003etic-tac-toe\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4772\"\u003elucide-icons/lucide#4772\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): changed \u003ccode\u003eid-card\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4820\"\u003elucide-icons/lucide#4820\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): changed \u003ccode\u003eid-card-lanyard\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4819\"\u003elucide-icons/lucide#4819\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): delegate \u003ccode\u003ecarton\u003c/code\u003e/\u003ccode\u003ecarton-off\u003c/code\u003e from lab by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4818\"\u003elucide-icons/lucide#4818\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/lucide-icons/lucide/compare/1.42.0...1.43.0\"\u003ehttps://github.com/lucide-icons/lucide/compare/1.42.0...1.43.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 1.42.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(docs): added better contribution guide by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4746\"\u003elucide-icons/lucide#4746\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(site): fix HomeHeroIconsCard.data.ts by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4805\"\u003elucide-icons/lucide#4805\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): deprecated swiss franc icons by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4799\"\u003elucide-icons/lucide#4799\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): add gap-horizontal and gap-vertical by \u003ca href=\"https://github.com/samuelalake\"\u003e\u003ccode\u003e@​samuelalake\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4544\"\u003elucide-icons/lucide#4544\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003etrash-off\u003c/code\u003e icon by \u003ca href=\"https://github.com/lx3133584\"\u003e\u003ccode\u003e@​lx3133584\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4788\"\u003elucide-icons/lucide#4788\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003ecircle-dashed-check\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4796\"\u003elucide-icons/lucide#4796\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003eequal-approximately-not\u003c/code\u003e icon by \u003ca href=\"https://github.com/ryck\"\u003e\u003ccode\u003e@​ryck\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4802\"\u003elucide-icons/lucide#4802\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added dome icons by \u003ca href=\"https://github.com/swastik7805\"\u003e\u003ccode\u003e@​swastik7805\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4261\"\u003elucide-icons/lucide#4261\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(lucide-react): Add Lucide React integration tests by \u003ca href=\"https://github.com/ericfennis\"\u003e\u003ccode\u003e@​ericfennis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4804\"\u003elucide-icons/lucide#4804\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(packages): extract icon build logic into \u003ccode\u003e@lucide/shared\u003c/code\u003e by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4409\"\u003elucide-icons/lucide#4409\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): changed \u003ccode\u003ecomputer\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4607\"\u003elucide-icons/lucide#4607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(dependencies): Update dependencies by \u003ca href=\"https://github.com/ericfennis\"\u003e\u003ccode\u003e@​ericfennis\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4806\"\u003elucide-icons/lucide#4806\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): changed \u003ccode\u003etable-2\u003c/code\u003e icon by \u003ca href=\"https://github.com/jguddas\"\u003e\u003ccode\u003e@​jguddas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4810\"\u003elucide-icons/lucide#4810\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003euser-group\u003c/code\u003e icons by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4782\"\u003elucide-icons/lucide#4782\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lx3133584\"\u003e\u003ccode\u003e@​lx3133584\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4788\"\u003elucide-icons/lucide#4788\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ryck\"\u003e\u003ccode\u003e@​ryck\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4802\"\u003elucide-icons/lucide#4802\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/lucide-icons/lucide/compare/1.41.0...1.42.0\"\u003ehttps://github.com/lucide-icons/lucide/compare/1.41.0...1.42.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 1.41.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(icons): Add new icons \u003ccode\u003egerm\u003c/code\u003e and \u003ccode\u003egerm-off\u003c/code\u003e by \u003ca href=\"https://github.com/rrod497\"\u003e\u003ccode\u003e@​rrod497\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4056\"\u003elucide-icons/lucide#4056\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003edoor-stairwell\u003c/code\u003e icon \u0026amp; updated \u003ccode\u003edoor-*\u003c/code\u003e icons by \u003ca href=\"https://github.com/jguddas\"\u003e\u003ccode\u003e@​jguddas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/3554\"\u003elucide-icons/lucide#3554\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003ecredit-card-reader\u003c/code\u003e icon by \u003ca href=\"https://github.com/jguddas\"\u003e\u003ccode\u003e@​jguddas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4616\"\u003elucide-icons/lucide#4616\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added 'engine' icon by \u003ca href=\"https://github.com/benhaube\"\u003e\u003ccode\u003e@​benhaube\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4598\"\u003elucide-icons/lucide#4598\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): fixed \u003ccode\u003egerm\u003c/code\u003e \u0026amp; \u003ccode\u003egerm-off\u003c/code\u003e by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4789\"\u003elucide-icons/lucide#4789\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump the vue-deps group with 2 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4771\"\u003elucide-icons/lucide#4771\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003evirus\u003c/code\u003e/\u003ccode\u003evirus-off\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4765\"\u003elucide-icons/lucide#4765\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(copilot-reviews): Improve use-cases description. by \u003ca href=\"https://github.com/ericfennis\"\u003e\u003ccode\u003e@​ericfennis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4558\"\u003elucide-icons/lucide#4558\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): add \u003ccode\u003ecan-soda\u003c/code\u003e icon by \u003ca href=\"https://github.com/jaynewey\"\u003e\u003ccode\u003e@​jaynewey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4718\"\u003elucide-icons/lucide#4718\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003esquare-alert\u003c/code\u003e Icon by \u003ca href=\"https://github.com/viralcodex\"\u003e\u003ccode\u003e@​viralcodex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/3687\"\u003elucide-icons/lucide#3687\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(lab): Add label for lab icons by \u003ca href=\"https://github.com/ericfennis\"\u003e\u003ccode\u003e@​ericfennis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4793\"\u003elucide-icons/lucide#4793\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): changed \u003ccode\u003elab/bottle-toothbrush-comb\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4756\"\u003elucide-icons/lucide#4756\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(\u003ccode\u003e@​lucide/lab\u003c/code\u003e): Create automatic release flow for \u003ccode\u003e@lucide/lab\u003c/code\u003e by \u003ca href=\"https://github.com/ericfennis\"\u003e\u003ccode\u003e@​ericfennis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4792\"\u003elucide-icons/lucide#4792\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): removed \u003ccode\u003etrash\u003c/code\u003e icon in favour of \u003ccode\u003etrash-2\u003c/code\u003e by \u003ca href=\"https://github.com/jguddas\"\u003e\u003ccode\u003e@​jguddas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/3141\"\u003elucide-icons/lucide#3141\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): changed \u003ccode\u003eleaf\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4801\"\u003elucide-icons/lucide#4801\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lucide-icons/lucide/commit/94e4cb9d9db5907053ebf3636a97c45529cf776b\"\u003e\u003ccode\u003e94e4cb9\u003c/code\u003e\u003c/a\u003e chore(dependencies): Update dependencies (\u003ca href=\"https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4806\"\u003e#4806\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lucide-icons/lucide/commit/99d25bdee231922e73e19525f57a585d1682fab2\"\u003e\u003ccode\u003e99d25bd\u003c/code\u003e\u003c/a\u003e feat(packages): extract icon build logic into \u003ccode\u003e@lucide/shared\u003c/code\u003e (\u003ca href=\"https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4409\"\u003e#4409\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lucide-icons/lucide/commit/75b55160aa9edd7095dfed1a6e3d88e66fb2b153\"\u003e\u003ccode\u003e75b5516\u003c/code\u003e\u003c/a\u003e chore(dev): upgrade ESLint to latest compatible stack (v10) (\u003ca href=\"https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4378\"\u003e#4378\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/lucide-icons/lucide/commits/1.43.0/packages/lucide-react\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `next` from 16.3.0 to 16.3.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003enext's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.4\u003c/h2\u003e\n\u003cp\u003eFollow-up release to \u003ca href=\"https://github.com/vercel/next.js/releases/tag/v16.3.3\"\u003ev16.3.3\u003c/a\u003e re-enabling AVIF Image Optimization (\u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97949\"\u003e#97949\u003c/a\u003e).\u003c/p\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003etestmode: Fix infinite recursion in testmode passthrough fetch (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97691\"\u003e#97691\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix build error when aliasing typescript to \u003ccode\u003e@​typescript/typescript6\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97997\"\u003e#97997\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix unset crossOrigin in Turbopack manifests (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97930\"\u003e#97930\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.3\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eCritical:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36\"\u003eUnauthenticated Remote Code Execution on windows-hosted servers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4\"\u003eUnauthenticated Remote Code Execution in Image Optimization API when AVIF files are used\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.2\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Scope app-entry export validation to files inside the app directory (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97357\"\u003e#97357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[backport] Fix catch-all index page being served for every other slug (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97416\"\u003e#97416\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: don't trace embedded WASM loader helpers (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97353\"\u003e#97353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97463\"\u003e#97463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: retain conditions when replacing resolve request keys (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97453\"\u003e#97453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Fix Turbopack worker chunk loading with asset prefix (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97419\"\u003e#97419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97603\"\u003e#97603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/lubieowoce\"\u003e\u003ccode\u003e@​lubieowoce\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[16.x] Turbopack: don't strip async-module runtime from shared runtime chunks by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96653\"\u003evercel/next.js#96653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] [turbopack] Add \u003ccode\u003eturbopack_ecmascript\u003c/code\u003e and \u003ccode\u003eturbopack_wasm\u003c/code\u003e's embeded FS to \u003ccode\u003einternal_assets_conditions\u003c/code\u003e by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96655\"\u003evercel/next.js#96655\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] [turbopack] Collapse nested promises in the analyzer by \u003ca href=\"https://github.com/sampoder\"\u003e\u003ccode\u003e@​sampoder\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96675\"\u003evercel/next.js#96675\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] fix(next/image): preserve image response after optimization by \u003ca href=\"https://github.com/styfle\"\u003e\u003ccode\u003e@​styfle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96733\"\u003evercel/next.js#96733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.3.x] Default deploy e2e tests to the repo next version by \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96900\"\u003evercel/next.js#96900\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Bump \u003ccode\u003e@​swc/helpers\u003c/code\u003e by \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96885\"\u003evercel/next.js#96885\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [turbopack] Raise registration calls in hoisted modules to the top by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97308\"\u003evercel/next.js#97308\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Fix missing styled-jsx styles in Pages Router SSR on adapter builds by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97302\"\u003evercel/next.js#97302\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [turbopack] Fix HMR for dynamic imports evaluated from layouts by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97317\"\u003evercel/next.js#97317\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Restore the live \u003ccode\u003eheaders()\u003c/code\u003e view of the incoming request by \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97311\"\u003evercel/next.js#97311\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/299180d3315c7ebd7b199d2b1a265b5986c5fc7d\"\u003e\u003ccode\u003e299180d\u003c/code\u003e\u003c/a\u003e v16.3.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/12e173dd73ed6c39622281c7282c8364234ad94f\"\u003e\u003ccode\u003e12e173d\u003c/code\u003e\u003c/a\u003e [16.3.x] Re-enable AVIF image optimization and require sharp 0.35.4 (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97949\"\u003e#97949\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/5d9022edd29e32d7061bc56cf713ffe8769cd900\"\u003e\u003ccode\u003e5d9022e\u003c/code\u003e\u003c/a\u003e [backport] Fix unset crossOrigin in Turbopack manifests (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97930\"\u003e#97930\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/d8f45609fa74e56f24958d45d93d3426511f957f\"\u003e\u003ccode\u003ed8f4560\u003c/code\u003e\u003c/a\u003e [16.3.x] Fix build error when aliasing typescript to \u003ccode\u003e@​typescript/typescript6\u003c/code\u003e ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/656aebfb58ce194fb603f18942dad6e94d15b21c\"\u003e\u003ccode\u003e656aebf\u003c/code\u003e\u003c/a\u003e [16.3] testmode: Fix infinite recursion in testmode passthrough fetch (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97691\"\u003e#97691\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/f37c1d656553b8950330b6683ab242a5c610135c\"\u003e\u003ccode\u003ef37c1d6\u003c/code\u003e\u003c/a\u003e [16.3.x] ci: remove pull_request_stats workflow (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97975\"\u003e#97975\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/a9a1cb7859f178f830ad3773b303130c21b19586\"\u003e\u003ccode\u003ea9a1cb7\u003c/code\u003e\u003c/a\u003e v16.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/968b9fcb26bdeb8e0a861a9df05361474666d51b\"\u003e\u003ccode\u003e968b9fc\u003c/code\u003e\u003c/a\u003e [16.3.x] Fix ISR misses with backslashes in segments when deployed on Windows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/3a15b4ac6ac8e70b1a9b18ecc18e8434462899b3\"\u003e\u003ccode\u003e3a15b4a\u003c/code\u003e\u003c/a\u003e [16.3.x] [next/image]: disable avif image optimization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/7378b51ea05a6745d3676bee00cb4c63aac3dd16\"\u003e\u003ccode\u003e7378b51\u003c/code\u003e\u003c/a\u003e Backport/docs fixes 16.3 (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97649\"\u003e#97649\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/compare/v16.3.0...v16.3.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `resend` from 6.19.0 to 6.26.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/resend/resend-node/releases\"\u003eresend's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.26.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(webhooks): add events.replay() by \u003ca href=\"https://github.com/gabrielmfern\"\u003e\u003ccode\u003e@​gabrielmfern\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/resend/resend-node/pull/1087\"\u003eresend/resend-node#1087\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/resend/resend-node/compare/v6.25.0...v6.26.0\"\u003ehttps://github.com/resend/resend-node/compare/v6.25.0...v6.26.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.25.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: allow CNAME type on domain SPF records by \u003ca href=\"https://github.com/vieiralucas\"\u003e\u003ccode\u003e@​vieiralucas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/resend/resend-node/pull/1085\"\u003eresend/resend-node#1085\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/resend/resend-node/compare/v6.24.0...v6.25.0\"\u003ehttps://github.com/resend/resend-node/compare/v6.24.0...v6.25.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.24.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(webhooks): promote event endpoints to stable by \u003ca href=\"https://github.com/gabrielmfern\"\u003e\u003ccode\u003e@​gabrielmfern\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/resend/resend-node/pull/1083\"\u003eresend/resend-node#1083\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/resend/resend-node/compare/v6.23.0...v6.24.0\"\u003ehttps://github.com/resend/resend-node/compare/v6.23.0...v6.24.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.23.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(segments): add segments.update() by \u003ca href=\"https://github.com/dielduarte\"\u003e\u003ccode\u003e@​dielduarte\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/resend/resend-node/pull/1084\"\u003eresend/resend-node#1084\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/resend/resend-node/compare/v6.22.1...v6.23.0\"\u003ehttps://github.com/resend/resend-node/compare/v6.22.1...v6.23.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.22.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: allow null contact first_name and last_name on webhook events by \u003ca href=\"https://github.com/gabrielmfern\"\u003e\u003ccode\u003e@​gabrielmfern\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/resend/resend-node/pull/1073\"\u003eresend/resend-node#1073\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump version to 6.22.1 by \u003ca href=\"https://github.com...\n\n_Description has been truncated_","html_url":"https://github.com/orbisdei/v2/pull/136","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/orbisdei%2Fv2/issues/136","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/136/packages"},{"uuid":"5430067211","node_id":"PR_kwDOS43PYc8AAAABDNsKuA","number":347,"state":"open","title":"chore(deps): bump undici from 6.27.0 to 8.10.2 in /clients/typescript","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-12T00:22:56.000Z","updated_at":"2026-09-12T00:23:18.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"undici","old_version":"6.27.0","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"}],"path":"/clients/typescript","ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 6.27.0 to 8.10.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm\"\u003eGHSA-vp8m-p9jh-q5pm\u003c/a\u003e: cache and deduplication interceptors could use caller-controlled request metadata instead of the authoritative dispatcher origin, enabling cross-origin cache poisoning and data disclosure. Undici now derives interceptor identities from the dispatcher origin and bypasses origin-dependent interceptors when no authoritative origin exists. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/caf6194d3dae989b731ed87ab85f182befe5eb80\"\u003ecaf6194d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e8f5868fb\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e66e12816\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6\"\u003e4411a238\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/662d0ea671fe64139e79533c913fce412765e1d7\"\u003e662d0ea6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003ecb75bbb3\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e7aac7f12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003ee905b5b8\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e2be07bf9\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e6d583124\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e0160a719\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps-dev): bump undici from 6.27.0 to 6.28.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5653\"\u003enodejs/undici#5653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump jest from 30.4.2 to 30.5.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5750\"\u003enodejs/undici#5750\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/analyze from 4.37.3 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5752\"\u003enodejs/undici#5752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5754\"\u003enodejs/undici#5754\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(h2): cover stream reset with NGHTTP2_INTERNAL_ERROR by \u003ca href=\"https://github.com/zeexzeex\"\u003e\u003ccode\u003e@​zeexzeex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5725\"\u003enodejs/undici#5725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): reject invalid resumed responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5724\"\u003enodejs/undici#5724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: make stale-while-revalidate cache update test deterministic by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5722\"\u003enodejs/undici#5722\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid unbounded recursion in Set-Cookie attribute parser by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5757\"\u003enodejs/undici#5757\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: honor SOCKS5 connection timeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5733\"\u003enodejs/undici#5733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(eventsource): validate Last-Event-ID on reconnect by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5746\"\u003enodejs/undici#5746\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid duplicate release attempts by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5745\"\u003enodejs/undici#5745\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(cache): refetch when 304 adds vary fields by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5732\"\u003enodejs/undici#5732\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etypes: expose PendingInterceptor and PendingInterceptorsFormatter on the MockAgent namespace by \u003ca href=\"https://github.com/RaphaelFakhri\"\u003e\u003ccode\u003e@​RaphaelFakhri\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5721\"\u003enodejs/undici#5721\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(codeql): align CodeQL action versions to v4.37.9 by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5759\"\u003enodejs/undici#5759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5760\"\u003enodejs/undici#5760\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(proxy-agent): guard Proxy-Authorization in iterable header containers by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5758\"\u003enodejs/undici#5758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: name the parameters these two blocks describe by \u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): fail the connection on a non-200 h2 extended CONNECT response by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(node-fetch): re-enable the set-cookie header combining test by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5730\"\u003enodejs/undici#5730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward rawHeaders writes through RetryController by \u003ca href=\"https://github.com/official-burak\"\u003e\u003ccode\u003e@​official-burak\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5727\"\u003enodejs/undici#5727\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5738\"\u003enodejs/undici#5738\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/5e541e0b9df7563e5766bbd469fbfe383d9ae6ca\"\u003e\u003ccode\u003e5e541e0\u003c/code\u003e\u003c/a\u003e Bumped v8.10.2 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5771\"\u003e#5771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/eb04cc39954e63e9b46bdf824e6efad9fff2e7b5\"\u003e\u003ccode\u003eeb04cc3\u003c/code\u003e\u003c/a\u003e fix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5738\"\u003e#5738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003e\u003ccode\u003ee905b5b\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e\u003ccode\u003e0160a71\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e\u003ccode\u003e66e1281\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e\u003ccode\u003e7aac7f1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003e\u003ccode\u003ecb75bbb\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e\u003ccode\u003e6d58312\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e\u003ccode\u003e8f5868f\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e\u003ccode\u003e2be07bf\u003c/code\u003e\u003c/a\u003e fix(cache): reject unsafe method response caching\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v8.10.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=6.27.0\u0026new-version=8.10.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/SBALAVIGNESH123/sketchlog/pull/347","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/SBALAVIGNESH123%2Fsketchlog/issues/347","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/347/packages"},{"uuid":"5429980099","node_id":"PR_kwDOOTUI_M8AAAABDNn8PA","number":1140,"state":"open","title":"Bump the prod group across 1 directory with 3 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-12T00:03:43.000Z","updated_at":"2026-09-12T00:04:50.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"prod","update_count":3,"packages":[{"name":"i18next","old_version":"26.4.0","new_version":"26.4.2","repository_url":"https://github.com/i18next/i18next"},{"name":"jose","old_version":"6.2.10","new_version":"6.2.11","repository_url":"https://github.com/panva/jose"},{"name":"undici","old_version":"8.10.0","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps the prod group with 3 updates in the / directory: [i18next](https://github.com/i18next/i18next), [jose](https://github.com/panva/jose) and [undici](https://github.com/nodejs/undici).\n\nUpdates `i18next` from 26.4.0 to 26.4.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/i18next/i18next/releases\"\u003ei18next's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev26.4.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: \u003ccode\u003e$\u0026amp;\u003c/code\u003e, \u003ccode\u003e$`\u003c/code\u003e, \u003ccode\u003e$'\u003c/code\u003e and \u003ccode\u003e$$\u003c/code\u003e inside a nested value (\u003ccode\u003e$t(key)\u003c/code\u003e) now stay literal. \u003ccode\u003enest()\u003c/code\u003e handed the resolved value straight to \u003ccode\u003eString.replace\u003c/code\u003e as the replacement argument, so those sequences were read as replacement patterns: \u003ccode\u003e$\u0026amp;\u003c/code\u003e re-inserted the \u003ccode\u003e$t(...)\u003c/code\u003e match, \u003ccode\u003e$`\u003c/code\u003e / \u003ccode\u003e$'\u003c/code\u003e inserted the text before / after it, and \u003ccode\u003e$$\u003c/code\u003e collapsed to \u003ccode\u003e$\u003c/code\u003e. Through \u003ccode\u003et()\u003c/code\u003e the \u003ccode\u003e$\u0026amp;\u003c/code\u003e case was worse than a wrong string: the nested lookup resets the shared nesting regexp, so the re-inserted \u003ccode\u003e$t(...)\u003c/code\u003e was matched again on every pass and \u003ccode\u003et()\u003c/code\u003e never returned — also under the default \u003ccode\u003eescapeValue: true\u003c/code\u003e when the value arrives via a variable forwarded through nesting options (\u003ccode\u003e$t(key, { \u0026quot;name\u0026quot;: \u0026quot;{{name}}\u0026quot; })\u003c/code\u003e with a name containing \u003ccode\u003e$\u0026amp;\u003c/code\u003e). The value is now \u003ccode\u003e$\u003c/code\u003e-escaped at the \u003ccode\u003eString.replace\u003c/code\u003e call, the same guard \u003ccode\u003einterpolate()\u003c/code\u003e already has, and a non-string value returned by a formatter in the nesting chain (\u003ccode\u003e$t(key, myFormat)\u003c/code\u003e) is stringified before that. Nested values are still not HTML-escaped (\u003ca href=\"https://redirect.github.com/i18next/i18next/issues/854\"\u003e#854\u003c/a\u003e). Thanks \u003ca href=\"https://github.com/mahirhir\"\u003e\u003ccode\u003e@​mahirhir\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/i18next/i18next/pull/2447\"\u003e#2447\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev26.4.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(types): the selector-form \u003ccode\u003ekeyPrefix\u003c/code\u003e overload of \u003ccode\u003egetFixedT()\u003c/code\u003e is now available under \u003ccode\u003eenableSelector: 'strict'\u003c/code\u003e. Its constraint was gated on \u003ccode\u003etrue | 'optimize'\u003c/code\u003e only, so under \u003ccode\u003e'strict'\u003c/code\u003e it collapsed to \u003ccode\u003enever\u003c/code\u003e, the overload dropped out, and the returned \u003ccode\u003et\u003c/code\u003e silently lost its \u003ccode\u003ekeyPrefix\u003c/code\u003e scope (\u003ccode\u003et(($) =\u0026gt; $.deep)\u003c/code\u003e failed with \u003ccode\u003eProperty 'deep' does not exist on type '{}'\u003c/code\u003e). The same call already typechecked under \u003ccode\u003etrue\u003c/code\u003e and \u003ccode\u003e'optimize'\u003c/code\u003e. Thanks \u003ca href=\"https://github.com/hovelopin\"\u003e\u003ccode\u003e@​hovelopin\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/i18next/i18next/pull/2446\"\u003e#2446\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/i18next/i18next/blob/master/CHANGELOG.md\"\u003ei18next's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e26.4.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: \u003ccode\u003e$\u0026amp;\u003c/code\u003e, \u003ccode\u003e$`\u003c/code\u003e, \u003ccode\u003e$'\u003c/code\u003e and \u003ccode\u003e$$\u003c/code\u003e inside a nested value (\u003ccode\u003e$t(key)\u003c/code\u003e) now stay literal. \u003ccode\u003enest()\u003c/code\u003e handed the resolved value straight to \u003ccode\u003eString.replace\u003c/code\u003e as the replacement argument, so those sequences were read as replacement patterns: \u003ccode\u003e$\u0026amp;\u003c/code\u003e re-inserted the \u003ccode\u003e$t(...)\u003c/code\u003e match, \u003ccode\u003e$`\u003c/code\u003e / \u003ccode\u003e$'\u003c/code\u003e inserted the text before / after it, and \u003ccode\u003e$$\u003c/code\u003e collapsed to \u003ccode\u003e$\u003c/code\u003e. Through \u003ccode\u003et()\u003c/code\u003e the \u003ccode\u003e$\u0026amp;\u003c/code\u003e case was worse than a wrong string: the nested lookup resets the shared nesting regexp, so the re-inserted \u003ccode\u003e$t(...)\u003c/code\u003e was matched again on every pass and \u003ccode\u003et()\u003c/code\u003e never returned — also under the default \u003ccode\u003eescapeValue: true\u003c/code\u003e when the value arrives via a variable forwarded through nesting options (\u003ccode\u003e$t(key, { \u0026quot;name\u0026quot;: \u0026quot;{{name}}\u0026quot; })\u003c/code\u003e with a name containing \u003ccode\u003e$\u0026amp;\u003c/code\u003e). The value is now \u003ccode\u003e$\u003c/code\u003e-escaped at the \u003ccode\u003eString.replace\u003c/code\u003e call, the same guard \u003ccode\u003einterpolate()\u003c/code\u003e already has, and a non-string value returned by a formatter in the nesting chain (\u003ccode\u003e$t(key, myFormat)\u003c/code\u003e) is stringified before that. Nested values are still not HTML-escaped (\u003ca href=\"https://redirect.github.com/i18next/i18next/issues/854\"\u003e#854\u003c/a\u003e). Thanks \u003ca href=\"https://github.com/mahirhir\"\u003e\u003ccode\u003e@​mahirhir\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/i18next/i18next/pull/2447\"\u003e#2447\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e26.4.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(types): the selector-form \u003ccode\u003ekeyPrefix\u003c/code\u003e overload of \u003ccode\u003egetFixedT()\u003c/code\u003e is now available under \u003ccode\u003eenableSelector: 'strict'\u003c/code\u003e. Its constraint was gated on \u003ccode\u003etrue | 'optimize'\u003c/code\u003e only, so under \u003ccode\u003e'strict'\u003c/code\u003e it collapsed to \u003ccode\u003enever\u003c/code\u003e, the overload dropped out, and the returned \u003ccode\u003et\u003c/code\u003e silently lost its \u003ccode\u003ekeyPrefix\u003c/code\u003e scope (\u003ccode\u003et(($) =\u0026gt; $.deep)\u003c/code\u003e failed with \u003ccode\u003eProperty 'deep' does not exist on type '{}'\u003c/code\u003e). The same call already typechecked under \u003ccode\u003etrue\u003c/code\u003e and \u003ccode\u003e'optimize'\u003c/code\u003e. Thanks \u003ca href=\"https://github.com/hovelopin\"\u003e\u003ccode\u003e@​hovelopin\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/i18next/i18next/pull/2446\"\u003e#2446\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next/commit/4dba50f20669c3678db0812255716eb7693ad2da\"\u003e\u003ccode\u003e4dba50f\u003c/code\u003e\u003c/a\u003e 26.4.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next/commit/e436b625a648e1a48ea27ecf5f2fba8020d67009\"\u003e\u003ccode\u003ee436b62\u003c/code\u003e\u003c/a\u003e build\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next/commit/d955fb086e9f4ded1200f51ecbb21034dbad1d92\"\u003e\u003ccode\u003ed955fb0\u003c/code\u003e\u003c/a\u003e fix: stringify formatter results in nested values, changelog v26.4.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next/commit/dfafa3ca725e1415ef20e7fb5b1b3e4468f3c425\"\u003e\u003ccode\u003edfafa3c\u003c/code\u003e\u003c/a\u003e fix: keep replacement patterns literal in nested values (\u003ca href=\"https://redirect.github.com/i18next/i18next/issues/2447\"\u003e#2447\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next/commit/3c9981e22dd471b6bca224aa1f60e04ba3f6153a\"\u003e\u003ccode\u003e3c9981e\u003c/code\u003e\u003c/a\u003e chore: keep dev-only and local files out of the npm package\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next/commit/c057ee048c55a61c095acc017365e997e4f723f8\"\u003e\u003ccode\u003ec057ee0\u003c/code\u003e\u003c/a\u003e 26.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next/commit/02e3e1659b7cc9fedaaf53797597483ef8003df2\"\u003e\u003ccode\u003e02e3e16\u003c/code\u003e\u003c/a\u003e changelog v26.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next/commit/6f198f2508ba8986d1bbf25a8b922d01afcf0751\"\u003e\u003ccode\u003e6f198f2\u003c/code\u003e\u003c/a\u003e fix(types): allow selector keyPrefix in getFixedT under enableSelector 'stric...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/i18next/i18next/compare/v26.4.0...v26.4.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `jose` from 6.2.10 to 6.2.11\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/panva/jose/releases\"\u003ejose's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.2.11\u003c/h2\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003erender subpath indexes as tables (\u003ca href=\"https://github.com/panva/jose/commit/94589ee9efe6cf257a133765d753bbe8d55f6ed3\"\u003e94589ee\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eshorten API index descriptions (\u003ca href=\"https://github.com/panva/jose/commit/681482fcca7577c6a4b8df61c992f195f6e6ac1b\"\u003e681482f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003emodel JWE key management modes (\u003ca href=\"https://github.com/panva/jose/commit/e01dda65d5d272c8dd44710d0c70673c1530038e\"\u003ee01dda6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypes:\u003c/strong\u003e reduce declaration repetition (\u003ca href=\"https://github.com/panva/jose/commit/55b970fc08c9082041f40473470ee0fe0e8b0087\"\u003e55b970f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/panva/jose/blob/main/CHANGELOG.md\"\u003ejose's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/panva/jose/compare/v6.2.10...v6.2.11\"\u003e6.2.11\u003c/a\u003e (2026-09-04)\u003c/h2\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003erender subpath indexes as tables (\u003ca href=\"https://github.com/panva/jose/commit/94589ee9efe6cf257a133765d753bbe8d55f6ed3\"\u003e94589ee\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eshorten API index descriptions (\u003ca href=\"https://github.com/panva/jose/commit/681482fcca7577c6a4b8df61c992f195f6e6ac1b\"\u003e681482f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003emodel JWE key management modes (\u003ca href=\"https://github.com/panva/jose/commit/e01dda65d5d272c8dd44710d0c70673c1530038e\"\u003ee01dda6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypes:\u003c/strong\u003e reduce declaration repetition (\u003ca href=\"https://github.com/panva/jose/commit/55b970fc08c9082041f40473470ee0fe0e8b0087\"\u003e55b970f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/f5e56061ea6c20d66bf1caeb0111141ec2afa961\"\u003e\u003ccode\u003ef5e5606\u003c/code\u003e\u003c/a\u003e chore(release): 6.2.11\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/d60f1b4c50bf39a3fc581fbcd56e791a760fc674\"\u003e\u003ccode\u003ed60f1b4\u003c/code\u003e\u003c/a\u003e chore: bump packages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/55b970fc08c9082041f40473470ee0fe0e8b0087\"\u003e\u003ccode\u003e55b970f\u003c/code\u003e\u003c/a\u003e refactor(types): reduce declaration repetition\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/681482fcca7577c6a4b8df61c992f195f6e6ac1b\"\u003e\u003ccode\u003e681482f\u003c/code\u003e\u003c/a\u003e docs: shorten API index descriptions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/33c88179c0e270ab2e599d5dbd7d024b9742775e\"\u003e\u003ccode\u003e33c8817\u003c/code\u003e\u003c/a\u003e build: verify published subpath contract\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/542829d5b61d31bfe26b805af1167808ed848ba1\"\u003e\u003ccode\u003e542829d\u003c/code\u003e\u003c/a\u003e build: compact emitted ESM syntax\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/94589ee9efe6cf257a133765d753bbe8d55f6ed3\"\u003e\u003ccode\u003e94589ee\u003c/code\u003e\u003c/a\u003e docs: render subpath indexes as tables\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/a778a0b31b94c720818625f762a0cd34def13f99\"\u003e\u003ccode\u003ea778a0b\u003c/code\u003e\u003c/a\u003e test: cover root exports and algorithm facades\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/e01dda65d5d272c8dd44710d0c70673c1530038e\"\u003e\u003ccode\u003ee01dda6\u003c/code\u003e\u003c/a\u003e refactor: model JWE key management modes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/920bc40e5d7c81bfa48e74687e8bed221928ba24\"\u003e\u003ccode\u003e920bc40\u003c/code\u003e\u003c/a\u003e ci: test trigger-ci pushes\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/panva/jose/compare/v6.2.10...v6.2.11\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 8.10.0 to 8.10.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm\"\u003eGHSA-vp8m-p9jh-q5pm\u003c/a\u003e: cache and deduplication interceptors could use caller-controlled request metadata instead of the authoritative dispatcher origin, enabling cross-origin cache poisoning and data disclosure. Undici now derives interceptor identities from the dispatcher origin and bypasses origin-dependent interceptors when no authoritative origin exists. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/caf6194d3dae989b731ed87ab85f182befe5eb80\"\u003ecaf6194d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e8f5868fb\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e66e12816\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6\"\u003e4411a238\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/662d0ea671fe64139e79533c913fce412765e1d7\"\u003e662d0ea6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003ecb75bbb3\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e7aac7f12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003ee905b5b8\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e2be07bf9\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e6d583124\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e0160a719\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps-dev): bump undici from 6.27.0 to 6.28.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5653\"\u003enodejs/undici#5653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump jest from 30.4.2 to 30.5.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5750\"\u003enodejs/undici#5750\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/analyze from 4.37.3 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5752\"\u003enodejs/undici#5752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5754\"\u003enodejs/undici#5754\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(h2): cover stream reset with NGHTTP2_INTERNAL_ERROR by \u003ca href=\"https://github.com/zeexzeex\"\u003e\u003ccode\u003e@​zeexzeex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5725\"\u003enodejs/undici#5725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): reject invalid resumed responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5724\"\u003enodejs/undici#5724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: make stale-while-revalidate cache update test deterministic by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5722\"\u003enodejs/undici#5722\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid unbounded recursion in Set-Cookie attribute parser by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5757\"\u003enodejs/undici#5757\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: honor SOCKS5 connection timeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5733\"\u003enodejs/undici#5733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(eventsource): validate Last-Event-ID on reconnect by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5746\"\u003enodejs/undici#5746\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid duplicate release attempts by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5745\"\u003enodejs/undici#5745\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(cache): refetch when 304 adds vary fields by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5732\"\u003enodejs/undici#5732\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etypes: expose PendingInterceptor and PendingInterceptorsFormatter on the MockAgent namespace by \u003ca href=\"https://github.com/RaphaelFakhri\"\u003e\u003ccode\u003e@​RaphaelFakhri\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5721\"\u003enodejs/undici#5721\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(codeql): align CodeQL action versions to v4.37.9 by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5759\"\u003enodejs/undici#5759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5760\"\u003enodejs/undici#5760\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(proxy-agent): guard Proxy-Authorization in iterable header containers by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5758\"\u003enodejs/undici#5758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: name the parameters these two blocks describe by \u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): fail the connection on a non-200 h2 extended CONNECT response by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(node-fetch): re-enable the set-cookie header combining test by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5730\"\u003enodejs/undici#5730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward rawHeaders writes through RetryController by \u003ca href=\"https://github.com/official-burak\"\u003e\u003ccode\u003e@​official-burak\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5727\"\u003enodejs/undici#5727\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5738\"\u003enodejs/undici#5738\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/5e541e0b9df7563e5766bbd469fbfe383d9ae6ca\"\u003e\u003ccode\u003e5e541e0\u003c/code\u003e\u003c/a\u003e Bumped v8.10.2 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5771\"\u003e#5771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/eb04cc39954e63e9b46bdf824e6efad9fff2e7b5\"\u003e\u003ccode\u003eeb04cc3\u003c/code\u003e\u003c/a\u003e fix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5738\"\u003e#5738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003e\u003ccode\u003ee905b5b\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e\u003ccode\u003e0160a71\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e\u003ccode\u003e66e1281\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e\u003ccode\u003e7aac7f1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003e\u003ccode\u003ecb75bbb\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e\u003ccode\u003e6d58312\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e\u003ccode\u003e8f5868f\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e\u003ccode\u003e2be07bf\u003c/code\u003e\u003c/a\u003e fix(cache): reject unsafe method response caching\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v8.10.0...v8.10.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/DEFRA/epr-frontend/pull/1140","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/DEFRA%2Fepr-frontend/issues/1140","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1140/packages"},{"uuid":"5429868392","node_id":"PR_kwDOTMBNAc8AAAABDNiawA","number":17,"state":"open","title":"Bump undici from 6.26.0 to 6.28.1","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":7,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T23:39:07.000Z","updated_at":"2026-09-11T23:41:19.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"undici","old_version":"6.26.0","new_version":"6.28.1","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 6.26.0 to 6.28.1.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.28.1\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2af0faf88b906d3127a360c3ac75164c0f95e5a5\"\u003e2af0faf8\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/07c60d9c7099a910451244afe42861bbdbdd974c\"\u003e07c60d9c\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/ce31bc824b578008faae5d3350da66c1b5f71548\"\u003ece31bc82\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eperf: reduce EventSourceStream parser allocations (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5032\"\u003e#5032\u003c/a\u003e) by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5647\"\u003enodejs/undici#5647\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v6.x] perf(h1): drop idle-socket timer floor with a ref'd setImmediate (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5707\"\u003e#5707\u003c/a\u003e) by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5770\"\u003enodejs/undici#5770\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v6.28.0...v6.28.1\"\u003ehttps://github.com/nodejs/undici/compare/v6.28.0...v6.28.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.28.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e740a0b7c\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003ecba3a52a\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e4fd5a0c6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003eaf748404\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e and \u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e affect the cache interceptor in Undici v7 and v8; Undici v6 is not in their affected version ranges.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ehttps://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.27.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e4 security advisories\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 6.27.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^6.27.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on patched version:\u003c/strong\u003e the v6 fixes shipped in \u003cstrong\u003ev6.27.0\u003c/strong\u003e, not \u003ccode\u003e6.26.0\u003c/code\u003e\n— \u003ccode\u003ev6.26.0\u003c/code\u003e contains only the chunked-EOF fix (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5308\"\u003e#5308\u003c/a\u003e) and the version bump, none\nof the security fixes below.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ffc8aa0fdd4c54024f384e57784d5047c8b4085a\"\u003e\u003ccode\u003effc8aa0\u003c/code\u003e\u003c/a\u003e Bumped v6.28.1 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5773\"\u003e#5773\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3866a3bc4ebaea2c6400db9193c2366072080dc4\"\u003e\u003ccode\u003e3866a3b\u003c/code\u003e\u003c/a\u003e perf(h1): drop idle-socket timer floor with a ref'd setImmediate (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5707\"\u003e#5707\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5770\"\u003e#5770\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ce31bc824b578008faae5d3350da66c1b5f71548\"\u003e\u003ccode\u003ece31bc8\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2af0faf88b906d3127a360c3ac75164c0f95e5a5\"\u003e\u003ccode\u003e2af0faf\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/07c60d9c7099a910451244afe42861bbdbdd974c\"\u003e\u003ccode\u003e07c60d9\u003c/code\u003e\u003c/a\u003e fix(websocket): destroy inflater after decompression limit\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/bd90fff2a6e1350ba87e9b70811c5337502d2e39\"\u003e\u003ccode\u003ebd90fff\u003c/code\u003e\u003c/a\u003e perf: reduce EventSourceStream parser allocations (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5032\"\u003e#5032\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5647\"\u003e#5647\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/01a912e49a50c48009ed2639d2a457a6ec26752a\"\u003e\u003ccode\u003e01a912e\u003c/code\u003e\u003c/a\u003e Bumped v6.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5591\"\u003e#5591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/481ecfc3280292ab7eb0abbc4d0139219126f15e\"\u003e\u003ccode\u003e481ecfc\u003c/code\u003e\u003c/a\u003e Use Node 22 and npm 11 to release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e\u003ccode\u003e740a0b7\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2698e492ed22c9ec704b5df573d612bdd03f6ca0\"\u003e\u003ccode\u003e2698e49\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v6.26.0...v6.28.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=6.26.0\u0026new-version=6.28.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Dustin4444/docs-16/network/alerts).\n\n\u003c/details\u003e\n\n\u003c!-- Reviewable:start --\u003e\n- - -\nThis change is [\u003cimg src=\"https://reviewable.io/review_button.svg\" height=\"34\" align=\"absmiddle\" alt=\"Reviewable\"/\u003e](https://reviewable.io/reviews/Dustin4444/docs-16/17)\n\u003c!-- Reviewable:end --\u003e\n","html_url":"https://github.com/Dustin4444/docs-16/pull/17","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Dustin4444%2Fdocs-16/issues/17","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/17/packages"},{"uuid":"5429843665","node_id":"PR_kwDOR-cqY88AAAABDNhMeg","number":164,"state":"open","title":"chore(deps): bump the npm_and_yarn group across 1 directory with 3 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T23:33:51.000Z","updated_at":"2026-09-11T23:34:24.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":3,"packages":[{"name":"esbuild","old_version":"0.27.3","new_version":"0.28.1","repository_url":"https://github.com/evanw/esbuild"},{"name":"sharp","old_version":"0.34.5","new_version":"0.35.4"},{"name":"undici","old_version":"7.24.8","new_version":"7.29.0"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 1 update in the /workers/pilot-landing directory: [esbuild](https://github.com/evanw/esbuild).\n\nUpdates `esbuild` from 0.27.3 to 0.28.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/evanw/esbuild/releases\"\u003eesbuild's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.28.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eDisallow \u003ccode\u003e\\\u003c/code\u003e in local development server HTTP requests (\u003ca href=\"https://github.com/evanw/esbuild/security/advisories/GHSA-g7r4-m6w7-qqqr\"\u003eGHSA-g7r4-m6w7-qqqr\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a security issue where HTTP requests to esbuild's local development server could traverse outside of the serve directory on Windows using a \u003ccode\u003e\\\u003c/code\u003e backslash character. It happened due to the use of Go's \u003ccode\u003epath.Clean()\u003c/code\u003e function, which only handles Unix-style \u003ccode\u003e/\u003c/code\u003e characters. HTTP requests with paths containing \u003ccode\u003e\\\u003c/code\u003e are no longer allowed.\u003c/p\u003e\n\u003cp\u003eThanks to \u003ca href=\"https://github.com/dellalibera\"\u003e\u003ccode\u003e@​dellalibera\u003c/code\u003e\u003c/a\u003e for reporting this issue.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdd integrity checks to the Deno API (\u003ca href=\"https://github.com/evanw/esbuild/security/advisories/GHSA-gv7w-rqvm-qjhr\"\u003eGHSA-gv7w-rqvm-qjhr\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThe previous release of esbuild added integrity checks to esbuild's npm install script. This release also adds integrity checks to esbuild's Deno install script. Now esbuild's Deno API will also fail with an error if the downloaded esbuild binary contains something other than the expected content.\u003c/p\u003e\n\u003cp\u003eNote that esbuild's Deno API installs from \u003ccode\u003eregistry.npmjs.org\u003c/code\u003e by default, but allows the \u003ccode\u003eNPM_CONFIG_REGISTRY\u003c/code\u003e environment variable to override this with a custom package registry. This change means that the esbuild executable served by \u003ccode\u003eNPM_CONFIG_REGISTRY\u003c/code\u003e must now match the expected content.\u003c/p\u003e\n\u003cp\u003eThanks to \u003ca href=\"https://github.com/sondt99\"\u003e\u003ccode\u003e@​sondt99\u003c/code\u003e\u003c/a\u003e for reporting this issue.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAvoid inlining \u003ccode\u003eusing\u003c/code\u003e and \u003ccode\u003eawait using\u003c/code\u003e declarations (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4482\"\u003e#4482\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003ePreviously esbuild's minifier sometimes incorrectly inlined \u003ccode\u003eusing\u003c/code\u003e and \u003ccode\u003eawait using\u003c/code\u003e declarations into subsequent uses of that declaration, which then fails to dispose of the resource correctly. This bug happened because inlining was done for \u003ccode\u003elet\u003c/code\u003e and \u003ccode\u003econst\u003c/code\u003e declarations by avoiding doing it for \u003ccode\u003evar\u003c/code\u003e declarations, which no longer worked when more declaration types were added. Here's an example:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Original code\r\n{\r\n  using x = new Resource()\r\n  x.activate()\r\n}\r\n\u003cp\u003e// Old output (with --minify)\u003cbr /\u003e\nnew Resource().activate();\u003c/p\u003e\n\u003cp\u003e// New output (with --minify)\u003cbr /\u003e\n{using e=new Resource;e.activate()}\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix module evaluation when an error is thrown (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4461\"\u003e#4461\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/evanw/esbuild/pull/4467\"\u003e#4467\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eIf an error is thrown during module evaluation, esbuild previously didn't preserve the state of the module for subsequent module references. This was observable if \u003ccode\u003eimport()\u003c/code\u003e or \u003ccode\u003erequire()\u003c/code\u003e is used to import a module multiple times. The thrown error is supposed to be thrown by every call to \u003ccode\u003eimport()\u003c/code\u003e or \u003ccode\u003erequire()\u003c/code\u003e, not just the first. With this release, esbuild will now throw the same error every time you call \u003ccode\u003eimport()\u003c/code\u003e or \u003ccode\u003erequire()\u003c/code\u003e on a module that throws during its evaluation.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix some edge cases around the \u003ccode\u003enew\u003c/code\u003e operator (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4477\"\u003e#4477\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003ePreviously esbuild incorrectly printed certain edge cases involving complex expressions inside the target of a \u003ccode\u003enew\u003c/code\u003e expression (specifically an optional chain and/or a tagged template literal). The generated code for the \u003ccode\u003enew\u003c/code\u003e target was not correctly wrapped with parentheses, and either contained a syntax error or had different semantics. These edge cases have been fixed so that they now correctly wrap the \u003ccode\u003enew\u003c/code\u003e target in parentheses. Here is an example of some affected code:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Original code\r\nnew (foo()`bar`)()\r\nnew (foo()?.bar)()\r\n\u003cp\u003e// Old output\u003cbr /\u003e\nnew foo()\u003ccode\u003ebar\u003c/code\u003e();\u003cbr /\u003e\nnew (foo())?.bar();\u003c/p\u003e\n\u003cp\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/evanw/esbuild/blob/main/CHANGELOG.md\"\u003eesbuild's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.28.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eDisallow \u003ccode\u003e\\\u003c/code\u003e in local development server HTTP requests (\u003ca href=\"https://github.com/evanw/esbuild/security/advisories/GHSA-g7r4-m6w7-qqqr\"\u003eGHSA-g7r4-m6w7-qqqr\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a security issue where HTTP requests to esbuild's local development server could traverse outside of the serve directory on Windows using a \u003ccode\u003e\\\u003c/code\u003e backslash character. It happened due to the use of Go's \u003ccode\u003epath.Clean()\u003c/code\u003e function, which only handles Unix-style \u003ccode\u003e/\u003c/code\u003e characters. HTTP requests with paths containing \u003ccode\u003e\\\u003c/code\u003e are no longer allowed.\u003c/p\u003e\n\u003cp\u003eThanks to \u003ca href=\"https://github.com/dellalibera\"\u003e\u003ccode\u003e@​dellalibera\u003c/code\u003e\u003c/a\u003e for reporting this issue.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdd integrity checks to the Deno API (\u003ca href=\"https://github.com/evanw/esbuild/security/advisories/GHSA-gv7w-rqvm-qjhr\"\u003eGHSA-gv7w-rqvm-qjhr\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThe previous release of esbuild added integrity checks to esbuild's npm install script. This release also adds integrity checks to esbuild's Deno install script. Now esbuild's Deno API will also fail with an error if the downloaded esbuild binary contains something other than the expected content.\u003c/p\u003e\n\u003cp\u003eNote that esbuild's Deno API installs from \u003ccode\u003eregistry.npmjs.org\u003c/code\u003e by default, but allows the \u003ccode\u003eNPM_CONFIG_REGISTRY\u003c/code\u003e environment variable to override this with a custom package registry. This change means that the esbuild executable served by \u003ccode\u003eNPM_CONFIG_REGISTRY\u003c/code\u003e must now match the expected content.\u003c/p\u003e\n\u003cp\u003eThanks to \u003ca href=\"https://github.com/sondt99\"\u003e\u003ccode\u003e@​sondt99\u003c/code\u003e\u003c/a\u003e for reporting this issue.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAvoid inlining \u003ccode\u003eusing\u003c/code\u003e and \u003ccode\u003eawait using\u003c/code\u003e declarations (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4482\"\u003e#4482\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003ePreviously esbuild's minifier sometimes incorrectly inlined \u003ccode\u003eusing\u003c/code\u003e and \u003ccode\u003eawait using\u003c/code\u003e declarations into subsequent uses of that declaration, which then fails to dispose of the resource correctly. This bug happened because inlining was done for \u003ccode\u003elet\u003c/code\u003e and \u003ccode\u003econst\u003c/code\u003e declarations by avoiding doing it for \u003ccode\u003evar\u003c/code\u003e declarations, which no longer worked when more declaration types were added. Here's an example:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Original code\n{\n  using x = new Resource()\n  x.activate()\n}\n\u003cp\u003e// Old output (with --minify)\u003cbr /\u003e\nnew Resource().activate();\u003c/p\u003e\n\u003cp\u003e// New output (with --minify)\u003cbr /\u003e\n{using e=new Resource;e.activate()}\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix module evaluation when an error is thrown (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4461\"\u003e#4461\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/evanw/esbuild/pull/4467\"\u003e#4467\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eIf an error is thrown during module evaluation, esbuild previously didn't preserve the state of the module for subsequent module references. This was observable if \u003ccode\u003eimport()\u003c/code\u003e or \u003ccode\u003erequire()\u003c/code\u003e is used to import a module multiple times. The thrown error is supposed to be thrown by every call to \u003ccode\u003eimport()\u003c/code\u003e or \u003ccode\u003erequire()\u003c/code\u003e, not just the first. With this release, esbuild will now throw the same error every time you call \u003ccode\u003eimport()\u003c/code\u003e or \u003ccode\u003erequire()\u003c/code\u003e on a module that throws during its evaluation.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix some edge cases around the \u003ccode\u003enew\u003c/code\u003e operator (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4477\"\u003e#4477\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003ePreviously esbuild incorrectly printed certain edge cases involving complex expressions inside the target of a \u003ccode\u003enew\u003c/code\u003e expression (specifically an optional chain and/or a tagged template literal). The generated code for the \u003ccode\u003enew\u003c/code\u003e target was not correctly wrapped with parentheses, and either contained a syntax error or had different semantics. These edge cases have been fixed so that they now correctly wrap the \u003ccode\u003enew\u003c/code\u003e target in parentheses. Here is an example of some affected code:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Original code\nnew (foo()`bar`)()\nnew (foo()?.bar)()\n\u003cp\u003e// Old output\u003cbr /\u003e\nnew foo()\u003ccode\u003ebar\u003c/code\u003e();\u003cbr /\u003e\nnew (foo())?.bar();\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/bb9db84c02433fbe37b3509f53f9f3e3cc48725e\"\u003e\u003ccode\u003ebb9db84\u003c/code\u003e\u003c/a\u003e publish 0.28.1 to npm\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/9ff053e53b8eeb990f59355dbea365277ac45ee2\"\u003e\u003ccode\u003e9ff053e\u003c/code\u003e\u003c/a\u003e security: add integrity checks to the Deno API\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/0a9bf2135b67c7e28989a5ba19f0f000805a5ab5\"\u003e\u003ccode\u003e0a9bf21\u003c/code\u003e\u003c/a\u003e enforce non-negative size in gzip parser\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/e2a1a7132058ee067fe736eac15f695861b8654e\"\u003e\u003ccode\u003ee2a1a71\u003c/code\u003e\u003c/a\u003e security: forbid \u003ccode\u003e\\\\\u003c/code\u003e in local dev server requests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/83a2cbfc35809f4fd5152da59572d7bed7739d78\"\u003e\u003ccode\u003e83a2cbf\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4482\"\u003e#4482\u003c/a\u003e: don't inline \u003ccode\u003eusing\u003c/code\u003e declarations\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/308ad745d824c77bc607603451b257d0f2fd9a38\"\u003e\u003ccode\u003e308ad74\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4471\"\u003e#4471\u003c/a\u003e: renaming of nested \u003ccode\u003evar\u003c/code\u003e declarations\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/f013f5f99a015bce92ec48d49181d4ad3177b29b\"\u003e\u003ccode\u003ef013f5f\u003c/code\u003e\u003c/a\u003e fix some typos\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/aafd6e48b1088336a5f5a17e930be7e840d43d8c\"\u003e\u003ccode\u003eaafd6e4\u003c/code\u003e\u003c/a\u003e chore: fix some minor issues in comments (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4462\"\u003e#4462\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/15300c30b5e22f7cfcbed850c246d35095658386\"\u003e\u003ccode\u003e15300c3\u003c/code\u003e\u003c/a\u003e follow up: cjs evaluation fixes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/1bda0c31d7697c0af44b3ab39b81e599e559a395\"\u003e\u003ccode\u003e1bda0c3\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4461\"\u003e#4461\u003c/a\u003e, fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4467\"\u003e#4467\u003c/a\u003e: esm evaluation fixes\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/evanw/esbuild/compare/v0.27.3...v0.28.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `sharp` from 0.34.5 to 0.35.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lovell/sharp/releases\"\u003esharp's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.35.4\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\"\u003ehttps://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.35.4-rc.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpgrade to libvips v8.18.6 for upstream bug fixes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7f1a0a22cc285fe180766f4935d50b55af6e8432\"\u003e\u003ccode\u003e7f1a0a2\u003c/code\u003e\u003c/a\u003e Release v0.35.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/f927818924bc5a9493d822a4e8b23ec5857c52e1\"\u003e\u003ccode\u003ef927818\u003c/code\u003e\u003c/a\u003e Upgrade to sharp-libvips v1.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e80209240d005c71e1173a50dd9cd4db4ce2a9e6\"\u003e\u003ccode\u003ee802092\u003c/code\u003e\u003c/a\u003e Prerelease v0.35.4-rc.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e13eb2f97a0a22f1ef726e8d0cd33f7c56835945\"\u003e\u003ccode\u003ee13eb2f\u003c/code\u003e\u003c/a\u003e CI: Fix wasm32 build (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4589\"\u003e#4589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/a82a0b3d58bc25854ad1e925e6eb0a50725d1489\"\u003e\u003ccode\u003ea82a0b3\u003c/code\u003e\u003c/a\u003e Upgrade to libvips v8.18.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/8044fe43e36d0ea7f8beb89f79a37bb0f3342e84\"\u003e\u003ccode\u003e8044fe4\u003c/code\u003e\u003c/a\u003e Bound resize dimensions to coordinate limit\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/147f8591a153bc4a1e199c3fe3150fac2931b30c\"\u003e\u003ccode\u003e147f859\u003c/code\u003e\u003c/a\u003e Docs: changelog entries for \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4578\"\u003e#4578\u003c/a\u003e \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ee5bfb853de75a611c64381783b04032a3a897d8\"\u003e\u003ccode\u003eee5bfb8\u003c/code\u003e\u003c/a\u003e Tests: use yauzl directly rather than via extract-zip wrapper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7a7788928f8a2a429f45039010a87cee35401694\"\u003e\u003ccode\u003e7a77889\u003c/code\u003e\u003c/a\u003e Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4588\"\u003e#4588\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ea5bef24c187b2c7ee3fe3cad3b45c8cb67a46fd\"\u003e\u003ccode\u003eea5bef2\u003c/code\u003e\u003c/a\u003e Improve support for input Streams finishing before output is requested (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/lovell/sharp/compare/v0.34.5...v0.35.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.24.8 to 7.29.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.28.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e7 security advisories\u003c/strong\u003e, all shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 7.28.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^7.28.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe v7 line is \u003cstrong\u003enot\u003c/strong\u003e affected by GHSA-38rv-x7px-6hhq (CVE-2026-9675), which is\nan 8.x-only regression.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on GHSA-hm92-r4w5-c3mj:\u003c/strong\u003e this fix shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e, not the\nearlier 7.2x line — the vulnerable single-pool code was still present through\n\u003ccode\u003ev7.27.2\u003c/code\u003e. The per-origin pool fix is\n\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5041\"\u003e#5041\u003c/a\u003e).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAdvisory\u003c/th\u003e\n\u003cth\u003eCVE\u003c/th\u003e\n\u003cth\u003eSeverity (CVSS)\u003c/th\u003e\n\u003cth\u003eFixed in\u003c/th\u003e\n\u003cth\u003eFix commit\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-12151\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8cb10f98\"\u003e\u003ccode\u003e8cb10f98\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g\"\u003eGHSA-vmh5-mc38-953g\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9697\u003c/td\u003e\n\u003ctd\u003eHigh (7.4)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/04201f89\"\u003e\u003ccode\u003e04201f89\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj\"\u003eGHSA-hm92-r4w5-c3mj\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6734\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6\"\u003eGHSA-pr7r-676h-xcf6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9678\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/85a24055\"\u003e\u003ccode\u003e85a24055\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv\"\u003eGHSA-p88m-4jfj-68fv\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9679\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m\"\u003eGHSA-g8m3-5g58-fq7m\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-11525\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52\"\u003eGHSA-35p6-xmwp-9g52\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6733\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ea8930cf\"\u003e\u003ccode\u003eea8930cf\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f9eba0ad9134e1c0977848476bba9d49734696e4\"\u003e\u003ccode\u003ef9eba0a\u003c/code\u003e\u003c/a\u003e Bumped v7.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5430\"\u003e#5430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.24.8...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Medal-Social/Pilot/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Medal-Social/pilot/pull/164","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Medal-Social%2Fpilot/issues/164","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/164/packages"},{"uuid":"5427702766","node_id":"PR_kwDORH_RdM8AAAABDL0acw","number":103,"state":"closed","title":"chore(deps): bump the npm_and_yarn group across 2 directories with 10 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":"2026-09-11T18:29:01.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-11T18:25:56.000Z","updated_at":"2026-09-11T18:32:39.000Z","time_to_close":185,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":10,"packages":[{"name":"nodemailer","old_version":"9.0.3","new_version":"9.1.1","repository_url":"https://github.com/nodemailer/nodemailer"},{"name":"typeorm","old_version":"0.3.30","new_version":"0.3.31","repository_url":"https://github.com/typeorm/typeorm"},{"name":"next","old_version":"16.2.9","new_version":"16.3.5"},{"name":"postcss","old_version":"8.5.16","new_version":"8.5.28"},{"name":"undici","old_version":"7.28.0","new_version":"7.29.1","repository_url":"https://github.com/nodejs/undici"},{"name":"browserslist","old_version":"4.28.4","new_version":"4.28.9"},{"name":"form-data","old_version":"4.0.5","new_version":"4.0.6"},{"name":"js-yaml","old_version":"3.14.2","new_version":"3.15.2"},{"name":"nanoid","old_version":"3.3.15","new_version":"3.3.19"},{"name":"sharp","old_version":"0.34.5","new_version":"0.35.4"},{"name":"nodemailer","old_version":"9.0.3","new_version":"9.1.1","repository_url":"https://github.com/nodemailer/nodemailer"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 2 updates in the / directory: [nodemailer](https://github.com/nodemailer/nodemailer) and [typeorm](https://github.com/typeorm/typeorm).\nBumps the npm_and_yarn group with 2 updates in the /backend directory: [typeorm](https://github.com/typeorm/typeorm) and [undici](https://github.com/nodejs/undici).\n\nUpdates `nodemailer` from 9.0.3 to 9.1.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodemailer/nodemailer/releases\"\u003enodemailer's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev9.1.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.1.0...v9.1.1\"\u003e9.1.1\u003c/a\u003e (2026-09-01)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e apply the message access policy in resolveContent (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/dc48ed395c4d6c79ee5c95eb6eff17bafe391474\"\u003edc48ed3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e keep message data from reopening the access sandbox (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/ab7ef348b9a97b1fd70e7bfbeb56d4ea4a07946b\"\u003eab7ef34\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e inherit the access policy from the tree a node hangs in (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/262d550b1e121e3ff4ef6675d6771a5b2b4ddcec\"\u003e262d550\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev9.1.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.0.6...v9.1.0\"\u003e9.1.0\u003c/a\u003e (2026-08-31)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e cap recipients per message with maxRecipients (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/7279ac8dee4f66c032981e6e51e3e7210ad0dcbf\"\u003e7279ac8\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eaddressparser:\u003c/strong\u003e handle address lists in linear time (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/9116da9528c6524cefaed75185602a7e85d20434\"\u003e9116da9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eaddressparser:\u003c/strong\u003e terminate the domain at an RFC 5322 comment (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/902b63e935435c30f4025901c0902dce64cd8880\"\u003e902b63e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e apply UTS-46 mapping when encoding a domain (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/259c32d7d266301e3377a212776c3fff993c0148\"\u003e259c32d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e dedupe envelope recipients in linear time (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/7cc38af418ffa6fc7e86085195ca5ca681694b3e\"\u003e7cc38af\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e flatten parsed addresses without concat.apply (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/83b8c48cbdb8b3116f2e1ba84af755b2c5661c0f\"\u003e83b8c48\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e keep the recipient dedupe linear across address headers (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/34da64282dcdc9b0581c721a27ab2fa226673150\"\u003e34da642\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e keep URL delimiters away from the domain mapper (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/b212ac4e27bce8182478044fcb8d1642ccdad46e\"\u003eb212ac4\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev9.0.6\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.0.5...v9.0.6\"\u003e9.0.6\u003c/a\u003e (2026-08-27)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eaddressparser:\u003c/strong\u003e recover the addr-spec from an angle-addr holding whitespace (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/e989a22ca4f5161929bf37be8fb07de635016fa7\"\u003ee989a22\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eharden copies of user supplied keys and URL fetching (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/2f667f4272cb2d7cb479b2e3903ab10600fc0eae\"\u003e2f667f4\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev9.0.5\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.0.4...v9.0.5\"\u003e9.0.5\u003c/a\u003e (2026-08-07)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eci:\u003c/strong\u003e retrigger the workflows dropped during the Actions outage (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/85d16c103ec69e237c7e55c0e3103f439c135ce3\"\u003e85d16c1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e escape specials in List-* header comments (\u003ca href=\"https://redirect.github.com/nodemailer/nodemailer/issues/1842\"\u003e#1842\u003c/a\u003e) (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/75913bba032623046dd7fa037b8b880e388d8357\"\u003e75913bb\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-funcs:\u003c/strong\u003e star the continuation key of a restarted parameter line (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/36bcf1a21a92b5a283c780e35aacd3080292d98d\"\u003e36bcf1a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e keep control chars out of header values and msg-id headers (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/15cf6d1c15cdf60f551618fd54fb727ea7aac94c\"\u003e15cf6d1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime:\u003c/strong\u003e encode DEL in header parameters and List-* comments (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/cf69430ffac1d246bfbab564daf321f31ed9e1dd\"\u003ecf69430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime:\u003c/strong\u003e keep control chars out of the remaining header positions (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/5ed9d26f85eecb48f4b3ae74ad33ed2abf002040\"\u003e5ed9d26\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md\"\u003enodemailer's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.1.0...v9.1.1\"\u003e9.1.1\u003c/a\u003e (2026-09-01)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e apply the message access policy in resolveContent (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/dc48ed395c4d6c79ee5c95eb6eff17bafe391474\"\u003edc48ed3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e keep message data from reopening the access sandbox (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/ab7ef348b9a97b1fd70e7bfbeb56d4ea4a07946b\"\u003eab7ef34\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e inherit the access policy from the tree a node hangs in (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/262d550b1e121e3ff4ef6675d6771a5b2b4ddcec\"\u003e262d550\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.0.6...v9.1.0\"\u003e9.1.0\u003c/a\u003e (2026-08-31)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e cap recipients per message with maxRecipients (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/7279ac8dee4f66c032981e6e51e3e7210ad0dcbf\"\u003e7279ac8\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eaddressparser:\u003c/strong\u003e handle address lists in linear time (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/9116da9528c6524cefaed75185602a7e85d20434\"\u003e9116da9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eaddressparser:\u003c/strong\u003e terminate the domain at an RFC 5322 comment (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/902b63e935435c30f4025901c0902dce64cd8880\"\u003e902b63e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e apply UTS-46 mapping when encoding a domain (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/259c32d7d266301e3377a212776c3fff993c0148\"\u003e259c32d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e dedupe envelope recipients in linear time (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/7cc38af418ffa6fc7e86085195ca5ca681694b3e\"\u003e7cc38af\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e flatten parsed addresses without concat.apply (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/83b8c48cbdb8b3116f2e1ba84af755b2c5661c0f\"\u003e83b8c48\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e keep the recipient dedupe linear across address headers (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/34da64282dcdc9b0581c721a27ab2fa226673150\"\u003e34da642\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e keep URL delimiters away from the domain mapper (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/b212ac4e27bce8182478044fcb8d1642ccdad46e\"\u003eb212ac4\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.0.5...v9.0.6\"\u003e9.0.6\u003c/a\u003e (2026-08-27)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eaddressparser:\u003c/strong\u003e recover the addr-spec from an angle-addr holding whitespace (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/e989a22ca4f5161929bf37be8fb07de635016fa7\"\u003ee989a22\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eharden copies of user supplied keys and URL fetching (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/2f667f4272cb2d7cb479b2e3903ab10600fc0eae\"\u003e2f667f4\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.0.4...v9.0.5\"\u003e9.0.5\u003c/a\u003e (2026-08-07)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eci:\u003c/strong\u003e retrigger the workflows dropped during the Actions outage (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/85d16c103ec69e237c7e55c0e3103f439c135ce3\"\u003e85d16c1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e escape specials in List-* header comments (\u003ca href=\"https://redirect.github.com/nodemailer/nodemailer/issues/1842\"\u003e#1842\u003c/a\u003e) (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/75913bba032623046dd7fa037b8b880e388d8357\"\u003e75913bb\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-funcs:\u003c/strong\u003e star the continuation key of a restarted parameter line (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/36bcf1a21a92b5a283c780e35aacd3080292d98d\"\u003e36bcf1a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e keep control chars out of header values and msg-id headers (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/15cf6d1c15cdf60f551618fd54fb727ea7aac94c\"\u003e15cf6d1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime:\u003c/strong\u003e encode DEL in header parameters and List-* comments (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/cf69430ffac1d246bfbab564daf321f31ed9e1dd\"\u003ecf69430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime:\u003c/strong\u003e keep control chars out of the remaining header positions (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/5ed9d26f85eecb48f4b3ae74ad33ed2abf002040\"\u003e5ed9d26\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime:\u003c/strong\u003e normalize an address parsed out of a string as well (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/63685f7dd4aefa75cc72a36f983f32f61cd6733e\"\u003e63685f7\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime:\u003c/strong\u003e normalize an address so header and envelope agree (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/a9343b47e42b9ccb27911ad8e73d4119c6170c85\"\u003ea9343b4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime:\u003c/strong\u003e stop a header key callback and the dkim tags from injecting (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/b7d772ea4ec12ee82e65a9b919af882bf0f125d9\"\u003eb7d772e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/ad4513f2a179e0484f9c95948211c186ba3ce7c9\"\u003e\u003ccode\u003ead4513f\u003c/code\u003e\u003c/a\u003e chore(master): release 9.1.1 (\u003ca href=\"https://redirect.github.com/nodemailer/nodemailer/issues/1850\"\u003e#1850\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/c3e261f2a3c032f582ec2f76a19d468f42ef2fcc\"\u003e\u003ccode\u003ec3e261f\u003c/code\u003e\u003c/a\u003e docs: replace dead Node.js c-ares dependencies link (\u003ca href=\"https://redirect.github.com/nodemailer/nodemailer/issues/1845\"\u003e#1845\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/c158a388739b61baa6570fb4a3e70bd65d6d2a5f\"\u003e\u003ccode\u003ec158a38\u003c/code\u003e\u003c/a\u003e docs: mark 9.x as the supported security line (\u003ca href=\"https://redirect.github.com/nodemailer/nodemailer/issues/1846\"\u003e#1846\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/262d550b1e121e3ff4ef6675d6771a5b2b4ddcec\"\u003e\u003ccode\u003e262d550\u003c/code\u003e\u003c/a\u003e fix(mime-node): inherit the access policy from the tree a node hangs in\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/ab7ef348b9a97b1fd70e7bfbeb56d4ea4a07946b\"\u003e\u003ccode\u003eab7ef34\u003c/code\u003e\u003c/a\u003e fix(mailer): keep message data from reopening the access sandbox\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/dc48ed395c4d6c79ee5c95eb6eff17bafe391474\"\u003e\u003ccode\u003edc48ed3\u003c/code\u003e\u003c/a\u003e fix(mailer): apply the message access policy in resolveContent\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/efd6e29c10c6e0c25c57bd2f2a71302838235a4f\"\u003e\u003ccode\u003eefd6e29\u003c/code\u003e\u003c/a\u003e chore(master): release 9.1.0 (\u003ca href=\"https://redirect.github.com/nodemailer/nodemailer/issues/1849\"\u003e#1849\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/1f9533b33eafec5c38b0fc2a2e7338b950d9fe77\"\u003e\u003ccode\u003e1f9533b\u003c/code\u003e\u003c/a\u003e chore(deps): update dev dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/b212ac4e27bce8182478044fcb8d1642ccdad46e\"\u003e\u003ccode\u003eb212ac4\u003c/code\u003e\u003c/a\u003e fix(mime-node): keep URL delimiters away from the domain mapper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/6aa7e3fc5cfa587ae8694048afccdb5f1e3d2a43\"\u003e\u003ccode\u003e6aa7e3f\u003c/code\u003e\u003c/a\u003e refactor: fold review findings into the address parsing changes\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.0.3...v9.1.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `typeorm` from 0.3.30 to 0.3.31\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/typeorm/typeorm/releases\"\u003etypeorm's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.3.31\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ecache:\u003c/strong\u003e release query runner on error in storeInCache (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12545\"\u003e#12545\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/a84b9b3d39c44cc0e5809b4680a5f046bda602cd\"\u003ea84b9b3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ecorrect grammar in AlreadyHasActiveConnectionError message (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12554\"\u003e#12554\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/304d1290a4b6bd47d7d38269bae6a8514f378c9c\"\u003e304d129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eentity-manager:\u003c/strong\u003e default invalidWhereValuesBehavior to throw on the write path (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12690\"\u003e#12690\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/44d8052ba4d226364c26e722826340d4ceb1419b\"\u003e44d8052\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eentity-manager:\u003c/strong\u003e validate where criteria in increment/decrement (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12692\"\u003e#12692\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/8a51b756bf31c885da1e1d92cb17d94819c7040a\"\u003e8a51b75\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emongodb:\u003c/strong\u003e use cursor.transform for doc to entity transformation and skip load broadcast in next if toArray (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/11926\"\u003e#11926\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/0bbefc914ef69b3826a4a2075b0b008c9a02e807\"\u003e0bbefc9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003emove hashing function to PlatformTools (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12648\"\u003e#12648\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/c456cbd5d40aa2e797314bd202956449f64efbac\"\u003ec456cbd\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003emultiple recursive cte problems (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12490\"\u003e#12490\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/7c26654f430a7190c331242d68e75111fb334ea3\"\u003e7c26654\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enormalization of FindOptionsWhere for arrays and Buffers (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12577\"\u003e#12577\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/a8173fcdf325c44bf3eb2101c6318b45c573102b\"\u003ea8173fc\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003epersistence:\u003c/strong\u003e preserve select false columns on the in-memory entity after save() (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12501\"\u003e#12501\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/324c46cd8669270dd5f22173cd78a7cab591349c\"\u003e324c46c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003epostgres:\u003c/strong\u003e improve normalizeDatetimeFunction for tstzrange data type (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12182\"\u003e#12182\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/bf47c9f1171b15523292e8914cfbdcfee542ef07\"\u003ebf47c9f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003equery-builder:\u003c/strong\u003e reject empty where criteria on update and delete operations (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12629\"\u003e#12629\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/81b946625d84bcf3ce720fea7d406003270169ee\"\u003e81b9466\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003equery-builder:\u003c/strong\u003e wrap inner joins under left joins correctly (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/11137\"\u003e#11137\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/d5f4b9d7e0f0aca63a9dd66e7ae26a15f7e8eee0\"\u003ed5f4b9d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eremove \u003ccode\u003erequire()\u003c/code\u003e calls that break bundlers (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12647\"\u003e#12647\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/30f9fc717bcfaa472d56680437105a6b9581014d\"\u003e30f9fc7\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etree-entity:\u003c/strong\u003e tree entity schema propagation in internal TreeRepository methods (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12590\"\u003e#12590\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/7fb7c2c7c30d57489921eed458dfb97a5d08d4b8\"\u003e7fb7c2c\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/typeorm/typeorm/compare/0.3.30...0.3.31\"\u003ehttps://github.com/typeorm/typeorm/compare/0.3.30...0.3.31\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/typeorm/typeorm/blob/0.3.31/CHANGELOG.md\"\u003etypeorm's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/typeorm/typeorm/compare/0.3.30...0.3.31\"\u003e0.3.31\u003c/a\u003e (2026-07-13)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003edocs:\u003c/strong\u003e correct project name in release flow (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12519\"\u003e#12519\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/3b9faa31ced080db2073cd92c42905dd402fa636\"\u003e3b9faa3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edocs:\u003c/strong\u003e resolve docs workflow issues (\u003ca href=\"https://github.com/typeorm/typeorm/commit/c3c09b043f68ad4b19cc7b02bbeb85e2f720305c\"\u003ec3c09b0\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edocs:\u003c/strong\u003e resolve docs workflow issues (\u003ca href=\"https://github.com/typeorm/typeorm/commit/f7b4b634647bd1a3e340fa421760183ebfb867be\"\u003ef7b4b63\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eentity-manager:\u003c/strong\u003e validate where criteria in increment/decrement (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12692\"\u003e#12692\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/a69a8c6816a493461f043c3bce8364a51fbf91ce\"\u003ea69a8c6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emigration:\u003c/strong\u003e escape backslashes and interpolation in generated template literals (\u003ca href=\"https://github.com/typeorm/typeorm/commit/b175f9b8be422edd2a2ac035ba90c3f2ce782dfe\"\u003eb175f9b\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enormalization of FindOptionsWhere for arrays and Buffers (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12577\"\u003e#12577\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/a309182c4495c8606dea96ed71ab3f2236663d64\"\u003ea309182\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003epersistence:\u003c/strong\u003e preserve select false columns on the in-memory entity after save() (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12501\"\u003e#12501\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/d8e91274662b85effbf6c79ff5d7379970839d27\"\u003ed8e9127\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003equery-builder:\u003c/strong\u003e reject empty where criteria on update and delete operations (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12629\"\u003e#12629\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/dfd972b80b9c79f4df429cd4a3cf171481928874\"\u003edfd972b\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etree-entity:\u003c/strong\u003e tree entity schema propagation in internal TreeRepository methods (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12590\"\u003e#12590\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/e1f93da606576660b7e907c9f8d90520394ed495\"\u003ee1f93da\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typeorm/typeorm/commit/797320375fb83b2e9af4a6455e0b1b4483be329d\"\u003e\u003ccode\u003e7973203\u003c/code\u003e\u003c/a\u003e ci: publish to npm from \u003ccode\u003ev0\u003c/code\u003e using the \u003ccode\u003elegacy\u003c/code\u003e tag\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typeorm/typeorm/commit/92e92767e3b9567bb97ca7552c752e8a57c15518\"\u003e\u003ccode\u003e92e9276\u003c/code\u003e\u003c/a\u003e ci: use \u003ccode\u003enpm@11\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typeorm/typeorm/commit/099c23ef51caf86407a06c7292881316337d7db3\"\u003e\u003ccode\u003e099c23e\u003c/code\u003e\u003c/a\u003e chore: prepare release 0.3.31 (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12676\"\u003e#12676\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typeorm/typeorm/commit/b175f9b8be422edd2a2ac035ba90c3f2ce782dfe\"\u003e\u003ccode\u003eb175f9b\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typeorm/typeorm/commit/a69a8c6816a493461f043c3bce8364a51fbf91ce\"\u003e\u003ccode\u003ea69a8c6\u003c/code\u003e\u003c/a\u003e fix(entity-manager): validate where criteria in increment/decrement (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12692\"\u003e#12692\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typeorm/typeorm/commit/dfd972b80b9c79f4df429cd4a3cf171481928874\"\u003e\u003ccode\u003edfd972b\u003c/code\u003e\u003c/a\u003e fix(query-builder): reject empty where criteria on update and delete operatio...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typeorm/typeorm/commit/a2d43639fdd762192a4d25716b6750a5618dfaf0\"\u003e\u003ccode\u003ea2d4363\u003c/code\u003e\u003c/a\u003e chore: update deps (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12661\"\u003e#12661\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typeorm/typeorm/commit/e1f93da606576660b7e907c9f8d90520394ed495\"\u003e\u003ccode\u003ee1f93da\u003c/code\u003e\u003c/a\u003e fix(tree-entity): tree entity schema propagation in internal TreeRepository m...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typeorm/typeorm/commit/a309182c4495c8606dea96ed71ab3f2236663d64\"\u003e\u003ccode\u003ea309182\u003c/code\u003e\u003c/a\u003e fix: normalization of FindOptionsWhere for arrays and Buffers (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12577\"\u003e#12577\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typeorm/typeorm/commit/d8e91274662b85effbf6c79ff5d7379970839d27\"\u003e\u003ccode\u003ed8e9127\u003c/code\u003e\u003c/a\u003e fix(persistence): preserve select false columns on the in-memory entity after...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/typeorm/typeorm/compare/0.3.30...0.3.31\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `next` from 16.2.9 to 16.3.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003enext's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.4\u003c/h2\u003e\n\u003cp\u003eFollow-up release to \u003ca href=\"https://github.com/vercel/next.js/releases/tag/v16.3.3\"\u003ev16.3.3\u003c/a\u003e re-enabling AVIF Image Optimization (\u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97949\"\u003e#97949\u003c/a\u003e).\u003c/p\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003etestmode: Fix infinite recursion in testmode passthrough fetch (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97691\"\u003e#97691\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix build error when aliasing typescript to \u003ccode\u003e@​typescript/typescript6\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97997\"\u003e#97997\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix unset crossOrigin in Turbopack manifests (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97930\"\u003e#97930\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.3\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eCritical:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36\"\u003eUnauthenticated Remote Code Execution on windows-hosted servers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4\"\u003eUnauthenticated Remote Code Execution in Image Optimization API when AVIF files are used\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.2\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Scope app-entry export validation to files inside the app directory (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97357\"\u003e#97357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[backport] Fix catch-all index page being served for every other slug (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97416\"\u003e#97416\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: don't trace embedded WASM loader helpers (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97353\"\u003e#97353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97463\"\u003e#97463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: retain conditions when replacing resolve request keys (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97453\"\u003e#97453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Fix Turbopack worker chunk loading with asset prefix (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97419\"\u003e#97419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97603\"\u003e#97603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/lubieowoce\"\u003e\u003ccode\u003e@​lubieowoce\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[16.x] Turbopack: don't strip async-module runtime from shared runtime chunks by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96653\"\u003evercel/next.js#96653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] [turbopack] Add \u003ccode\u003eturbopack_ecmascript\u003c/code\u003e and \u003ccode\u003eturbopack_wasm\u003c/code\u003e's embeded FS to \u003ccode\u003einternal_assets_conditions\u003c/code\u003e by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96655\"\u003evercel/next.js#96655\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] [turbopack] Collapse nested promises in the analyzer by \u003ca href=\"https://github.com/sampoder\"\u003e\u003ccode\u003e@​sampoder\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96675\"\u003evercel/next.js#96675\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] fix(next/image): preserve image response after optimization by \u003ca href=\"https://github.com/styfle\"\u003e\u003ccode\u003e@​styfle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96733\"\u003evercel/next.js#96733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.3.x] Default deploy e2e tests to the repo next version by \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96900\"\u003evercel/next.js#96900\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Bump \u003ccode\u003e@​swc/helpers\u003c/code\u003e by \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96885\"\u003evercel/next.js#96885\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [turbopack] Raise registration calls in hoisted modules to the top by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97308\"\u003evercel/next.js#97308\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Fix missing styled-jsx styles in Pages Router SSR on adapter builds by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97302\"\u003evercel/next.js#97302\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [turbopack] Fix HMR for dynamic imports evaluated from layouts by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97317\"\u003evercel/next.js#97317\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Restore the live \u003ccode\u003eheaders()\u003c/code\u003e view of the incoming request by \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97311\"\u003evercel/next.js#97311\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/ca2c75eb7f8d9dd012a8bb83c06132149fe221f9\"\u003e\u003ccode\u003eca2c75e\u003c/code\u003e\u003c/a\u003e v16.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/14fb290de65077e9f1e22ef56d8de6cc1e63d436\"\u003e\u003ccode\u003e14fb290\u003c/code\u003e\u003c/a\u003e [backport] Fix use cache prerender signal retention (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98448\"\u003e#98448\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/2b1f28dbe1de344807ec0946a85171bc890a6047\"\u003e\u003ccode\u003e2b1f28d\u003c/code\u003e\u003c/a\u003e [16.3.x] Add CSP nonce to script tags of loading and template files (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98403\"\u003e#98403\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/4b56cee3f01d3b249edcd798b51895d5126a4170\"\u003e\u003ccode\u003e4b56cee\u003c/code\u003e\u003c/a\u003e [16.3.x] Backport docs fixes (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98317\"\u003e#98317\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/5568a02a7d47f9cb088e58350f2c2e68d9e93a00\"\u003e\u003ccode\u003e5568a02\u003c/code\u003e\u003c/a\u003e [backport] docs: local development: Rewrite docker section, add Windows Dev D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/93249ab2144132abfd4a8d611dad5b5978107ee2\"\u003e\u003ccode\u003e93249ab\u003c/code\u003e\u003c/a\u003e [16.3.X] Emit whole-app server NFTs when \u003ccode\u003eoutput: 'standalone'\u003c/code\u003e is used with ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/6549fd7c4e15a8883b0ad1c2ef67dec287a44f12\"\u003e\u003ccode\u003e6549fd7\u003c/code\u003e\u003c/a\u003e [16.3.x] next/image: reject empty image on read/write to disk cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98186\"\u003e#98186\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/d9eac96e7526ff0b9cb51db9801f06e741fe1960\"\u003e\u003ccode\u003ed9eac96\u003c/code\u003e\u003c/a\u003e [16.3.x] next/image: skip 0-byte entries when initializing disk LRU cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/9\"\u003e#9\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/84b35feccb2b53a563e41ad2dfe7a5fe08c58d3f\"\u003e\u003ccode\u003e84b35fe\u003c/code\u003e\u003c/a\u003e [test] Fix 16.3 deploy test assertions (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98133\"\u003e#98133\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/14f9c1ac4e084a44633c354476ddeaf70969cd90\"\u003e\u003ccode\u003e14f9c1a\u003c/code\u003e\u003c/a\u003e [16.3.x][ci] Run flake detection and new deploy tests when merged and on back...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/compare/v16.2.9...v16.3.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.16 to 8.5.28\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.28\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes types regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed removing any comments starting with \u003ccode\u003e/*#\u003c/code\u003e (by \u003ca href=\"https://github.com/dylanpulver\"\u003e\u003ccode\u003e@​dylanpulver\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e*\u003c/code\u003e hack before a comment in Custom Properties (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed empty values in the middle of \u003ccode\u003elist.comma()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed whitespace-only values in \u003ccode\u003elist.space()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed rule’s end position on space before semicolon (by \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/romainmenke\"\u003e\u003ccode\u003e@​romainmenke\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed Chinese text in deprecation warning (by \u003ca href=\"https://github.com/Jesse205\"\u003e\u003ccode\u003e@​Jesse205\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.28\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes types regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed removing any comments starting with \u003ccode\u003e/*#\u003c/code\u003e (by \u003ca href=\"https://github.com/dylanpulver\"\u003e\u003ccode\u003e@​dylanpulver\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e*\u003c/code\u003e hack before a comment in Custom Properties (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed empty values in the middle of \u003ccode\u003elist.comma()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed whitespace-only values in \u003ccode\u003elist.space()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed rule’s end position on space before semicolon (by \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/romainmenke\"\u003e\u003ccode\u003e@​romainmenke\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed Chinese text in deprecation warning (by \u003ca href=\"https://github.com/Jesse205\"\u003e\u003ccode\u003e@​Jesse205\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/e544bffc4f4b3966d8ec69c41744b3ed65afc64a\"\u003e\u003ccode\u003ee544bff\u003c/code\u003e\u003c/a\u003e Release 8.5.28 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f8fc2525717a6a7216659f7be43c525f60c6a15a\"\u003e\u003ccode\u003ef8fc252\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/5039fd78962d285abea5d7b3aebef32f053781ce\"\u003e\u003ccode\u003e5039fd7\u003c/code\u003e\u003c/a\u003e Add missed release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/ae40ca499cf6a9afdbb264c0ec09e71fe934e2af\"\u003e\u003ccode\u003eae40ca4\u003c/code\u003e\u003c/a\u003e Release 8.5.27 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/62b1626bb7fbb28eda616d002cbd525d239b18ba\"\u003e\u003ccode\u003e62b1626\u003c/code\u003e\u003c/a\u003e Fix linter\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/1dba9384515a2dbc64517697c2f738b6d5c3f9a4\"\u003e\u003ccode\u003e1dba938\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3e82edc9f037faa41647342dceceba9b841f9881\"\u003e\u003ccode\u003e3e82edc\u003c/code\u003e\u003c/a\u003e Keep non-annotation comments when the processor has no plugins (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2150\"\u003e#2150\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/6d23bc362203118478bc8051b81f2910907ebe6e\"\u003e\u003ccode\u003e6d23bc3\u003c/code\u003e\u003c/a\u003e Fix link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/508e9976be81536292e7666741e1c35e876b9a6a\"\u003e\u003ccode\u003e508e997\u003c/code\u003e\u003c/a\u003e Add GitHub Sponsors link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/e993739dc49b6055f7dfc59b161d75702f0b2b8b\"\u003e\u003ccode\u003ee993739\u003c/code\u003e\u003c/a\u003e Add CodeRabbit sponsor (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2145\"\u003e#2145\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.16...8.5.28\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.28.0 to 7.29.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `browserslist` from 4.28.4 to 4.28.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/releases\"\u003ebrowserslist's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eincluding kaios\u003c/code\u003e in baseline queries (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved parsing performance.\u003c/li\u003e\n\u003cli\u003eFixed unbounded memory growth (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed prototype write issue (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Electron version queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003e\u0026gt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;=\u003c/code\u003e queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md\"\u003ebrowserslist's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eincluding kaios\u003c/code\u003e in baseline queries (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved parsing performance.\u003c/li\u003e\n\u003cli\u003eFixed unbounded memory growth (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed prototype write issue (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Electron version queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003e\u0026gt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;=\u003c/code\u003e queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/12ed5252dabc14fee4e97b465894b2f90910ca62\"\u003e\u003ccode\u003e12ed525\u003c/code\u003e\u003c/a\u003e Release 4.28.9 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/b1d8cf9d7a7dc76f6585425a8360218289194297\"\u003e\u003ccode\u003eb1d8cf9\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/21517b651c915cdbbfb8c122268bc36f5cabb7ef\"\u003e\u003ccode\u003e21517b6\u003c/code\u003e\u003c/a\u003e Improve \u003ccode\u003eor\u003c/code\u003e parsing performance\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/f2f2e6cfb01bb4942941d328737546f4e2ae41ad\"\u003e\u003ccode\u003ef2f2e6c\u003c/code\u003e\u003c/a\u003e Release 4.28.8 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/d0787c88fa29ba895fea51cfe921232c7b5d1377\"\u003e\u003ccode\u003ed0787c8\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/fcf8fa9857b30ccdf801a548f5d09d3c4ff0d43f\"\u003e\u003ccode\u003efcf8fa9\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/browserslist/browserslist/issues/939\"\u003e#939\u003c/a\u003e from Jaybhade/fix/baseline-kaios-without-downstream\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/57ecd64454e9252afdd6a7e76926e13dda48a38c\"\u003e\u003ccode\u003e57ecd64\u003c/code\u003e\u003c/a\u003e fix: support \u0026quot;including kaios\u0026quot; without downstream\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/093a0f67bb0becda55235d767b134df3197c54a1\"\u003e\u003ccode\u003e093a0f6\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/b637868045806d2fba4c24eb0060e4cc8b1db276\"\u003e\u003ccode\u003eb637868\u003c/code\u003e\u003c/a\u003e Release 4.28.7 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/313f4659b9f985ade89d1d6a54a860371c41cc46\"\u003e\u003ccode\u003e313f465\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/browserslist/browserslist/compare/4.28.4...4.28.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `form-data` from 4.0.5 to 4.0.6\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/form-data/form-data/blob/master/CHANGELOG.md\"\u003eform-data's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/form-data/form-data/compare/v4.0.5...v4.0.6\"\u003ev4.0.6\u003c/a\u003e - 2026-06-12\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] escape CR, LF, and \u003ccode\u003e\u0026quot;\u003c/code\u003e in field names and filenames \u003ca href=\"https://github.com/form-data/form-data/commit/8dff42c6da654ed4e7ad4acb7f8ccd3831217c99\"\u003e\u003ccode\u003e8dff42c\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003etape\u003c/code\u003e \u003ca href=\"https://github.com/form-data/form-data/commit/f31d21ef10bf46e46344c3ee4f99acbef6be43e1\"\u003e\u003ccode\u003ef31d21e\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Deps] update \u003ccode\u003ehasown\u003c/code\u003e, \u003ccode\u003emime-types\u003c/code\u003e \u003ca href=\"https://github.com/form-data/form-data/commit/92ae0eb5da94d6f01925d5f4fcffb2a1e50ed7cd\"\u003e\u003ccode\u003e92ae0eb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003ejs-randomness-predictor\u003c/code\u003e \u003ca href=\"https://github.com/form-data/form-data/commit/67b0f65c2e0b065a511d42227d35e4d367644e97\"\u003e\u003ccode\u003e67b0f65\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/form-data/form-data/commit/64190db548c0179e37206858e39f27cf513e9435\"\u003e\u003ccode\u003e64190db\u003c/code\u003e\u003c/a\u003e v4.0.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/form-data/form-data/commit/92ae0eb5da94d6f01925d5f4fcffb2a1e50ed7cd\"\u003e\u003ccode\u003e92ae0eb\u003c/code\u003e\u003c/a\u003e [Deps] update \u003ccode\u003ehasown\u003c/code\u003e, \u003ccode\u003emime-types\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/form-data/form-data/commit/f31d21ef10bf46e46344c3ee4f99acbef6be43e1\"\u003e\u003ccode\u003ef31d21e\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003etape\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/form-data/form-data/commit/8dff42c6da654ed4e7ad4acb7f8ccd3831217c99\"\u003e\u003ccode\u003e8dff42c\u003c/code\u003e\u003c/a\u003e [Fix] escape CR, LF, and \u003ccode\u003e\u0026quot;\u003c/code\u003e in field names and filenames\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/form-data/form-data/commit/67b0f65c2e0b065a511d42227d35e4d367644e97\"\u003e\u003ccode\u003e67b0f65\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003ejs-randomness-predictor\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/form-data/form-data/compare/v4.0.5...v4.0.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `js-yaml` from 3.14.2 to 3.15.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md\"\u003ejs-yaml's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.15.2 - 2026-08-26\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Hard-limit merge sequence size to 100.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Count empty mappings in merge sequences toward \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e\nto limit CPU usage, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/797\"\u003e#797\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.15.1 - 2026-07-31\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Remove quadratic complexity from \u003ccode\u003e!!omap\u003c/code\u003e duplicate key detection.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.15.0 - 2026-06-27\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e (10000) loader option to limit the total number of\nkeys processed by YAML merge (\u003ccode\u003e\u0026lt;\u0026lt;\u003c/code\u003e) across one \u003ccode\u003esafeLoad()\u003c/code\u003e / \u003ccode\u003esafeLoadAll()\u003c/code\u003e\ncall.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/5c45bd6e960603c13644f5cc8b572ca257723b36\"\u003e\u003ccode\u003e5c45bd6\u003c/code\u003e\u003c/a\u003e 3.15.2 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/5a708f9f4f22e78b87ebe363848cfa4fa4818c0d\"\u003e\u003ccode\u003e5a708f9\u003c/code\u003e\u003c/a\u003e dist rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/3485bc06ff8a0251505f44a00414d90df2466639\"\u003e\u003ccode\u003e3485bc0\u003c/code\u003e\u003c/a\u003e Backport merge limits from v5.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/f34812f1cea794f8c21e0a4e1f3a2584b720f305\"\u003e\u003ccode\u003ef34812f\u003c/code\u003e\u003c/a\u003e Update .gitignore\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/ab85ae2c622bc6d8cdbceccafe9f9b7df80463ed\"\u003e\u003ccode\u003eab85ae2\u003c/code\u003e\u003c/a\u003e 3.15.1 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/30a5e7647a4454f7bac969bfbbe7eac9921a4279\"\u003e\u003ccode\u003e30a5e76\u003c/code\u003e\u003c/a\u003e dist rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/22a8071ef032117bc6249c330b240ac3aa2d3ded\"\u003e\u003ccode\u003e22a8071\u003c/code\u003e\u003c/a\u003e Backport quadratic complexity fix for !!omap\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/c34b6c40027a769eb0d67958ae615268a1d55f54\"\u003e\u003ccode\u003ec34b6c4\u003c/code\u003e\u003c/a\u003e 3.15.0 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/21e13d363f33501c7ee6ca988b88c29084999f72\"\u003e\u003ccode\u003e21e13d3\u003c/code\u003e\u003c/a\u003e dist rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/4165c62630d64fe4f25fb0d03139c7e137b24b1c\"\u003e\u003ccode\u003e4165c62\u003c/code\u003e\u003c/a\u003e Add v3-legacy tag for publish\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodeca/js-yaml/compare/3.14.2...3.15.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nanoid` from 3.3.15 to 3.3.19\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/releases\"\u003enanoid's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/blob/main/CHANGELOG.md\"\u003enanoid's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID (by \u003ca href=\"https://github.com/geoffrey-diederichs\"\u003e\u003ccode\u003e@​geoffrey-diederichs\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/eb63bd6775188dc35d143bf24868be094f19b5ee\"\u003e\u003ccode\u003eeb63bd6\u003c/code\u003e\u003c/a\u003e Release 3.3.19 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9067e0361a643ab2c94ddd67606efbf275f6c0dd\"\u003e\u003ccode\u003e9067e03\u003c/code\u003e\u003c/a\u003e Sync CJS and ESM\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9ad98052b316c5e707f8098ace509d2ae165e54d\"\u003e\u003ccode\u003e9ad9805\u003c/code\u003e\u003c/a\u003e Release 3.3.18 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/55e50a0621ec084b4bb4000ea4e86e1191bd3da8\"\u003e\u003ccode\u003e55e50a0\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e10f8d40ce9d1ab47f66d65a16b48086432730d0\"\u003e\u003ccode\u003ee10f8d4\u003c/code\u003e\u003c/a\u003e Update index.native.js (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/606\"\u003e#606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/73d67168136b36fd3b644159b0cff149da4905d9\"\u003e\u003ccode\u003e73d6716\u003c/code\u003e\u003c/a\u003e Release 3.3.17 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/f9d13f150847d117877adee3460a46eceb0cf49b\"\u003e\u003ccode\u003ef9d13f1\u003c/code\u003e\u003c/a\u003e Sync 0 size behaviour with PostCSS 5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9760e112757cf7d46a79abd7a133bc4958757bb8\"\u003e\u003ccode\u003e9760e11\u003c/code\u003e\u003c/a\u003e Release 3.3.16 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66d\"\u003e\u003ccode\u003ee835c9b\u003c/code\u003e\u003c/a\u003e fix(non-secure): clamp negative size to prevent infinite loop (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/601\"\u003e#601\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/96dd086eb24396a275fa93ee78d73b2fece35809\"\u003e\u003ccode\u003e96dd086\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ai/nanoid/compare/3.3.15...3.3.19\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `sharp` from 0.34.5 to 0.35.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lovell/sharp/releases\"\u003esharp's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.35.4\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\"\u003ehttps://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.35.4-rc.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpgrade to libvips v8.18.6 for upstream bug fixes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7f1a0a22cc285fe180766f4935d50b55af6e8432\"\u003e\u003ccode\u003e7f1a0a2\u003c/code\u003e\u003c/a\u003e Release v0.35.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/f927818924bc5a9493d822a4e8b23ec5857c52e1\"\u003e\u003ccode\u003ef927818\u003c/code\u003e\u003c/a\u003e Upgrade to sharp-libvips v1.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e80209240d005c71e1173a50dd9cd4db4ce2a9e6\"\u003e\u003ccode\u003ee802092\u003c/code\u003e\u003c/a\u003e Prerelease v0.35.4-rc.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e13eb2f97a0a22f1ef726e8d0cd33f7c56835945\"\u003e\u003ccode\u003ee13eb2f\u003c/code\u003e\u003c/a\u003e CI: Fix wasm32 build (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4589\"\u003e#4589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/a82a0b3d58bc25854ad1e925e6eb0a50725d1489\"\u003e\u003ccode\u003ea82a0b3\u003c/code\u003e\u003c/a\u003e Upgrade to libvips v8.18.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/8044fe43e36d0ea7f8beb89f79a37bb0f3342e84\"\u003e\u003ccode\u003e8044fe4\u003c/code\u003e\u003c/a\u003e Bound resize dimensions to coordinate limit\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/147f8591a153bc4a1e199c3fe3150fac2931b30c\"\u003e\u003ccode\u003e147f859\u003c/code\u003e\u003c/a\u003e Docs: changelog entries for \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4578\"\u003e#4578\u003c/a\u003e \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ee5bfb853de75a611c64381783b04032a3a897d8\"\u003e\u003ccode\u003eee5bfb8\u003c/code\u003e\u003c/a\u003e Tests: use yauzl directly rather than via extract-zip wrapper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7a7788928f8a2a429f45039010a87cee35401694\"\u003e\u003ccode\u003e7a77889\u003c/code\u003e\u003c/a\u003e Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4588\"\u003e#4588\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ea5bef24c187b2c7ee3fe3cad3b45c8cb67a46fd\"\u003e\u003ccode\u003eea5bef2\u003c/code\u003e\u003c/a\u003e Improve support for input Streams finishing before output is requested (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/lovell/sharp/compare/v0.34.5...v0.35.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nodemailer` from 9.0.3 to 9.1.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodemailer/nodemailer/releases\"\u003enodemailer's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev9.1.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.1.0...v9.1.1\"\u003e9.1.1\u003c/a\u003e (2026-09-01)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e apply the message access policy in resolveContent (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/dc48ed395c4d6c79ee5c95eb6eff17bafe391474\"\u003edc48ed3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e keep message data from reopening the access sandbox (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/ab7ef348b9a97b1fd70e7bfbeb56d4ea4a07946b\"\u003eab7ef34\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e inherit the access policy from the tree a node hangs in (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/262d550b1e121e3ff4ef6675d6771a5b2b4ddcec\"\u003e262d550\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev9.1.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.0.6...v9.1.0\"\u003e9.1.0\u003c/a\u003e (2026-08-31)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e cap recipients per message with maxRecipients (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/7279ac8dee4f66c032981e6e51e3e7210ad0dcbf\"\u003e7279ac8\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eaddressparser:\u003c/strong\u003e handle address lists in linear time (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/9116da9528c6524cefaed75185602a7e85d20434\"\u003e9116da9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eaddressparser:\u003c/strong\u003e terminate the domain at an RFC 5322 comment (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/902b63e935435c30f4025901c0902dce64cd8880\"\u003e902b63e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e apply UTS-46 mapping when encoding a domain (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/259c32d7d266301e3377a212776c3fff993c0148\"\u003e259c32d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e dedupe envelope recipients in linear time (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/7cc38af418ffa6fc7e86085195ca5ca681694b3e\"\u003e7cc38af\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e flatten parsed addresses without concat.apply (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/83b8c48cbdb8b3116f2e1ba84af755b2c5661c0f\"\u003e83b8c48\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e keep the recipient dedupe linear across address headers (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/34da64282dcdc9b0581c721a27ab2fa226673150\"\u003e34da642\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e keep URL delimiters away from the domain mapper (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/b212ac4e27bce8182478044fcb8d1642ccdad46e\"\u003eb212ac4\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev9.0.6\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.0.5...v9.0.6\"\u003e9.0.6\u003c/a\u003e (2026-08-27)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eaddressparser:\u003c/strong\u003e recover the addr-spec from an angle-addr holding whitespace (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/e989a22ca4f5161929bf37be8fb07de635016fa7\"\u003ee989a22\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eharden copies of user supplied keys and URL fetching (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/2f667f4272cb2d7cb479b2e3903ab10600fc0eae\"\u003e2f667f4\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev9.0.5\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.0.4...v9.0.5\"\u003e9.0.5\u003c/a\u003e (2026-08-07)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eci:\u003c/strong\u003e retrigger the workflows dropped during the Actions outage (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/85d16c103ec69e237c7e55c0e3103f439c135ce3\"\u003e85d16c1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e escape specials in List-* header comments (\u003ca href=\"https://redirect.github.com/nodemailer/nodemailer/issues/1842\"\u003e#1842\u003c/a\u003e) (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/75913bba032623046dd7fa037b8b880e388d8357\"\u003e75913bb\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-funcs:\u003c/strong\u003e star the continuation key of a restarted parameter line (\u003ca href=\"...\n\n_Description has been truncated_","html_url":"https://github.com/iam-dev/oms-nest/pull/103","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/iam-dev%2Foms-nest/issues/103","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/103/packages"},{"uuid":"5427651950","node_id":"PR_kwDOQlxMks8AAAABDLxzYQ","number":177,"state":"open","title":"Chore(deps): bump the minor-and-patch group across 1 directory with 17 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T18:19:40.000Z","updated_at":"2026-09-11T18:24:41.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Chore(deps): bump","group_name":"minor-and-patch","update_count":17,"packages":[{"name":"@swc/core","old_version":"1.16.1","new_version":"1.16.2","repository_url":"https://github.com/swc-project/swc"},{"name":"eslint","old_version":"10.9.1","new_version":"10.10.0","repository_url":"https://github.com/eslint/eslint"},{"name":"squawk-cli","old_version":"2.63.0","new_version":"2.64.0","repository_url":"https://github.com/sbdchd/squawk"},{"name":"tuffgal","old_version":"0.2.0-alpha.8","new_version":"0.3.0-alpha.1","repository_url":"https://github.com/nschneble/tuffgal"},{"name":"typescript-eslint","old_version":"8.68.0","new_version":"8.70.0","repository_url":"https://github.com/typescript-eslint/typescript-eslint"},{"name":"pg-boss","old_version":"12.28.0","new_version":"12.30.0","repository_url":"https://github.com/timgit/pg-boss"},{"name":"undici","old_version":"8.10.0","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"},{"name":"@eslint/eslintrc","old_version":"3.3.6","new_version":"3.3.7","repository_url":"https://github.com/eslint/eslintrc"},{"name":"@types/node","old_version":"26.4.0","new_version":"26.5.0","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"globals","old_version":"17.11.0","new_version":"17.12.0","repository_url":"https://github.com/sindresorhus/globals"},{"name":"jest","old_version":"30.4.2","new_version":"30.5.1","repository_url":"https://github.com/jestjs/jest"},{"name":"react-router","old_version":"8.3.0","new_version":"8.3.1","repository_url":"https://github.com/remix-run/react-router"},{"name":"@testing-library/user-event","old_version":"14.6.6","new_version":"14.6.7","repository_url":"https://github.com/testing-library/user-event"},{"name":"@types/react-dom","old_version":"19.2.5","new_version":"19.2.7","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"@vitejs/plugin-react","old_version":"6.1.0","new_version":"6.1.1","repository_url":"https://github.com/vitejs/vite-plugin-react"},{"name":"eslint-plugin-react-refresh","old_version":"0.5.5","new_version":"0.5.6","repository_url":"https://github.com/ArnaudBarre/eslint-plugin-react-refresh"},{"name":"subset-font","old_version":"2.5.0","new_version":"2.7.0","repository_url":"https://github.com/papandreou/subset-font"}],"path":null,"ecosystem":"npm"},"body":"Bumps the minor-and-patch group with 17 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@swc/core](https://github.com/swc-project/swc/tree/HEAD/packages/core) | `1.16.1` | `1.16.2` |\n| [eslint](https://github.com/eslint/eslint) | `10.9.1` | `10.10.0` |\n| [squawk-cli](https://github.com/sbdchd/squawk) | `2.63.0` | `2.64.0` |\n| [tuffgal](https://github.com/nschneble/tuffgal) | `0.2.0-alpha.8` | `0.3.0-alpha.1` |\n| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.68.0` | `8.70.0` |\n| [pg-boss](https://github.com/timgit/pg-boss) | `12.28.0` | `12.30.0` |\n| [undici](https://github.com/nodejs/undici) | `8.10.0` | `8.10.2` |\n| [@eslint/eslintrc](https://github.com/eslint/eslintrc) | `3.3.6` | `3.3.7` |\n| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.4.0` | `26.5.0` |\n| [globals](https://github.com/sindresorhus/globals) | `17.11.0` | `17.12.0` |\n| [jest](https://github.com/jestjs/jest/tree/HEAD/packages/jest) | `30.4.2` | `30.5.1` |\n| [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router) | `8.3.0` | `8.3.1` |\n| [@testing-library/user-event](https://github.com/testing-library/user-event) | `14.6.6` | `14.6.7` |\n| [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom) | `19.2.5` | `19.2.7` |\n| [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) | `6.1.0` | `6.1.1` |\n| [eslint-plugin-react-refresh](https://github.com/ArnaudBarre/eslint-plugin-react-refresh) | `0.5.5` | `0.5.6` |\n| [subset-font](https://github.com/papandreou/subset-font) | `2.5.0` | `2.7.0` |\n\n\nUpdates `@swc/core` from 1.16.1 to 1.16.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/swc-project/swc/blob/main/CHANGELOG.md\"\u003e@​swc/core's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.16.2] - 2026-09-04\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/compat)\u003c/strong\u003e Preserve for-of var binding scope (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12158\"\u003e#12158\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/f6d5bd12bf267dbb2e1551ccacd82b198e6edc6f\"\u003ef6d5bd1\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/decorators)\u003c/strong\u003e Drop params from getter replacing decorated private method (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12161\"\u003e#12161\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/d56f5943861178b91ff6e718bddb10e997da1a8c\"\u003ed56f594\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/flow)\u003c/strong\u003e Preserve Flow component type semantics (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12090\"\u003e#12090\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/c8d5b497c4895367b0902bde42b3f6a3fa5b7c24\"\u003ec8d5b49\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/minifier)\u003c/strong\u003e Mark for update and test as executed multiple time (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12131\"\u003e#12131\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/1260e362fd9bb15cf93b2d3ce595290c7ff272cf\"\u003e1260e36\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/minifier)\u003c/strong\u003e Report for loop var decl as assign (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12136\"\u003e#12136\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/783bbc29c8ccbc7d2dfa73860dd2765ee09d459d\"\u003e783bbc2\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/minifier)\u003c/strong\u003e Don't replace value-used console.*.bind() calls with undefined (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12138\"\u003e#12138\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/ed742230471f5462da9f24a8a4c1566d8fa8ef68\"\u003eed74223\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/minifier)\u003c/strong\u003e Drop spans of cached \u003ccode\u003eglobals\u003c/code\u003e values (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12129\"\u003e#12129\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/9a306b890ac9d4fc8698faf6c55ff95e82983585\"\u003e9a306b8\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/minifier)\u003c/strong\u003e Preserve effects of returned value calls (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12140\"\u003e#12140\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/c37b5a954794cf0e4cfa419868899385f067bc05\"\u003ec37b5a9\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/minifier)\u003c/strong\u003e Avoid JSX sequence inlining loop (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12149\"\u003e#12149\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/4e79b94930d7fc21b794f3c480fea4c9f8f8344e\"\u003e4e79b94\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/minifier)\u003c/strong\u003e Preserve bindings in copied inline arrows (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12141\"\u003e#12141\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/cf7b5c96430be5fc5fab4820c6bf75eb53f5c712\"\u003ecf7b5c9\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/minifier)\u003c/strong\u003e Preserve do-while control-flow targets (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12160\"\u003e#12160\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/f62c437dc2546d8cf3aa8211970f72693a357d0c\"\u003ef62c437\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/minifier)\u003c/strong\u003e Preserve pure annotation ownership (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12180\"\u003e#12180\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/ec780f927369cc81dfa3a1aca73802d7e5885a96\"\u003eec780f9\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/parser)\u003c/strong\u003e Retry ambiguous Program parsing (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12142\"\u003e#12142\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/141a3201322dd3cf1acb317fe1c8889cdeda9358\"\u003e141a320\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/parser)\u003c/strong\u003e Preserve await grammar boundaries (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12156\"\u003e#12156\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/c7326832e57d2d3effe9eb1b3c415424ae68bf21\"\u003ec732683\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/quote)\u003c/strong\u003e Restore await parsing (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12163\"\u003e#12163\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/918f5174a17425cd49c3eedc1e761ebdf1fc3d2e\"\u003e918f517\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/swc-project/swc/commit/5ae9149e67e86d2b23eae6b46cf1f8585778f7af\"\u003e\u003ccode\u003e5ae9149\u003c/code\u003e\u003c/a\u003e chore: Publish \u003ccode\u003e1.16.2\u003c/code\u003e with \u003ccode\u003eswc_core\u003c/code\u003e \u003ccode\u003ev78.0.0\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/swc-project/swc/commit/5c24a37d7a9306a79225ba5da7b4bebf49a91b55\"\u003e\u003ccode\u003e5c24a37\u003c/code\u003e\u003c/a\u003e chore: Publish \u003ccode\u003e1.16.2-nightly-20260904.1\u003c/code\u003e with \u003ccode\u003eswc_core\u003c/code\u003e \u003ccode\u003ev78.0.0\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/swc-project/swc/commits/v1.16.2/packages/core\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `eslint` from 10.9.1 to 10.10.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/eslint/eslint/releases\"\u003eeslint's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev10.10.0\u003c/h2\u003e\n\u003ch2\u003eFeatures\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/264b4346d1963701df0c398b4aeb2f6e8b2af93e\"\u003e\u003ccode\u003e264b434\u003c/code\u003e\u003c/a\u003e feat: add \u003ccode\u003ed\u003c/code\u003e and \u003ccode\u003ev\u003c/code\u003e flags to \u003ccode\u003eno-unexpected-multiline\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21305\"\u003e#21305\u003c/a\u003e) (Gihyeon Jeong / 정기현)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/c6cc6c592f30901345d94ef75e0d42c1894fae6c\"\u003e\u003ccode\u003ec6cc6c5\u003c/code\u003e\u003c/a\u003e feat: check \u003ccode\u003eObject.prototype\u003c/code\u003e property names in \u003ccode\u003enew-cap\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21269\"\u003e#21269\u003c/a\u003e) (crimsonjay0)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/5661fa65fde9fd4c14f0b730e3cee6a42fc657c1\"\u003e\u003ccode\u003e5661fa6\u003c/code\u003e\u003c/a\u003e feat: no-extra-bind false negatives with class fields and static blocks (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21260\"\u003e#21260\u003c/a\u003e) (synthex-byte)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/bb47dc6da2399a8f76c0c0c3273e6bc314c480e5\"\u003e\u003ccode\u003ebb47dc6\u003c/code\u003e\u003c/a\u003e fix: update dependency file-entry-cache to v11 (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/20801\"\u003e#20801\u003c/a\u003e) (Milos Djermanovic)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/427ac0a014066c36aa57fa8fa9af20fd9fb591e1\"\u003e\u003ccode\u003e427ac0a\u003c/code\u003e\u003c/a\u003e fix: use format strings in debug calls (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21247\"\u003e#21247\u003c/a\u003e) (Francesco Trotta)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/9d8153223dbf47b9aecdc1474202aaee4845f146\"\u003e\u003ccode\u003e9d81532\u003c/code\u003e\u003c/a\u003e fix: support \u003ccode\u003e__proto__\u003c/code\u003e in \u003ccode\u003e/* exported */\u003c/code\u003e comments (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21261\"\u003e#21261\u003c/a\u003e) (sethamus)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/87e0a082438264ad90b87fd74165ab4fd90f63ef\"\u003e\u003ccode\u003e87e0a08\u003c/code\u003e\u003c/a\u003e fix: prefer-object-has-own autofix breaks when Object is shadowed (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21282\"\u003e#21282\u003c/a\u003e) (김채영)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/8e2cb142217f2efee1d10dcc02bfb75145ae775d\"\u003e\u003ccode\u003e8e2cb14\u003c/code\u003e\u003c/a\u003e fix: \u003ccode\u003enew-cap\u003c/code\u003e false positive for \u003ccode\u003eUTC\u003c/code\u003e calls with \u003ccode\u003eproperties: false\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21275\"\u003e#21275\u003c/a\u003e) (Pixel)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/9f4a364ab0ade048dfce1f37792b1d461d866e55\"\u003e\u003ccode\u003e9f4a364\u003c/code\u003e\u003c/a\u003e fix: Ignore static imports in no-unreachable (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21276\"\u003e#21276\u003c/a\u003e) (Taha Kotil)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/2417cad57d7d1bc4cf3ecf0f0575cfb10ff2011c\"\u003e\u003ccode\u003e2417cad\u003c/code\u003e\u003c/a\u003e docs: Update README (GitHub Actions Bot)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/9cecb8a0a2348070abf72321965d41919c7cc626\"\u003e\u003ccode\u003e9cecb8a\u003c/code\u003e\u003c/a\u003e docs: document \u003ccode\u003e\\c\u003c/code\u003e control letter escapes in no-control-regex (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21286\"\u003e#21286\u003c/a\u003e) (한국)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/8724829f69f8ed80c876e3a5a017da199ce78739\"\u003e\u003ccode\u003e8724829\u003c/code\u003e\u003c/a\u003e docs: update compat table links (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21263\"\u003e#21263\u003c/a\u003e) (fnx)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/5634542be580750ffb1a5766470f9e9c72719696\"\u003e\u003ccode\u003e5634542\u003c/code\u003e\u003c/a\u003e docs: Clarify eqeqeq suggestion behavior (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21256\"\u003e#21256\u003c/a\u003e) (Müslüm Yılmaz)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eChores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/b3d876b46083d67899eb1d9613118c1c583632a2\"\u003e\u003ccode\u003eb3d876b\u003c/code\u003e\u003c/a\u003e chore: disable npm audit in ecosystem tests (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21306\"\u003e#21306\u003c/a\u003e) (Francesco Trotta)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/1696682791661c13167eb905da2f38d1b8f4a3bf\"\u003e\u003ccode\u003e1696682\u003c/code\u003e\u003c/a\u003e ci: restore EMFILE test on Node.js 26 (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21297\"\u003e#21297\u003c/a\u003e) (Marry (Subin Yang))\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/2c7f5d6f47a92e8c0847af103e40fdb2f4dc61ef\"\u003e\u003ccode\u003e2c7f5d6\u003c/code\u003e\u003c/a\u003e chore: update github/codeql-action action to v4.37.9 (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21296\"\u003e#21296\u003c/a\u003e) (renovate[bot])\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/3c753f18b461bfbf36d41a79a7863c093ef48489\"\u003e\u003ccode\u003e3c753f1\u003c/code\u003e\u003c/a\u003e chore: update eslint (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21289\"\u003e#21289\u003c/a\u003e) (renovate[bot])\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/1c734690bf6f4f9c542bec428d5a1a5c6cc4a19b\"\u003e\u003ccode\u003e1c73469\u003c/code\u003e\u003c/a\u003e chore: update ecosystem plugins (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21280\"\u003e#21280\u003c/a\u003e) (ESLint Bot)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/08a02be429e21fc93d86c8dd16cec6dc945ea2c1\"\u003e\u003ccode\u003e08a02be\u003c/code\u003e\u003c/a\u003e test: add error locations to \u003ccode\u003eno-extra-boolean-cast\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21266\"\u003e#21266\u003c/a\u003e) (lumir)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/77bb1db8e730b7da2347c647d60f215706aa349a\"\u003e\u003ccode\u003e77bb1db\u003c/code\u003e\u003c/a\u003e chore: update github/codeql-action action to v4.37.8 (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21270\"\u003e#21270\u003c/a\u003e) (renovate[bot])\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/007e81ac0ad66bd0be4887d88a276df292ae0bed\"\u003e\u003ccode\u003e007e81a\u003c/code\u003e\u003c/a\u003e ci: skip EMFILE test on Node.js 26 (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21265\"\u003e#21265\u003c/a\u003e) (lumir)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/0430280e7cca9dc0fdbf0bc50464e98e84285c49\"\u003e\u003ccode\u003e0430280\u003c/code\u003e\u003c/a\u003e chore: improve ecosystem tests compatibility on Windows (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21178\"\u003e#21178\u003c/a\u003e) (crimsonjay0)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/3f20a57c6293371b6193d3fb6746c2b7b2ac2689\"\u003e\u003ccode\u003e3f20a57\u003c/code\u003e\u003c/a\u003e 10.10.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/f4e5284803854423c4c2536696888c28ce4a151f\"\u003e\u003ccode\u003ef4e5284\u003c/code\u003e\u003c/a\u003e Build: changelog update for 10.10.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/bb47dc6da2399a8f76c0c0c3273e6bc314c480e5\"\u003e\u003ccode\u003ebb47dc6\u003c/code\u003e\u003c/a\u003e fix: update dependency file-entry-cache to v11 (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/20801\"\u003e#20801\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/427ac0a014066c36aa57fa8fa9af20fd9fb591e1\"\u003e\u003ccode\u003e427ac0a\u003c/code\u003e\u003c/a\u003e fix: use format strings in debug calls (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21247\"\u003e#21247\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/b3d876b46083d67899eb1d9613118c1c583632a2\"\u003e\u003ccode\u003eb3d876b\u003c/code\u003e\u003c/a\u003e chore: disable npm audit in ecosystem tests (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21306\"\u003e#21306\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/9d8153223dbf47b9aecdc1474202aaee4845f146\"\u003e\u003ccode\u003e9d81532\u003c/code\u003e\u003c/a\u003e fix: support \u003ccode\u003e__proto__\u003c/code\u003e in \u003ccode\u003e/* exported */\u003c/code\u003e comments (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21261\"\u003e#21261\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/264b4346d1963701df0c398b4aeb2f6e8b2af93e\"\u003e\u003ccode\u003e264b434\u003c/code\u003e\u003c/a\u003e feat: add \u003ccode\u003ed\u003c/code\u003e and \u003ccode\u003ev\u003c/code\u003e flags to \u003ccode\u003eno-unexpected-multiline\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21305\"\u003e#21305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/1696682791661c13167eb905da2f38d1b8f4a3bf\"\u003e\u003ccode\u003e1696682\u003c/code\u003e\u003c/a\u003e ci: restore EMFILE test on Node.js 26 (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21297\"\u003e#21297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/2c7f5d6f47a92e8c0847af103e40fdb2f4dc61ef\"\u003e\u003ccode\u003e2c7f5d6\u003c/code\u003e\u003c/a\u003e chore: update github/codeql-action action to v4.37.9 (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21296\"\u003e#21296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/87e0a082438264ad90b87fd74165ab4fd90f63ef\"\u003e\u003ccode\u003e87e0a08\u003c/code\u003e\u003c/a\u003e fix: prefer-object-has-own autofix breaks when Object is shadowed (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21282\"\u003e#21282\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/eslint/eslint/compare/v10.9.1...v10.10.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `squawk-cli` from 2.63.0 to 2.64.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/sbdchd/squawk/releases\"\u003esquawk-cli's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eUpdate prefer-robust-stmts to be alembic version aware + code formatter\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003elinter: prefer-robust-stmts aware of alembic version update transactions (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1311\"\u003e#1311\u003c/a\u003e). Thanks \u003ca href=\"https://github.com/DylanGriffith\"\u003e\u003ccode\u003e@​DylanGriffith\u003c/code\u003e\u003c/a\u003e!\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003efmt: support for all statements (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1321\"\u003e#1321\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1319\"\u003e#1319\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1317\"\u003e#1317\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1312\"\u003e#1312\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1310\"\u003e#1310\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1309\"\u003e#1309\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1307\"\u003e#1307\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1306\"\u003e#1306\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1305\"\u003e#1305\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1303\"\u003e#1303\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1302\"\u003e#1302\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1300\"\u003e#1300\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1299\"\u003e#1299\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eide: add formatting support (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1315\"\u003e#1315\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eide: code action isnull -\u0026gt; is null, notnull -\u0026gt; is not null (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1296\"\u003e#1296\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eide: code actions for func params (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1322\"\u003e#1322\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eide: code action to convert \u003ccode\u003edefault\u003c/code\u003e to \u003ccode\u003e=\u003c/code\u003e in function syntax (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1316\"\u003e#1316\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eide: code actions for :=/=\u0026gt; \u0026amp; value/: rewrites (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1313\"\u003e#1313\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eparser: validation for variadic, function defaults, params (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1325\"\u003e#1325\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1324\"\u003e#1324\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1323\"\u003e#1323\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eparser: validate string literal type cast (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1320\"\u003e#1320\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eplayground: add code formatting output (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1326\"\u003e#1326\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eparser: split bit \u0026amp; time type ast nodes (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1297\"\u003e#1297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eparser: add nodes for interval \u0026amp; array bounds (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1301\"\u003e#1301\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eparser: improve parsing of operators in using and exclude (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1304\"\u003e#1304\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eparser: refactor percent type out of ast::Type (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1318\"\u003e#1318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eparser: refactor char type into character and varchar nodes (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1295\"\u003e#1295\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003esyntax: fix unquoting \u0026amp; add more funcs (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1298\"\u003e#1298\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/sbdchd/squawk/blob/master/CHANGELOG.md\"\u003esquawk-cli's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.64.0 - 2026-08-31\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003elinter: prefer-robust-stmts aware of alembic version update transactions (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1311\"\u003e#1311\u003c/a\u003e). Thanks \u003ca href=\"https://github.com/DylanGriffith\"\u003e\u003ccode\u003e@​DylanGriffith\u003c/code\u003e\u003c/a\u003e!\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003efmt: support for all statements (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1321\"\u003e#1321\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1319\"\u003e#1319\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1317\"\u003e#1317\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1312\"\u003e#1312\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1310\"\u003e#1310\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1309\"\u003e#1309\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1307\"\u003e#1307\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1306\"\u003e#1306\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1305\"\u003e#1305\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1303\"\u003e#1303\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1302\"\u003e#1302\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1300\"\u003e#1300\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1299\"\u003e#1299\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eide: add formatting support (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1315\"\u003e#1315\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eide: code action isnull -\u0026gt; is null, notnull -\u0026gt; is not null (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1296\"\u003e#1296\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eide: code actions for func params (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1322\"\u003e#1322\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eide: code action to convert \u003ccode\u003edefault\u003c/code\u003e to \u003ccode\u003e=\u003c/code\u003e in function syntax (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1316\"\u003e#1316\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eide: code actions for :=/=\u0026gt; \u0026amp; value/: rewrites (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1313\"\u003e#1313\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eparser: validation for variadic, function defaults, params (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1325\"\u003e#1325\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1324\"\u003e#1324\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1323\"\u003e#1323\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eparser: validate string literal type cast (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1320\"\u003e#1320\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eplayground: add code formatting output (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1326\"\u003e#1326\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eparser: split bit \u0026amp; time type ast nodes (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1297\"\u003e#1297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eparser: add nodes for interval \u0026amp; array bounds (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1301\"\u003e#1301\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eparser: improve parsing of operators in using and exclude (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1304\"\u003e#1304\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eparser: refactor percent type out of ast::Type (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1318\"\u003e#1318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eparser: refactor char type into character and varchar nodes (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1295\"\u003e#1295\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003esyntax: fix unquoting \u0026amp; add more funcs (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1298\"\u003e#1298\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbdchd/squawk/commit/0c55115ca14b5051cb39bbb8996f9b240f82f4b8\"\u003e\u003ccode\u003e0c55115\u003c/code\u003e\u003c/a\u003e release: 2.64.0 (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1327\"\u003e#1327\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbdchd/squawk/commit/f1fa317b752fea0fb5dc10c134213ee9d1060dd9\"\u003e\u003ccode\u003ef1fa317\u003c/code\u003e\u003c/a\u003e playground: add code formatting output (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1326\"\u003e#1326\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbdchd/squawk/commit/7d219a5d8ecfecb10fa0fe819b8a077097283d0d\"\u003e\u003ccode\u003e7d219a5\u003c/code\u003e\u003c/a\u003e parser: add validation for variadic (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1325\"\u003e#1325\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbdchd/squawk/commit/9ced3719da27a6871cef00d0480be659e3fd318d\"\u003e\u003ccode\u003e9ced371\u003c/code\u003e\u003c/a\u003e parser: add validation for function defaults (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1324\"\u003e#1324\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbdchd/squawk/commit/a96667a7dfa6a817bcee68aedcf599fe284fd0ae\"\u003e\u003ccode\u003ea96667a\u003c/code\u003e\u003c/a\u003e parser: add validation for params (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1323\"\u003e#1323\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbdchd/squawk/commit/7cc4f56a14b962f659f673240b5cbb9ed6821caf\"\u003e\u003ccode\u003e7cc4f56\u003c/code\u003e\u003c/a\u003e ide: code actions for func params (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1322\"\u003e#1322\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbdchd/squawk/commit/707a17d8473767f5499a6bc6aa67f8e4191fd159\"\u003e\u003ccode\u003e707a17d\u003c/code\u003e\u003c/a\u003e fmt: avoid quoting things that don't need quoting (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1321\"\u003e#1321\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbdchd/squawk/commit/ba6210126cde692eaa594893032758719d3a5a08\"\u003e\u003ccode\u003eba62101\u003c/code\u003e\u003c/a\u003e parser: validate string literal type cast (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1320\"\u003e#1320\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbdchd/squawk/commit/a573962f257c3b67b87692285bbdd4b90bd70830\"\u003e\u003ccode\u003ea573962\u003c/code\u003e\u003c/a\u003e parser: test typed literals \u0026amp; simplify type modifier formatting (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1319\"\u003e#1319\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbdchd/squawk/commit/79be8ee9b97e8acf2ba6b033e096324ca93824a9\"\u003e\u003ccode\u003e79be8ee\u003c/code\u003e\u003c/a\u003e parser: refactor percent type out of ast::Type (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1318\"\u003e#1318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/sbdchd/squawk/compare/v2.63.0...v2.64.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tuffgal` from 0.2.0-alpha.8 to 0.3.0-alpha.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nschneble/tuffgal/releases\"\u003etuffgal's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.3.0-alpha.1\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003ediff.maxDiffPixels\u003c/code\u003e, a per-action budget for how many pixels may differ and still pass. An action now passes only when it clears both mean SSIM at or above \u003ccode\u003essimThreshold\u003c/code\u003e and differing pixels at or under \u003ccode\u003emaxDiffPixels\u003c/code\u003e.\u003c/p\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003eBreaking default.\u003c/strong\u003e \u003ccode\u003emaxDiffPixels\u003c/code\u003e defaults to \u003ccode\u003e0\u003c/code\u003e, so a run that used to pass on SSIM tolerance alone can now report \u003ccode\u003echanged\u003c/code\u003e.\u003c/p\u003e\n\u003ch2\u003ev0.2.2-alpha.1\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003ebrowserArgs\u003c/code\u003e config option; extra command-line flags are now passed directly through to \u003ccode\u003echromium.launch()\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eThe motivating case is \u003ccode\u003e--force-color-profile=srgb\u003c/code\u003e because without it Chromium renders through whatever ICC profile the host OS reports, and a laptop and CI container can shift baseline pixels for a reason that has nothing to do with what's being tested.\u003c/p\u003e\n\u003cp\u003eIf you omit the field, nothing changes from before.\u003c/p\u003e\n\u003ch2\u003ev0.2.1-alpha.1\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eA \u003ccode\u003eneeds\u003c/code\u003e label that no story \u003ccode\u003eproduces\u003c/code\u003e fails the run when declared in \u003ccode\u003eseededLabels\u003c/code\u003e and \u003ccode\u003e\u0026lt;paths.authState\u0026gt;/\u0026lt;label\u0026gt;.json\u003c/code\u003e is on disk\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nschneble/tuffgal/blob/main/CHANGELOG.md\"\u003etuffgal's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[0.3.0-alpha.1] – 2026-09-03\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003ediff.maxDiffPixels\u003c/code\u003e, a per-action budget for how many pixels may differ\nand still pass. An action now passes only when it clears both mean SSIM at\nor above \u003ccode\u003essimThreshold\u003c/code\u003e and differing pixels at or under \u003ccode\u003emaxDiffPixels\u003c/code\u003e.\u003c/p\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003eBreaking default.\u003c/strong\u003e \u003ccode\u003emaxDiffPixels\u003c/code\u003e defaults to \u003ccode\u003e0\u003c/code\u003e, so a run that used\nto pass on SSIM tolerance alone can now report \u003ccode\u003echanged\u003c/code\u003e.\u003c/p\u003e\n\u003ch2\u003e[0.2.2-alpha.1] – 2026-09-01\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003ebrowserArgs\u003c/code\u003e config option; extra command-line flags are now passed\ndirectly through to \u003ccode\u003echromium.launch()\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eThe motivating case is \u003ccode\u003e--force-color-profile=srgb\u003c/code\u003e because without it\nChromium renders through whatever ICC profile the host OS reports, and a\nlaptop and CI container can shift baseline pixels for a reason that has\nnothing to do with what's being tested.\u003c/p\u003e\n\u003cp\u003eIf you omit the field, nothing changes from before.\u003c/p\u003e\n\u003ch2\u003e[0.2.1-alpha.1] – 2026-08-27\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eA \u003ccode\u003eneeds\u003c/code\u003e label that no story \u003ccode\u003eproduces\u003c/code\u003e fails the run when declared in\n\u003ccode\u003eseededLabels\u003c/code\u003e and \u003ccode\u003e\u0026lt;paths.authState\u0026gt;/\u0026lt;label\u0026gt;.json\u003c/code\u003e is on disk\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nschneble/tuffgal/commit/1fec44c48002ad31d9ae0fc3ff89a602e10504f3\"\u003e\u003ccode\u003e1fec44c\u003c/code\u003e\u003c/a\u003e Add a maxDiffPixels gate beside the SSIM gate (\u003ca href=\"https://redirect.github.com/nschneble/tuffgal/issues/51\"\u003e#51\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nschneble/tuffgal/commit/d4e1cbeae1af6a833223163f387518c855b5bbd8\"\u003e\u003ccode\u003ed4e1cbe\u003c/code\u003e\u003c/a\u003e Add browser args config option for Chromium launch flags (\u003ca href=\"https://redirect.github.com/nschneble/tuffgal/issues/49\"\u003e#49\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nschneble/tuffgal/commit/407b30ace0b584d4d954f7547c1b264d269f690d\"\u003e\u003ccode\u003e407b30a\u003c/code\u003e\u003c/a\u003e Bump monocart-coverage-reports from 2.12.12 to 2.13.0 (\u003ca href=\"https://redirect.github.com/nschneble/tuffgal/issues/48\"\u003e#48\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nschneble/tuffgal/commit/f164ddbdd1443c8183d1ef9336b43e4298a4a2d1\"\u003e\u003ccode\u003ef164ddb\u003c/code\u003e\u003c/a\u003e Bump eslint from 10.8.1 to 10.9.1 (\u003ca href=\"https://redirect.github.com/nschneble/tuffgal/issues/47\"\u003e#47\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nschneble/tuffgal/commit/d97c9aa2f3b1627f9d6c25d5c8fbb65bf6dc50f2\"\u003e\u003ccode\u003ed97c9aa\u003c/code\u003e\u003c/a\u003e Split scheduler.ts into planner/executor files (\u003ca href=\"https://redirect.github.com/nschneble/tuffgal/issues/46\"\u003e#46\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nschneble/tuffgal/commit/608af997afc3d41cdf23c9cbbf9378c0e63d1cd0\"\u003e\u003ccode\u003e608af99\u003c/code\u003e\u003c/a\u003e Collapse runScheduledStory's positional params (\u003ca href=\"https://redirect.github.com/nschneble/tuffgal/issues/45\"\u003e#45\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nschneble/tuffgal/commit/5390daa455cf6e234cc2741faf53a9aa4c862f57\"\u003e\u003ccode\u003e5390daa\u003c/code\u003e\u003c/a\u003e Bump tsx from 4.23.8 to 4.23.12 (\u003ca href=\"https://redirect.github.com/nschneble/tuffgal/issues/39\"\u003e#39\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nschneble/tuffgal/commit/a163f1dd45cc9913cd258ab6e4813dff5a79bc76\"\u003e\u003ccode\u003ea163f1d\u003c/code\u003e\u003c/a\u003e Bump typescript-eslint from 8.66.0 to 8.68.0 (\u003ca href=\"https://redirect.github.com/nschneble/tuffgal/issues/38\"\u003e#38\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nschneble/tuffgal/commit/1b0f2558ba3e5b736c70ed4f593bd01797b41026\"\u003e\u003ccode\u003e1b0f255\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003e@​types/node\u003c/code\u003e from 26.1.2 to 26.3.0 (\u003ca href=\"https://redirect.github.com/nschneble/tuffgal/issues/36\"\u003e#36\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nschneble/tuffgal/commit/403c26b2440d8d120798a64ff3d2354ff3ca5b67\"\u003e\u003ccode\u003e403c26b\u003c/code\u003e\u003c/a\u003e Accept a pre-seeded label with no producing story (\u003ca href=\"https://redirect.github.com/nschneble/tuffgal/issues/42\"\u003e#42\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nschneble/tuffgal/compare/v0.2.0-alpha.8...v0.3.0-alpha.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `typescript-eslint` from 8.68.0 to 8.70.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases\"\u003etypescript-eslint's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.70.0\u003c/h2\u003e\n\u003ch2\u003e8.70.0 (2026-09-07)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-generated-empty-object-type] add rule (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12730\"\u003e#12730\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ewebsite:\u003c/strong\u003e generate per-page social preview cards (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12734\"\u003e#12734\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003euse stable release of pnpm 12 (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12808\"\u003e#12808\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate pnpm to 12.3.4 and dedupe Docusaurus packages (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12829\"\u003e#12829\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [member-ordering] don't report fields that read fields declared before them (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12729\"\u003e#12729\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-unnecessary-condition] no false positive on RHS of a nested logical expression (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12728\"\u003e#12728\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-deprecated] report deprecated imported values used in object shorthand properties (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12780\"\u003e#12780\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eproject-service:\u003c/strong\u003e avoid discarded tsserver logs (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12748\"\u003e#12748\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypescript-estree:\u003c/strong\u003e clarify the parserOptions.project error message (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12817\"\u003e#12817\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBarry \u003ca href=\"https://github.com/barry166\"\u003e\u003ccode\u003e@​barry166\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEvyatar Daud \u003ca href=\"https://github.com/StyleShit\"\u003e\u003ccode\u003e@​StyleShit\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJosh Goldberg\u003c/li\u003e\n\u003cli\u003eJosh Goldberg ✨ \u003ca href=\"https://github.com/JoshuaKGoldberg\"\u003e\u003ccode\u003e@​JoshuaKGoldberg\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eKirk Waiblinger \u003ca href=\"https://github.com/kirkwaiblinger\"\u003e\u003ccode\u003e@​kirkwaiblinger\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUlrich Stark \u003ca href=\"https://github.com/ulrichstark\"\u003e\u003ccode\u003e@​ulrichstark\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e송재욱\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003ev8.69.0\u003c/h2\u003e\n\u003ch2\u003e8.69.0 (2026-08-31)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-misused-promises] add flagUnions option for checkConditionals (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12603\"\u003e#12603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-mixed-enums] use scope analysis instead of type checking for merged namespaces (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12731\"\u003e#12731\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [unified-signatures] compare type parameters by constraint instead of name (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12741\"\u003e#12741\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-meaningless-void-operator] report void on non-call expressions (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12727\"\u003e#12727\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ewebsite:\u003c/strong\u003e respect allowJs playground config (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12744\"\u003e#12744\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAbdu Alim Arlikhozhaev \u003ca href=\"https://github.com/Arlikhozhaev\"\u003e\u003ccode\u003e@​Arlikhozhaev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEvyatar Daud \u003ca href=\"https://github.com/StyleShit\"\u003e\u003ccode\u003e@​StyleShit\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md\"\u003etypescript-eslint's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.70.0 (2026-09-07)\u003c/h2\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-deprecated] report deprecated imported values used in object shorthand properties (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12780\"\u003e#12780\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUlrich Stark \u003ca href=\"https://github.com/ulrichstark\"\u003e\u003ccode\u003e@​ulrichstark\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003e8.69.0 (2026-08-31)\u003c/h2\u003e\n\u003cp\u003eThis was a version bump only for typescript-eslint to align it with other projects, there were no code changes.\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.69.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/7ee76085c22e923c0036b8e0733a3ca7dfd82b60\"\u003e\u003ccode\u003e7ee7608\u003c/code\u003e\u003c/a\u003e chore(release): publish 8.70.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/4586535ab24d7d5e9b3ba87e4adb8636f9314aca\"\u003e\u003ccode\u003e4586535\u003c/code\u003e\u003c/a\u003e fix(eslint-plugin): [no-deprecated] report deprecated imported values used in...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/9a6e546823e5d8f2dc015df2aa66c0230615e209\"\u003e\u003ccode\u003e9a6e546\u003c/code\u003e\u003c/a\u003e chore(release): publish 8.69.0\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.0/packages/typescript-eslint\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pg-boss` from 12.28.0 to 12.30.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/timgit/pg-boss/releases\"\u003epg-boss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e12.30.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cp\u003eSchema version: \u003cstrong\u003e40\u003c/strong\u003e (a migration runs on upgrade — see \u003ca href=\"https://github.com/timgit/pg-boss/blob/HEAD/#upgrading\"\u003eUpgrading\u003c/a\u003e).\u003c/p\u003e\n\u003cp\u003eFetch is now an ordered index walk instead of a sort, and maintenance reports when vacuum has stopped keeping up with the queues. Options \u003ccode\u003epriority\u003c/code\u003e and \u003ccode\u003eorderByCreatedOn\u003c/code\u003e are now deprecated.\u003c/p\u003e\n\u003ch2\u003eHighlights\u003c/h2\u003e\n\u003ch3\u003eThe fetch index matches the fetch\u003c/h3\u003e\n\u003cp\u003eThe fetch orders by \u003ccode\u003epriority desc, created_on\u003c/code\u003e, but the index led with \u003ccode\u003estart_after\u003c/code\u003e, so every poll read all eligible rows and sorted them. On a 500k-row job table that is a \u003ccode\u003etop-N heapsort\u003c/code\u003e over 5,257 buffers:\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eLimit (actual time=44.880..47.794 rows=1)\r\n  Buffers: shared hit=5257\r\n  -\u0026gt;  Sort  Sort Key: priority DESC, created_on\r\n        Sort Method: top-N heapsort\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eThe index now leads with the sort keys and keeps \u003ccode\u003estart_after\u003c/code\u003e as a trailing key column, so the same fetch is an ordered walk that stops at the first row:\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eLimit (actual time=0.079..0.080 rows=1)\r\n  Buffers: shared hit=16\r\n  -\u0026gt;  Index Scan using job_common_i11\r\n        Index Cond: ((name = 'q') AND (start_after \u0026lt; now()))\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003e\u003cstrong\u003e47.8 ms → 0.11 ms\u003c/strong\u003e, 5,257 buffers → 16. Cost is 27% more index (15 MB → 19 MB at 500k rows).\u003c/p\u003e\n\u003ch3\u003e\u003ccode\u003epriority\u003c/code\u003e and \u003ccode\u003eorderByCreatedOn\u003c/code\u003e are deprecated\u003c/h3\u003e\n\u003cp\u003eBoth of these options were created to optimize perf, based on the previous index. As of this release, they are \u003cstrong\u003eignored\u003c/strong\u003e  and will be rejected in the next major. Jobs are always fetched in priority and creation order.\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// no longer changes anything, and emits a DeprecationWarning once per option per instance\r\nawait boss.fetch('my-queue', { priority: false })\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cpre\u003e\u003ccode\u003e(node:1234) [PGBOSS_DEP_FETCH_SORT] DeprecationWarning: priority: false is deprecated and now ignored\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eRun with \u003ccode\u003e--trace-deprecation\u003c/code\u003e to find the call site, or \u003ccode\u003e--throw-deprecation\u003c/code\u003e to fail a build on it. It is a Node deprecation rather than a pg-boss \u003ccode\u003ewarning\u003c/code\u003e event, which stays reserved for database and queue health.\u003c/p\u003e\n\u003cp\u003eIf you set \u003ccode\u003epriority: false\u003c/code\u003e for throughput, remove it: it was measured roughly \u003cstrong\u003e180x slower\u003c/strong\u003e than the default, since no index leads with \u003ccode\u003ecreated_on\u003c/code\u003e.\u003c/p\u003e\n\u003ch3\u003eVacuum health is monitored\u003c/h3\u003e\n\u003cp\u003eA primary failure pattern of Postgres-hosted queues is a busy server that is unable to perform maintenance via autovacuum.  Until now pg-boss reported a symptom via a warning about a queue's backlog, but the remedy for this wasn't clear.  One easy solution to this warning is to increase workers, concurrency, or batch size.  If the actual cause was related to a busy server, adding more polling workers or increasing busyness could instead make this issue worse, or at best not improve anything.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timgit/pg-boss/commit/180a54b65ce492bf990e524cda2d38b19f0df3f4\"\u003e\u003ccode\u003e180a54b\u003c/code\u003e\u003c/a\u003e Job fetch index tuning and vacuum monitoring (\u003ca href=\"https://redirect.github.com/timgit/pg-boss/issues/885\"\u003e#885\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timgit/pg-boss/commit/20fdc8aeed2fb6294eb03a71f319d1eee4ce3ba5\"\u003e\u003ccode\u003e20fdc8a\u003c/code\u003e\u003c/a\u003e added reindex to maintenance (\u003ca href=\"https://redirect.github.com/timgit/pg-boss/issues/883\"\u003e#883\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timgit/pg-boss/commit/4a1d22bf31cacb42397c4b60184ff9f000f13d89\"\u003e\u003ccode\u003e4a1d22b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/timgit/pg-boss/issues/882\"\u003e#882\u003c/a\u003e from timgit/dependabot/github_actions/actions/checkou...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timgit/pg-boss/commit/ac393d655415d31a3309d19d5847e7f04510b71d\"\u003e\u003ccode\u003eac393d6\u003c/code\u003e\u003c/a\u003e Merge branch 'master' into dependabot/github_actions/actions/checkout-7.0.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timgit/pg-boss/commit/85aff3d672f1523a84c28f0cf0c31869806d1581\"\u003e\u003ccode\u003e85aff3d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/timgit/pg-boss/issues/881\"\u003e#881\u003c/a\u003e from timgit/dependabot/github_actions/actions/setup-n...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timgit/pg-boss/commit/e80d368f23b21ddbed066c1f1085182052d506c0\"\u003e\u003ccode\u003ee80d368\u003c/code\u003e\u003c/a\u003e ci: bump actions/checkout from 5.1.0 to 7.0.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timgit/pg-boss/commit/6a1e10805e6158f4df5205f678d83f876ad0c6f6\"\u003e\u003ccode\u003e6a1e108\u003c/code\u003e\u003c/a\u003e ci: bump actions/setup-node from 5.0.0 to 7.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timgit/pg-boss/commit/78089bbd51cce5e70282f6e5f9a9d937856ab414\"\u003e\u003ccode\u003e78089bb\u003c/code\u003e\u003c/a\u003e deps and versioning\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timgit/pg-boss/commit/749af4fe18e66c76a0121aff462ad0410f020005\"\u003e\u003ccode\u003e749af4f\u003c/code\u003e\u003c/a\u003e raise error during publish if any downstream queues throw\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timgit/pg-boss/commit/e1918c0280325b0aa3f4c26910d379dfe96af364\"\u003e\u003ccode\u003ee1918c0\u003c/code\u003e\u003c/a\u003e update sponsors page for new tiers and logo sizes\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/timgit/pg-boss/compare/12.28.0...12.30.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 8.10.0 to 8.10.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm\"\u003eGHSA-vp8m-p9jh-q5pm\u003c/a\u003e: cache and deduplication interceptors could use caller-controlled request metadata instead of the authoritative dispatcher origin, enabling cross-origin cache poisoning and data disclosure. Undici now derives interceptor identities from the dispatcher origin and bypasses origin-dependent interceptors when no authoritative origin exists. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/caf6194d3dae989b731ed87ab85f182befe5eb80\"\u003ecaf6194d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e8f5868fb\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e66e12816\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6\"\u003e4411a238\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/662d0ea671fe64139e79533c913fce412765e1d7\"\u003e662d0ea6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003ecb75bbb3\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e7aac7f12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003ee905b5b8\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e2be07bf9\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e6d583124\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e0160a719\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps-dev): bump undici from 6.27.0 to 6.28.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5653\"\u003enodejs/undici#5653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump jest from 30.4.2 to 30.5.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5750\"\u003enodejs/undici#5750\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/analyze from 4.37.3 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5752\"\u003enodejs/undici#5752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5754\"\u003enodejs/undici#5754\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(h2): cover stream reset with NGHTTP2_INTERNAL_ERROR by \u003ca href=\"https://github.com/zeexzeex\"\u003e\u003ccode\u003e@​zeexzeex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5725\"\u003enodejs/undici#5725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): reject invalid resumed responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5724\"\u003enodejs/undici#5724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: make stale-while-revalidate cache update test deterministic by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5722\"\u003enodejs/undici#5722\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid unbounded recursion in Set-Cookie attribute parser by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5757\"\u003enodejs/undici#5757\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: honor SOCKS5 connection timeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5733\"\u003enodejs/undici#5733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(eventsource): validate Last-Event-ID on reconnect by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5746\"\u003enodejs/undici#5746\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid duplicate release attempts by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5745\"\u003enodejs/undici#5745\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(cache): refetch when 304 adds vary fields by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5732\"\u003enodejs/undici#5732\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etypes: expose PendingInterceptor and PendingInterceptorsFormatter on the MockAgent namespace by \u003ca href=\"https://github.com/RaphaelFakhri\"\u003e\u003ccode\u003e@​RaphaelFakhri\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5721\"\u003enodejs/undici#5721\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(codeql): align CodeQL action versions to v4.37.9 by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5759\"\u003enodejs/undici#5759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5760\"\u003enodejs/undici#5760\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(proxy-agent): guard Proxy-Authorization in iterable header containers by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5758\"\u003enodejs/undici#5758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: name the parameters these two blocks describe by \u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): fail the connection on a non-200 h2 extended CONNECT response by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(node-fetch): re-enable the set-cookie header combining test by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5730\"\u003enodejs/undici#5730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward rawHeaders writes through RetryController by \u003ca href=\"https://github.com/official-burak\"\u003e\u003ccode\u003e@​official-burak\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5727\"\u003enodejs/undici#5727\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5738\"\u003enodejs/undici#5738\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/5e541e0b9df7563e5766bbd469fbfe383d9ae6ca\"\u003e\u003ccode\u003e5e541e0\u003c/code\u003e\u003c/a\u003e Bumped v8.10.2 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5771\"\u003e#5771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/eb04cc39954e63e9b46bdf824e6efad9fff2e7b5\"\u003e\u003ccode\u003eeb04cc3\u003c/code\u003e\u003c/a\u003e fix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5738\"\u003e#5738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003e\u003ccode\u003ee905b5b\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e\u003ccode\u003e0160a71\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e\u003ccode\u003e66e1281\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e\u003ccode\u003e7aac7f1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003e\u003ccode\u003ecb75bbb\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e\u003ccode\u003e6d58312\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e\u003ccode\u003e8f5868f\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e\u003ccode\u003e2be07bf\u003c/code\u003e\u003c/a\u003e fix(cache): reject unsafe method response caching\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v8.10.0...v8.10.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@eslint/eslintrc` from 3.3.6 to 3.3.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/eslint/eslintrc/releases\"\u003e@​eslint/eslintrc's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eeslintrc: v3.3.7\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/eslint/eslintrc/compare/eslintrc-v3.3.6...eslintrc-v3.3.7\"\u003e3.3.7\u003c/a\u003e (2026-09-01)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump js-yaml to 4.3.1 (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/239\"\u003e#239\u003c/a\u003e) (\u003ca href=\"https://github.com/eslint/eslintrc/commit/f27e7c94e6d9438bd51cb483d8d5da768e1cc0b9\"\u003ef27e7c9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate js-yaml to 4.3.2 to address security vulnerability (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/243\"\u003e#243\u003c/a\u003e) (\u003ca href=\"https://github.com/eslint/eslintrc/commit/bb0d97a338937b88fa99d6bbc0a904e34eda3d5f\"\u003ebb0d97a\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/eslint/eslintrc/blob/main/CHANGELOG.md\"\u003e@​eslint/eslintrc's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/eslint/eslintrc/compare/eslintrc-v3.3.6...eslintrc-v3.3.7\"\u003e3.3.7\u003c/a\u003e (2026-09-01)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump js-yaml to 4.3.1 (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/239\"\u003e#239\u003c/a\u003e) (\u003ca href=\"https://github.com/eslint/eslintrc/commit/f27e7c94e6d9438bd51cb483d8d5da768e1cc0b9\"\u003ef27e7c9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate js-yaml to 4.3.2 to address security vulnerability (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/243\"\u003e#243\u003c/a\u003e) (\u003ca href=\"https://github.com/eslint/eslintrc/commit/bb0d97a338937b88fa99d6bbc0a904e34eda3d5f\"\u003ebb0d97a\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/7943fa6dd55b236a539f658b88c763a4f9fbb38d\"\u003e\u003ccode\u003e7943fa6\u003c/code\u003e\u003c/a\u003e chore: release 3.3.7 🚀 (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/240\"\u003e#240\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/bb0d97a338937b88fa99d6bbc0a904e34eda3d5f\"\u003e\u003ccode\u003ebb0d97a\u003c/code\u003e\u003c/a\u003e fix: update js-yaml to 4.3.2 to address security vulnerability (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/243\"\u003e#243\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/5b4abc9c74dd92b9eb782ca81d559a88906509e9\"\u003e\u003ccode\u003e5b4abc9\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/f27e7c94e6d9438bd51cb483d8d5da768e1cc0b9\"\u003e\u003ccode\u003ef27e7c9\u003c/code\u003e\u003c/a\u003e fix: Bump js-yaml to 4.3.1 (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/239\"\u003e#239\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/b75e1d2425deebfd1ec7f952dda7d0c4f4d65d5c\"\u003e\u003ccode\u003eb75e1d2\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/302c13310e148268f990df3edbfd10dab44f2678\"\u003e\u003ccode\u003e302c133\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/e62e7661b0d9063e42a37af5551bbcb1897e188d\"\u003e\u003ccode\u003ee62e766\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/cf27f9fd8f775d94500f2569a5bfb6a7de9cdb33\"\u003e\u003ccode\u003ecf27f9f\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/c7f4cdf1ffa86e28b5b8bf09f9e8bc7fadbf87ff\"\u003e\u003ccode\u003ec7f4cdf\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/3319822ac925e018c47fcafa351b20ea0bf6eeff\"\u003e\u003ccode\u003e3319822\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/eslint/eslintrc/compare/eslintrc-v3.3.6...eslintrc-v3.3.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@types/node` from 26.4.0 to 26.5.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `globals` from 17.11.0 to 17.12.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/sindresorhus/globals/releases\"\u003eglobals's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev17.12.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate globals (2026-09-01) (\u003ca href=\"https://redirect.github.com/sindresorhus/globals/issues/353\"\u003e#353\u003c/a\u003e)  50a2119\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003e__webpack_layer__\u003c/code\u003e global (\u003ca href=\"https://redirect.github.com/sindresorhus/globals/issues/351\"\u003e#351\u003c/a\u003e)  779a11a\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/sindresorhus/globals/compare/v17.11.0...v17.12.0\"\u003ehttps://github.com/sindresorhus/globals/compare/v17.11.0...v17.12.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sindresorhus/globals/commit/98008c3200fc994ef3c074699e8ce0c9691fd071\"\u003e\u003ccode\u003e98008c3\u003c/code\u003e\u003c/a\u003e 17.12.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sindresorhus/globals/commit/50a2119777b37fef046c2e0bc24bca0bd9feb0be\"\u003e\u003ccode\u003e50a2119\u003c/code\u003e\u003c/a\u003e Update globals (2026-09-01) (\u003ca href=\"https://redirect.github.com/sindresorhus/globals/issues/353\"\u003e#353\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sindresorhus/globals/commit/779a11a345f072a7fbb76b8b92458987a9a8fa38\"\u003e\u003ccode\u003e779a11a\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003e__webpack_layer__\u003c/code\u003e global (\u003ca href=\"https://redirect.github.com/sindresorhus/globals/issues/351\"\u003e#351\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/sindresorhus/globals/compare/v17.11.0...v17.12.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `jest` from 30.4.2 to 30.5.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jestjs/jest/releases\"\u003ejest's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev30.5.1\u003c/h2\u003e\n\u003ch2\u003eFixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e[jest-config]\u003c/code\u003e Don't warn about global-only options in the config that supplies the global config - the root config a project resolves to, or the first entry of \u003ccode\u003e--projects\u003c/code\u003e when no root config is passed (\u003ca href=\"https://redirect.github.com/jestjs/jest/pull/16411\"\u003e#16411\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e[jest-config, jest-types]\u003c/code\u003e Stop accepting \u003ccode\u003ereporters\u003c/code\u003e, \u003ccode\u003ecoverageReporters\u003c/code\u003e, \u003ccode\u003eworkerIdleMemoryLimit\u003c/code\u003e, \u003ccode\u003ecwd\u003c/code\u003e and \u003ccode\u003erunnerOptions\u003c/code\u003e in a project config - they were silently ignored, and now warn like the other global-only options (\u003ca href=\"https://redirect.github.com/jestjs/jest/pull/16411\"\u003e#16411\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e[jest-config, jest-validate]\u003c/code\u003e Warn about \u003ccode\u003emaxWorkers\u003c/code\u003e and \u003ccode\u003ecoverageThreshold\u003c/code\u003e in a project config instead of dropping them without a word (\u003ca href=\"https://redirect.github.com/jestjs/jest/pull/16411\"\u003e#16411\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e[jest-resolve]\u003c/code\u003e Match \u003ccode\u003emoduleNameMapper\u003c/code\u003e patterns against the specifier as written again (reverting \u003ca href=\"https://redirect.github.com/jestjs/jest/pull/16390\"\u003e#16390\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/jestjs/jest/pull/16417\"\u003e#16417\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e[jest-runtime]\u003c/code\u003e Resolve package \u003ccode\u003eimports\u003c/code\u003e specifiers like \u003ccode\u003e#dep\u003c/code\u003e under ESM again (\u003ca href=\"https://redirect.github.com/jestjs/jest/pull/16413\"\u003e#16413\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eChore \u0026amp; Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e[jest-util]\u003c/code\u003e Name the \u003ccode\u003etestEnvironmentOptions.globalsCleanup\u003c/code\u003e option and link the docs from the \u003ccode\u003eJEST-01\u003c/code\u003e deprecation warning, and document the option's modes (\u003ca href=\"https://redirect.github.com/jestjs/jest/pull/16404\"\u003e#16404\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/HuzaifaChaudary\"\u003e\u003ccode\u003e@​HuzaifaChaudary\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/jestjs/jest/pull/16413\"\u003ejestjs/jest#16413\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/jestjs/jest/compare/v30.5.0...v30.5.1\"\u003ehttps://github.com/jestjs/jest/compare/v30.5.0...v30.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev30.5.0\u003c/h2\u003e\n\u003cp\u003eOn a personal note: King Harald V of Norway passed away this morning. He ascended the throne 35 years ago, two months before I was born. This release is dedicated to his memory. Hvil i fred 🇳🇴\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003eThis is a big release. It touches \u003ccode\u003ejest-runtime\u003c/code\u003e, \u003ccode\u003ejest-resolve\u003c/code\u003e and \u003ccode\u003ejest-haste-map\u003c/code\u003e in many places, and with this many changes there might be regressions 😬. If your suite behaves differently after upgrading, please \u003ca href=\"https://github.com/jestjs/jest/issues\"\u003eopen an issue\u003c/a\u003e.\u003c/p\u003e\n\u003ch1\u003eHighlights\u003c/h1\u003e\n\u003ch2\u003e\u003ccode\u003ewhenCalledWith\u003c/code\u003e\u003c/h2\u003e\n\u003cp\u003eMock functions can now configure return values per argument list, contributed by \u003ca href=\"https://github.com/timkindberg\"\u003e\u003ccode\u003e@​timkindberg\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/jestjs/jest/pull/16053\"\u003e#16053\u003c/a\u003e):\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003econst fn = jest.fn();\r\nfn.whenCalledWith('apple').mockReturnValue('red');\r\nfn.w...\n\n_Description has been truncated_","html_url":"https://github.com/nschneble/linklater/pull/177","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/nschneble%2Flinklater/issues/177","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/177/packages"},{"uuid":"5427082744","node_id":"PR_kwDOPVYLUM8AAAABDLVD3g","number":1264,"state":"open","title":"chore(deps): bump undici from 8.10.0 to 8.10.2","user":"dependabot[bot]","labels":["dependencies","javascript","agent:clean"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T17:14:29.000Z","updated_at":"2026-09-11T17:15:58.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"undici","old_version":"8.10.0","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 8.10.0 to 8.10.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm\"\u003eGHSA-vp8m-p9jh-q5pm\u003c/a\u003e: cache and deduplication interceptors could use caller-controlled request metadata instead of the authoritative dispatcher origin, enabling cross-origin cache poisoning and data disclosure. Undici now derives interceptor identities from the dispatcher origin and bypasses origin-dependent interceptors when no authoritative origin exists. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/caf6194d3dae989b731ed87ab85f182befe5eb80\"\u003ecaf6194d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e8f5868fb\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e66e12816\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6\"\u003e4411a238\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/662d0ea671fe64139e79533c913fce412765e1d7\"\u003e662d0ea6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003ecb75bbb3\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e7aac7f12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003ee905b5b8\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e2be07bf9\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e6d583124\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e0160a719\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps-dev): bump undici from 6.27.0 to 6.28.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5653\"\u003enodejs/undici#5653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump jest from 30.4.2 to 30.5.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5750\"\u003enodejs/undici#5750\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/analyze from 4.37.3 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5752\"\u003enodejs/undici#5752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5754\"\u003enodejs/undici#5754\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(h2): cover stream reset with NGHTTP2_INTERNAL_ERROR by \u003ca href=\"https://github.com/zeexzeex\"\u003e\u003ccode\u003e@​zeexzeex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5725\"\u003enodejs/undici#5725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): reject invalid resumed responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5724\"\u003enodejs/undici#5724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: make stale-while-revalidate cache update test deterministic by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5722\"\u003enodejs/undici#5722\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid unbounded recursion in Set-Cookie attribute parser by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5757\"\u003enodejs/undici#5757\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: honor SOCKS5 connection timeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5733\"\u003enodejs/undici#5733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(eventsource): validate Last-Event-ID on reconnect by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5746\"\u003enodejs/undici#5746\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid duplicate release attempts by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5745\"\u003enodejs/undici#5745\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(cache): refetch when 304 adds vary fields by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5732\"\u003enodejs/undici#5732\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etypes: expose PendingInterceptor and PendingInterceptorsFormatter on the MockAgent namespace by \u003ca href=\"https://github.com/RaphaelFakhri\"\u003e\u003ccode\u003e@​RaphaelFakhri\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5721\"\u003enodejs/undici#5721\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(codeql): align CodeQL action versions to v4.37.9 by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5759\"\u003enodejs/undici#5759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5760\"\u003enodejs/undici#5760\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(proxy-agent): guard Proxy-Authorization in iterable header containers by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5758\"\u003enodejs/undici#5758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: name the parameters these two blocks describe by \u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): fail the connection on a non-200 h2 extended CONNECT response by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(node-fetch): re-enable the set-cookie header combining test by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5730\"\u003enodejs/undici#5730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward rawHeaders writes through RetryController by \u003ca href=\"https://github.com/official-burak\"\u003e\u003ccode\u003e@​official-burak\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5727\"\u003enodejs/undici#5727\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5738\"\u003enodejs/undici#5738\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/5e541e0b9df7563e5766bbd469fbfe383d9ae6ca\"\u003e\u003ccode\u003e5e541e0\u003c/code\u003e\u003c/a\u003e Bumped v8.10.2 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5771\"\u003e#5771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/eb04cc39954e63e9b46bdf824e6efad9fff2e7b5\"\u003e\u003ccode\u003eeb04cc3\u003c/code\u003e\u003c/a\u003e fix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5738\"\u003e#5738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003e\u003ccode\u003ee905b5b\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e\u003ccode\u003e0160a71\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e\u003ccode\u003e66e1281\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e\u003ccode\u003e7aac7f1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003e\u003ccode\u003ecb75bbb\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e\u003ccode\u003e6d58312\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e\u003ccode\u003e8f5868f\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e\u003ccode\u003e2be07bf\u003c/code\u003e\u003c/a\u003e fix(cache): reject unsafe method response caching\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v8.10.0...v8.10.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=8.10.0\u0026new-version=8.10.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/Nano-Collective/nanocoder/pull/1264","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Nano-Collective%2Fnanocoder/issues/1264","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1264/packages"},{"uuid":"5426665380","node_id":"PR_kwDOPbQ_jc8AAAABDK_aVQ","number":1308,"state":"open","title":"chore(deps): bump undici from 7.28.0 to 8.10.2","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T16:29:28.000Z","updated_at":"2026-09-11T16:31:10.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"undici","old_version":"7.28.0","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 7.28.0 to 8.10.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm\"\u003eGHSA-vp8m-p9jh-q5pm\u003c/a\u003e: cache and deduplication interceptors could use caller-controlled request metadata instead of the authoritative dispatcher origin, enabling cross-origin cache poisoning and data disclosure. Undici now derives interceptor identities from the dispatcher origin and bypasses origin-dependent interceptors when no authoritative origin exists. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/caf6194d3dae989b731ed87ab85f182befe5eb80\"\u003ecaf6194d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e8f5868fb\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e66e12816\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6\"\u003e4411a238\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/662d0ea671fe64139e79533c913fce412765e1d7\"\u003e662d0ea6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003ecb75bbb3\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e7aac7f12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003ee905b5b8\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e2be07bf9\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e6d583124\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e0160a719\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps-dev): bump undici from 6.27.0 to 6.28.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5653\"\u003enodejs/undici#5653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump jest from 30.4.2 to 30.5.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5750\"\u003enodejs/undici#5750\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/analyze from 4.37.3 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5752\"\u003enodejs/undici#5752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5754\"\u003enodejs/undici#5754\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(h2): cover stream reset with NGHTTP2_INTERNAL_ERROR by \u003ca href=\"https://github.com/zeexzeex\"\u003e\u003ccode\u003e@​zeexzeex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5725\"\u003enodejs/undici#5725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): reject invalid resumed responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5724\"\u003enodejs/undici#5724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: make stale-while-revalidate cache update test deterministic by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5722\"\u003enodejs/undici#5722\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid unbounded recursion in Set-Cookie attribute parser by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5757\"\u003enodejs/undici#5757\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: honor SOCKS5 connection timeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5733\"\u003enodejs/undici#5733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(eventsource): validate Last-Event-ID on reconnect by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5746\"\u003enodejs/undici#5746\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid duplicate release attempts by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5745\"\u003enodejs/undici#5745\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(cache): refetch when 304 adds vary fields by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5732\"\u003enodejs/undici#5732\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etypes: expose PendingInterceptor and PendingInterceptorsFormatter on the MockAgent namespace by \u003ca href=\"https://github.com/RaphaelFakhri\"\u003e\u003ccode\u003e@​RaphaelFakhri\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5721\"\u003enodejs/undici#5721\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(codeql): align CodeQL action versions to v4.37.9 by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5759\"\u003enodejs/undici#5759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5760\"\u003enodejs/undici#5760\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(proxy-agent): guard Proxy-Authorization in iterable header containers by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5758\"\u003enodejs/undici#5758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: name the parameters these two blocks describe by \u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): fail the connection on a non-200 h2 extended CONNECT response by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(node-fetch): re-enable the set-cookie header combining test by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5730\"\u003enodejs/undici#5730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward rawHeaders writes through RetryController by \u003ca href=\"https://github.com/official-burak\"\u003e\u003ccode\u003e@​official-burak\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5727\"\u003enodejs/undici#5727\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5738\"\u003enodejs/undici#5738\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/5e541e0b9df7563e5766bbd469fbfe383d9ae6ca\"\u003e\u003ccode\u003e5e541e0\u003c/code\u003e\u003c/a\u003e Bumped v8.10.2 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5771\"\u003e#5771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/eb04cc39954e63e9b46bdf824e6efad9fff2e7b5\"\u003e\u003ccode\u003eeb04cc3\u003c/code\u003e\u003c/a\u003e fix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5738\"\u003e#5738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003e\u003ccode\u003ee905b5b\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e\u003ccode\u003e0160a71\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e\u003ccode\u003e66e1281\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e\u003ccode\u003e7aac7f1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003e\u003ccode\u003ecb75bbb\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e\u003ccode\u003e6d58312\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e\u003ccode\u003e8f5868f\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e\u003ccode\u003e2be07bf\u003c/code\u003e\u003c/a\u003e fix(cache): reject unsafe method response caching\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v8.10.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=7.28.0\u0026new-version=8.10.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/hackerai-tech/hackerai/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/hackerai-tech/hackerai/pull/1308","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/hackerai-tech%2Fhackerai/issues/1308","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1308/packages"},{"uuid":"5426437776","node_id":"PR_kwDOQzBxXc8AAAABDKzhQQ","number":3686,"state":"open","title":"chore(deps): bump the production-minor-and-patch group across 1 directory with 15 updates","user":"dependabot[bot]","labels":["dependencies","javascript","P2","status: ⏳ waiting on author","merge-risk: 🚨 automation","rating: 🦐 gold shrimp","needs-cli-release"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T16:05:30.000Z","updated_at":"2026-09-11T16:10:15.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"production-minor-and-patch","update_count":15,"packages":[{"name":"@openclaw/plugin-inspector","old_version":"0.3.23","new_version":"0.3.24","repository_url":"https://github.com/openclaw/plugin-inspector"},{"name":"@tanstack/react-router","old_version":"1.170.29","new_version":"1.170.33","repository_url":"https://github.com/TanStack/router"},{"name":"@tanstack/react-start","old_version":"1.168.46","new_version":"1.168.50","repository_url":"https://github.com/TanStack/router"},{"name":"@vercel/oidc","old_version":"3.8.4","new_version":"3.8.5","repository_url":"https://github.com/vercel/vercel"},{"name":"convex","old_version":"1.44.0","new_version":"1.45.0","repository_url":"https://github.com/get-convex/convex-backend"},{"name":"convex-helpers","old_version":"0.1.123","new_version":"0.1.124","repository_url":"https://github.com/get-convex/convex-helpers"},{"name":"ignore","old_version":"7.0.6","new_version":"7.0.9","repository_url":"https://github.com/kaelzhang/node-ignore"},{"name":"jose","old_version":"6.2.9","new_version":"6.2.12","repository_url":"https://github.com/panva/jose"},{"name":"lucide-react","old_version":"1.31.0","new_version":"1.43.0","repository_url":"https://github.com/lucide-icons/lucide"},{"name":"mermaid","old_version":"11.16.1","new_version":"11.17.2","repository_url":"https://github.com/mermaid-js/mermaid"},{"name":"resend","old_version":"6.20.0","new_version":"6.26.0","repository_url":"https://github.com/resend/resend-node"},{"name":"zod","old_version":"4.4.3","new_version":"4.5.4","repository_url":"https://github.com/colinhacks/zod"},{"name":"undici","old_version":"7.29.0","new_version":"7.29.1","repository_url":"https://github.com/nodejs/undici"},{"name":"@clack/prompts","old_version":"1.7.0","new_version":"1.8.0","repository_url":"https://github.com/bombshell-dev/clack"},{"name":"p-retry","old_version":"8.0.0","new_version":"8.0.1","repository_url":"https://github.com/sindresorhus/p-retry"}],"path":null,"ecosystem":"npm"},"body":"Bumps the production-minor-and-patch group with 15 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@openclaw/plugin-inspector](https://github.com/openclaw/plugin-inspector) | `0.3.23` | `0.3.24` |\n| [@tanstack/react-router](https://github.com/TanStack/router/tree/HEAD/packages/react-router) | `1.170.29` | `1.170.33` |\n| [@tanstack/react-start](https://github.com/TanStack/router/tree/HEAD/packages/react-start) | `1.168.46` | `1.168.50` |\n| [@vercel/oidc](https://github.com/vercel/vercel/tree/HEAD/packages/oidc) | `3.8.4` | `3.8.5` |\n| [convex](https://github.com/get-convex/convex-backend/tree/HEAD/npm-packages/convex) | `1.44.0` | `1.45.0` |\n| [convex-helpers](https://github.com/get-convex/convex-helpers/tree/HEAD/packages/convex-helpers) | `0.1.123` | `0.1.124` |\n| [ignore](https://github.com/kaelzhang/node-ignore) | `7.0.6` | `7.0.9` |\n| [jose](https://github.com/panva/jose) | `6.2.9` | `6.2.12` |\n| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.31.0` | `1.43.0` |\n| [mermaid](https://github.com/mermaid-js/mermaid) | `11.16.1` | `11.17.2` |\n| [resend](https://github.com/resend/resend-node) | `6.20.0` | `6.26.0` |\n| [zod](https://github.com/colinhacks/zod) | `4.4.3` | `4.5.4` |\n| [undici](https://github.com/nodejs/undici) | `7.29.0` | `7.29.1` |\n| [@clack/prompts](https://github.com/bombshell-dev/clack/tree/HEAD/packages/prompts) | `1.7.0` | `1.8.0` |\n| [p-retry](https://github.com/sindresorhus/p-retry) | `8.0.0` | `8.0.1` |\n\n\nUpdates `@openclaw/plugin-inspector` from 0.3.23 to 0.3.24\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/openclaw/plugin-inspector/releases\"\u003e@​openclaw/plugin-inspector's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eplugin-inspector v0.3.24\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRecognize compiled CommonJS plugin factory calls when checking expected channel registrations, preserving source references and excluding factory values passed to wrappers.\u003c/li\u003e\n\u003cli\u003eClassify widget presenters as metadata-only synthetic probes without invoking presentation callbacks.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVerification\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/@openclaw/plugin-inspector/v/0.3.24\"\u003enpm package 0.3.24\u003c/a\u003e · \u003ca href=\"https://registry.npmjs.org/@openclaw/plugin-inspector/-/plugin-inspector-0.3.24.tgz\"\u003eregistry tarball\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openclaw/plugin-inspector/actions/runs/33412907740\"\u003eSuccessful release workflow\u003c/a\u003e, source \u003ccode\u003e92db8c57e1d5544c522c7c882a33be1ad4e253b9\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eRegistry signatures and provenance verified for this package, tag, workflow, source commit, and run attempt. The complete uncompressed package archive matches the locally tested candidate.\u003c/li\u003e\n\u003cli\u003eTarball SHA-256: \u003ccode\u003e292232b5c2aa34a73ef110333a14240ec07b53a730be1d2d62cb4c76441e9404\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eIntegrity: \u003ccode\u003esha512-g74+lsc3vSinAKbaqlsSvsaWvzkFv71ZVWOzXp4uFDisR1g9fiv/HvoKQI3uenlV0aJr/oD+FZukTs/jyXlr/A==\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/openclaw/plugin-inspector/blob/main/CHANGELOG.md\"\u003e@​openclaw/plugin-inspector's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.3.24 - 2026-08-31\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRecognize compiled CommonJS plugin factory calls when checking expected channel registrations, preserving source references and excluding factory values passed to wrappers.\u003c/li\u003e\n\u003cli\u003eClassify widget presenters as metadata-only synthetic probes without invoking presentation callbacks.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openclaw/plugin-inspector/commit/92db8c57e1d5544c522c7c882a33be1ad4e253b9\"\u003e\u003ccode\u003e92db8c5\u003c/code\u003e\u003c/a\u003e chore: prepare plugin-inspector 0.3.24 (\u003ca href=\"https://redirect.github.com/openclaw/plugin-inspector/issues/67\"\u003e#67\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openclaw/plugin-inspector/commit/2c7629c625667f9939a811db0f6cd83db16f2121\"\u003e\u003ccode\u003e2c7629c\u003c/code\u003e\u003c/a\u003e fix: recognize compiled factories and classify widget presenters (\u003ca href=\"https://redirect.github.com/openclaw/plugin-inspector/issues/66\"\u003e#66\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openclaw/plugin-inspector/commit/1bc30801caa74d8cab760eb62638098c9d9402a7\"\u003e\u003ccode\u003e1bc3080\u003c/code\u003e\u003c/a\u003e chore(deps): refresh Crabbox pnpm to 12.1.0 (\u003ca href=\"https://redirect.github.com/openclaw/plugin-inspector/issues/65\"\u003e#65\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/openclaw/plugin-inspector/compare/v0.3.23...v0.3.24\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@tanstack/react-router` from 1.170.29 to 1.170.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/TanStack/router/releases\"\u003e@​tanstack/react-router's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​tanstack/react-router\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.33\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8165\"\u003e#8165\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/2f20c00224c5ba63467551914e0c37012588c4c2\"\u003e\u003ccode\u003e2f20c00\u003c/code\u003e\u003c/a\u003e - Exclude structural descendants below error and not-found boundaries from route lifecycle callbacks. Preserve lifecycle membership through invalidation, hydration, background reloads, and superseded navigation publication.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8209\"\u003e#8209\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/28a5e4504e4ea5cb1480667a4bea2588a53e110f\"\u003e\u003ccode\u003e28a5e45\u003c/code\u003e\u003c/a\u003e - Preserve falsy thrown values in React and Vue error boundaries. Type React and Vue boundary error components and \u003ccode\u003eonCatch\u003c/code\u003e callbacks as \u003ccode\u003eunknown\u003c/code\u003e. Solid boundary errors remain typed as \u003ccode\u003eError\u003c/code\u003e; SSR now wraps non-\u003ccode\u003eError\u003c/code\u003e loader errors to match Solid’s native boundary behavior, preserving the original value in \u003ccode\u003ecause\u003c/code\u003e. Router state and loader \u003ccode\u003eonError\u003c/code\u003e values are unchanged.\u003c/p\u003e\n\u003cp\u003eWhen upgrading React or Vue, narrow boundary errors (for example, with \u003ccode\u003eerror instanceof Error\u003c/code\u003e) before reading \u003ccode\u003emessage\u003c/code\u003e or \u003ccode\u003estack\u003c/code\u003e. \u003ccode\u003eErrorComponentProps\u0026lt;TError\u0026gt;\u003c/code\u003e remains available for values narrowed to a specific error type. Route \u003ccode\u003eonError\u003c/code\u003e types are unchanged.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8161\"\u003e#8161\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/f0b5eda544606686a8a8d675a686ca1366428b96\"\u003e\u003ccode\u003ef0b5eda\u003c/code\u003e\u003c/a\u003e - Retain successful not-found matches as terminal shared boundaries during client navigation, preserving route context while the destination loads.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8251\"\u003e#8251\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/0497caeef3ff7e1c1c6080eca38bca24e7ec320b\"\u003e\u003ccode\u003e0497cae\u003c/code\u003e\u003c/a\u003e - Use URL.canParse for absolute URL checks in links, navigation, redirects, and build configuration. Preserve a URL constructor fallback for older browsers.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8169\"\u003e#8169\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/0caf6b9a2b7e14b0b146c74cc27cb05c19d700a5\"\u003e\u003ccode\u003e0caf6b9\u003c/code\u003e\u003c/a\u003e - Fix route-scoped \u003ccode\u003euseMatch\u003c/code\u003e, \u003ccode\u003euseSearch\u003c/code\u003e, and \u003ccode\u003euseParams\u003c/code\u003e APIs to forward the \u003ccode\u003eshouldThrow\u003c/code\u003e option and preserve optional return types when \u003ccode\u003eshouldThrow: false\u003c/code\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8257\"\u003e#8257\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/cf166d160e6397007a979bfc7065b45ff69ea543\"\u003e\u003ccode\u003ecf166d1\u003c/code\u003e\u003c/a\u003e - Fix repeated \u003ccode\u003einnerHTML\u003c/code\u003e writes for unchanged styles and data scripts during React re-renders. This prevents unnecessary CSS parsing and Trusted Types errors during client navigation.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated dependencies [\u003ca href=\"https://github.com/TanStack/router/commit/edf0e16ebfe82ec6e8f68f403a1fda8de9e28889\"\u003e\u003ccode\u003eedf0e16\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/2f20c00224c5ba63467551914e0c37012588c4c2\"\u003e\u003ccode\u003e2f20c00\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/28a5e4504e4ea5cb1480667a4bea2588a53e110f\"\u003e\u003ccode\u003e28a5e45\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/08eff50c447a154a3373909009e9e4375cea17ce\"\u003e\u003ccode\u003e08eff50\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/216c0c48036fd1a33163b70dcabfed2b893808b0\"\u003e\u003ccode\u003e216c0c4\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/2f9150309bc472f4a75cbe98adcdb50c76b12c7a\"\u003e\u003ccode\u003e2f91503\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/f0b5eda544606686a8a8d675a686ca1366428b96\"\u003e\u003ccode\u003ef0b5eda\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/50eafcaebbbedb6fde3b2816de7a0ace8cde4832\"\u003e\u003ccode\u003e50eafca\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/0497caeef3ff7e1c1c6080eca38bca24e7ec320b\"\u003e\u003ccode\u003e0497cae\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/ee283480dfa51150a2e0b096a6eff94a89ff8b3f\"\u003e\u003ccode\u003eee28348\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/9035abc41163d83409ef582f7743a3c7be57dd93\"\u003e\u003ccode\u003e9035abc\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/c18e69081475a7c98f9d40bd0fe6da78ccb84598\"\u003e\u003ccode\u003ec18e690\u003c/code\u003e\u003c/a\u003e]:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/router-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.171.28\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/history\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.162.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/TanStack/router/blob/main/packages/react-router/CHANGELOG.md\"\u003e@​tanstack/react-router's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.170.33\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8165\"\u003e#8165\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/2f20c00224c5ba63467551914e0c37012588c4c2\"\u003e\u003ccode\u003e2f20c00\u003c/code\u003e\u003c/a\u003e - Exclude structural descendants below error and not-found boundaries from route lifecycle callbacks. Preserve lifecycle membership through invalidation, hydration, background reloads, and superseded navigation publication.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8209\"\u003e#8209\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/28a5e4504e4ea5cb1480667a4bea2588a53e110f\"\u003e\u003ccode\u003e28a5e45\u003c/code\u003e\u003c/a\u003e - Preserve falsy thrown values in React and Vue error boundaries. Type React and Vue boundary error components and \u003ccode\u003eonCatch\u003c/code\u003e callbacks as \u003ccode\u003eunknown\u003c/code\u003e. Solid boundary errors remain typed as \u003ccode\u003eError\u003c/code\u003e; SSR now wraps non-\u003ccode\u003eError\u003c/code\u003e loader errors to match Solid’s native boundary behavior, preserving the original value in \u003ccode\u003ecause\u003c/code\u003e. Router state and loader \u003ccode\u003eonError\u003c/code\u003e values are unchanged.\u003c/p\u003e\n\u003cp\u003eWhen upgrading React or Vue, narrow boundary errors (for example, with \u003ccode\u003eerror instanceof Error\u003c/code\u003e) before reading \u003ccode\u003emessage\u003c/code\u003e or \u003ccode\u003estack\u003c/code\u003e. \u003ccode\u003eErrorComponentProps\u0026lt;TError\u0026gt;\u003c/code\u003e remains available for values narrowed to a specific error type. Route \u003ccode\u003eonError\u003c/code\u003e types are unchanged.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8161\"\u003e#8161\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/f0b5eda544606686a8a8d675a686ca1366428b96\"\u003e\u003ccode\u003ef0b5eda\u003c/code\u003e\u003c/a\u003e - Retain successful not-found matches as terminal shared boundaries during client navigation, preserving route context while the destination loads.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8251\"\u003e#8251\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/0497caeef3ff7e1c1c6080eca38bca24e7ec320b\"\u003e\u003ccode\u003e0497cae\u003c/code\u003e\u003c/a\u003e - Use URL.canParse for absolute URL checks in links, navigation, redirects, and build configuration. Preserve a URL constructor fallback for older browsers.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8169\"\u003e#8169\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/0caf6b9a2b7e14b0b146c74cc27cb05c19d700a5\"\u003e\u003ccode\u003e0caf6b9\u003c/code\u003e\u003c/a\u003e - Fix route-scoped \u003ccode\u003euseMatch\u003c/code\u003e, \u003ccode\u003euseSearch\u003c/code\u003e, and \u003ccode\u003euseParams\u003c/code\u003e APIs to forward the \u003ccode\u003eshouldThrow\u003c/code\u003e option and preserve optional return types when \u003ccode\u003eshouldThrow: false\u003c/code\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8257\"\u003e#8257\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/cf166d160e6397007a979bfc7065b45ff69ea543\"\u003e\u003ccode\u003ecf166d1\u003c/code\u003e\u003c/a\u003e - Fix repeated \u003ccode\u003einnerHTML\u003c/code\u003e writes for unchanged styles and data scripts during React re-renders. This prevents unnecessary CSS parsing and Trusted Types errors during client navigation.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated dependencies [\u003ca href=\"https://github.com/TanStack/router/commit/edf0e16ebfe82ec6e8f68f403a1fda8de9e28889\"\u003e\u003ccode\u003eedf0e16\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/2f20c00224c5ba63467551914e0c37012588c4c2\"\u003e\u003ccode\u003e2f20c00\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/28a5e4504e4ea5cb1480667a4bea2588a53e110f\"\u003e\u003ccode\u003e28a5e45\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/08eff50c447a154a3373909009e9e4375cea17ce\"\u003e\u003ccode\u003e08eff50\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/216c0c48036fd1a33163b70dcabfed2b893808b0\"\u003e\u003ccode\u003e216c0c4\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/2f9150309bc472f4a75cbe98adcdb50c76b12c7a\"\u003e\u003ccode\u003e2f91503\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/f0b5eda544606686a8a8d675a686ca1366428b96\"\u003e\u003ccode\u003ef0b5eda\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/50eafcaebbbedb6fde3b2816de7a0ace8cde4832\"\u003e\u003ccode\u003e50eafca\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/0497caeef3ff7e1c1c6080eca38bca24e7ec320b\"\u003e\u003ccode\u003e0497cae\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/ee283480dfa51150a2e0b096a6eff94a89ff8b3f\"\u003e\u003ccode\u003eee28348\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/9035abc41163d83409ef582f7743a3c7be57dd93\"\u003e\u003ccode\u003e9035abc\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/c18e69081475a7c98f9d40bd0fe6da78ccb84598\"\u003e\u003ccode\u003ec18e690\u003c/code\u003e\u003c/a\u003e]:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/router-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.171.28\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/history\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.162.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.170.32\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8130\"\u003e#8130\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/cb281d70c1f5fe780f9d07bc500ea3a284a4e04b\"\u003e\u003ccode\u003ecb281d7\u003c/code\u003e\u003c/a\u003e - preserve context during reloads\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated dependencies [\u003ca href=\"https://github.com/TanStack/router/commit/fa652872812c9433ba8b9d9a285e51b535e7367c\"\u003e\u003ccode\u003efa65287\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/cb281d70c1f5fe780f9d07bc500ea3a284a4e04b\"\u003e\u003ccode\u003ecb281d7\u003c/code\u003e\u003c/a\u003e]:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/router-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.171.27\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.170.31\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies [\u003ca href=\"https://github.com/TanStack/router/commit/3e016ac84ffec8119f0c25cfdd1fb17e5292bd34\"\u003e\u003ccode\u003e3e016ac\u003c/code\u003e\u003c/a\u003e]:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/router-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.171.26\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.170.30\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8084\"\u003e#8084\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/5d3785dcc366b66b1c261b5d01e66af778ff1175\"\u003e\u003ccode\u003e5d3785d\u003c/code\u003e\u003c/a\u003e - preserve pending UI across retained routes\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8068\"\u003e#8068\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/f75cada01707e51fb9650dd301bc04f8b2265a2a\"\u003e\u003ccode\u003ef75cada\u003c/code\u003e\u003c/a\u003e - direct export of CatchBoundary class component, remove function wrapper\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated dependencies [\u003ca href=\"https://github.com/TanStack/router/commit/5d3785dcc366b66b1c261b5d01e66af778ff1175\"\u003e\u003ccode\u003e5d3785d\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/63d2cc9155ff5374112f7d067d0b278bafeb8486\"\u003e\u003ccode\u003e63d2cc9\u003c/code\u003e\u003c/a\u003e]:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/router-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.171.25\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/a58e01c604e2d189ef8c8c1ad6ac8747e03aa88c\"\u003e\u003ccode\u003ea58e01c\u003c/code\u003e\u003c/a\u003e ci: Version Packages (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-router/issues/8182\"\u003e#8182\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/08eff50c447a154a3373909009e9e4375cea17ce\"\u003e\u003ccode\u003e08eff50\u003c/code\u003e\u003c/a\u003e fix(router-core): fix dangling references in published declarations (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-router/issues/8207\"\u003e#8207\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/cf166d160e6397007a979bfc7065b45ff69ea543\"\u003e\u003ccode\u003ecf166d1\u003c/code\u003e\u003c/a\u003e fix(react-router): avoid rewriting unchanged head assets (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-router/issues/8257\"\u003e#8257\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/07b3bc971de1538264dcb461aea28a80e8209efc\"\u003e\u003ccode\u003e07b3bc9\u003c/code\u003e\u003c/a\u003e test(react-router): cover pending and not-found context (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-router/issues/8243\"\u003e#8243\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/2f20c00224c5ba63467551914e0c37012588c4c2\"\u003e\u003ccode\u003e2f20c00\u003c/code\u003e\u003c/a\u003e fix(router-core): skip lifecycle callbacks below fallback boundaries (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-router/issues/8165\"\u003e#8165\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/0497caeef3ff7e1c1c6080eca38bca24e7ec320b\"\u003e\u003ccode\u003e0497cae\u003c/code\u003e\u003c/a\u003e perf(router): use URL.canParse for absolute URL checks (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-router/issues/8251\"\u003e#8251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/28a5e4504e4ea5cb1480667a4bea2588a53e110f\"\u003e\u003ccode\u003e28a5e45\u003c/code\u003e\u003c/a\u003e fix(router): handle unknown error boundary values (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-router/issues/8209\"\u003e#8209\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/f0b5eda544606686a8a8d675a686ca1366428b96\"\u003e\u003ccode\u003ef0b5eda\u003c/code\u003e\u003c/a\u003e fix(router-core): retain not-found boundary during navigation (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-router/issues/8161\"\u003e#8161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/0caf6b9a2b7e14b0b146c74cc27cb05c19d700a5\"\u003e\u003ccode\u003e0caf6b9\u003c/code\u003e\u003c/a\u003e fix: preserve shouldThrow in route-scoped hooks (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-router/issues/8169\"\u003e#8169\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/a5a5bacc8fdf30b7823caf0a94908c3e0db27aa2\"\u003e\u003ccode\u003ea5a5bac\u003c/code\u003e\u003c/a\u003e ci: Version Packages (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-router/issues/8133\"\u003e#8133\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/TanStack/router/commits/@tanstack/react-router@1.170.33/packages/react-router\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@tanstack/react-start` from 1.168.46 to 1.168.50\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/TanStack/router/releases\"\u003e@​tanstack/react-start's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​tanstack/react-start\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.168.50\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies [\u003ca href=\"https://github.com/TanStack/router/commit/2f20c00224c5ba63467551914e0c37012588c4c2\"\u003e\u003ccode\u003e2f20c00\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/28a5e4504e4ea5cb1480667a4bea2588a53e110f\"\u003e\u003ccode\u003e28a5e45\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/f0b5eda544606686a8a8d675a686ca1366428b96\"\u003e\u003ccode\u003ef0b5eda\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/37877da166fe4ce055c7b85e138b6681ebd7e8b4\"\u003e\u003ccode\u003e37877da\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/0497caeef3ff7e1c1c6080eca38bca24e7ec320b\"\u003e\u003ccode\u003e0497cae\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/0caf6b9a2b7e14b0b146c74cc27cb05c19d700a5\"\u003e\u003ccode\u003e0caf6b9\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/cf166d160e6397007a979bfc7065b45ff69ea543\"\u003e\u003ccode\u003ecf166d1\u003c/code\u003e\u003c/a\u003e]:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-router\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.33\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-plugin-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.171.40\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-client\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.168.31\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-rsc\u003c/code\u003e\u003ca href=\"https://github.com/0\"\u003e\u003ccode\u003e@​0\u003c/code\u003e\u003c/a\u003e.1.49\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-server\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.167.38\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-client-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.28\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-server-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.169.32\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/TanStack/router/blob/main/packages/react-start/CHANGELOG.md\"\u003e@​tanstack/react-start's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.168.50\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies [\u003ca href=\"https://github.com/TanStack/router/commit/2f20c00224c5ba63467551914e0c37012588c4c2\"\u003e\u003ccode\u003e2f20c00\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/28a5e4504e4ea5cb1480667a4bea2588a53e110f\"\u003e\u003ccode\u003e28a5e45\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/f0b5eda544606686a8a8d675a686ca1366428b96\"\u003e\u003ccode\u003ef0b5eda\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/37877da166fe4ce055c7b85e138b6681ebd7e8b4\"\u003e\u003ccode\u003e37877da\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/0497caeef3ff7e1c1c6080eca38bca24e7ec320b\"\u003e\u003ccode\u003e0497cae\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/0caf6b9a2b7e14b0b146c74cc27cb05c19d700a5\"\u003e\u003ccode\u003e0caf6b9\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/cf166d160e6397007a979bfc7065b45ff69ea543\"\u003e\u003ccode\u003ecf166d1\u003c/code\u003e\u003c/a\u003e]:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-router\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.33\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-plugin-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.171.40\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-client\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.168.31\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-rsc\u003c/code\u003e\u003ca href=\"https://github.com/0\"\u003e\u003ccode\u003e@​0\u003c/code\u003e\u003c/a\u003e.1.49\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-server\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.167.38\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-client-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.28\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-server-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.169.32\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.168.49\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies [\u003ca href=\"https://github.com/TanStack/router/commit/cb281d70c1f5fe780f9d07bc500ea3a284a4e04b\"\u003e\u003ccode\u003ecb281d7\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/a0041bb36e700b3263b894e4d1573d924383b56b\"\u003e\u003ccode\u003ea0041bb\u003c/code\u003e\u003c/a\u003e]:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-router\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.32\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-plugin-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.171.39\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-client\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.168.30\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-rsc\u003c/code\u003e\u003ca href=\"https://github.com/0\"\u003e\u003ccode\u003e@​0\u003c/code\u003e\u003c/a\u003e.1.48\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-server\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.167.37\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-client-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.27\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-server-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.169.31\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.168.48\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies []:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-router\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.31\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-client\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.168.29\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-rsc\u003c/code\u003e\u003ca href=\"https://github.com/0\"\u003e\u003ccode\u003e@​0\u003c/code\u003e\u003c/a\u003e.1.47\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-server\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.167.36\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-client-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.26\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-plugin-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.171.38\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-server-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.169.30\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.168.47\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies [\u003ca href=\"https://github.com/TanStack/router/commit/5d3785dcc366b66b1c261b5d01e66af778ff1175\"\u003e\u003ccode\u003e5d3785d\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/f75cada01707e51fb9650dd301bc04f8b2265a2a\"\u003e\u003ccode\u003ef75cada\u003c/code\u003e\u003c/a\u003e]:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-router\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.30\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-client\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.168.28\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-rsc\u003c/code\u003e\u003ca href=\"https://github.com/0\"\u003e\u003ccode\u003e@​0\u003c/code\u003e\u003c/a\u003e.1.46\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-server\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.167.35\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-client-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.25\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-plugin-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.171.37\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/a58e01c604e2d189ef8c8c1ad6ac8747e03aa88c\"\u003e\u003ccode\u003ea58e01c\u003c/code\u003e\u003c/a\u003e ci: Version Packages (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-start/issues/8182\"\u003e#8182\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/a5a5bacc8fdf30b7823caf0a94908c3e0db27aa2\"\u003e\u003ccode\u003ea5a5bac\u003c/code\u003e\u003c/a\u003e ci: Version Packages (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-start/issues/8133\"\u003e#8133\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/4fcbcde90d1c356baa741a98f3947b36b821ecc6\"\u003e\u003ccode\u003e4fcbcde\u003c/code\u003e\u003c/a\u003e ci: Version Packages (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-start/issues/8119\"\u003e#8119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/a78f2af5b49ba21d50398611f55fa4195cb83e67\"\u003e\u003ccode\u003ea78f2af\u003c/code\u003e\u003c/a\u003e ci: Version Packages (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-start/issues/8079\"\u003e#8079\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/f97188fdb4c3964bd47b556a904cd85e3142d06e\"\u003e\u003ccode\u003ef97188f\u003c/code\u003e\u003c/a\u003e chore: localize package dependencies (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-start/issues/8078\"\u003e#8078\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/TanStack/router/commits/@tanstack/react-start@1.168.50/packages/react-start\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@vercel/oidc` from 3.8.4 to 3.8.5\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/vercel/blob/main/packages/oidc/CHANGELOG.md\"\u003e@​vercel/oidc's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.8.5\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies [7a3a2ef]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​vercel/cli-config\u003c/code\u003e\u003ca href=\"https://github.com/0\"\u003e\u003ccode\u003e@​0\u003c/code\u003e\u003c/a\u003e.2.4\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/vercel/commit/7978e3ccfed6daf3da1fd8adf4eb85f136e52f9e\"\u003e\u003ccode\u003e7978e3c\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/vercel/tree/HEAD/packages/oidc/issues/13861\"\u003e#13861\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/vercel/commit/d1ca3ed3ac1b9830403dc9dc3520e963ef8bec8e\"\u003e\u003ccode\u003ed1ca3ed\u003c/code\u003e\u003c/a\u003e Upgrade tests to run on Node 22 by default (\u003ca href=\"https://github.com/vercel/vercel/tree/HEAD/packages/oidc/issues/13856\"\u003e#13856\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/vercel/commit/814148b7a06bcbb2e9dda34772e70c991a1c6f42\"\u003e\u003ccode\u003e814148b\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/vercel/tree/HEAD/packages/oidc/issues/13782\"\u003e#13782\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/vercel/commit/821e4b8e8eded000b3d4e864594730e8741ef522\"\u003e\u003ccode\u003e821e4b8\u003c/code\u003e\u003c/a\u003e [oidc] add file extension to dynamic imports (\u003ca href=\"https://github.com/vercel/vercel/tree/HEAD/packages/oidc/issues/13815\"\u003e#13815\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/vercel/commit/17a7205fd554ef8af9680fa0aa111fa0489d8708\"\u003e\u003ccode\u003e17a7205\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/vercel/tree/HEAD/packages/oidc/issues/13763\"\u003e#13763\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/vercel/commit/0617e3ef5def33d0ec051432f87f60d5bb7ed604\"\u003e\u003ccode\u003e0617e3e\u003c/code\u003e\u003c/a\u003e Lower version of \u003ccode\u003e@​vercel/oidc\u003c/code\u003e so it stops breaking releases (\u003ca href=\"https://github.com/vercel/vercel/tree/HEAD/packages/oidc/issues/13729\"\u003e#13729\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/vercel/commit/775e077713cc30f65ab63e04279f743a06652c2c\"\u003e\u003ccode\u003e775e077\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/vercel/tree/HEAD/packages/oidc/issues/13682\"\u003e#13682\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/vercel/commit/a133e534e7dfd785beeeb0dcafed8d2c991e9f11\"\u003e\u003ccode\u003ea133e53\u003c/code\u003e\u003c/a\u003e Add refresh token behavior to getVercelOidcToken (\u003ca href=\"https://github.com/vercel/vercel/tree/HEAD/packages/oidc/issues/13608\"\u003e#13608\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/vercel/commit/444a0e21f754dea678ef3d115cf908da21217c73\"\u003e\u003ccode\u003e444a0e2\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/vercel/tree/HEAD/packages/oidc/issues/13605\"\u003e#13605\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/vercel/commit/fa8d4c76ea50c4844031f56209b21845818212fc\"\u003e\u003ccode\u003efa8d4c7\u003c/code\u003e\u003c/a\u003e create \u003ccode\u003e@​vercel/oidc\u003c/code\u003e and \u003ccode\u003e@​vercel/oidc-aws-credentials-provider\u003c/code\u003e  (\u003ca href=\"https://github.com/vercel/vercel/tree/HEAD/packages/oidc/issues/13548\"\u003e#13548\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/vercel/vercel/commits/@vercel/frameworks@3.8.5/packages/oidc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `convex` from 1.44.0 to 1.45.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/get-convex/convex-backend/blob/main/npm-packages/convex/CHANGELOG.md\"\u003econvex's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.45.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eLocal deployments now upgrade to a new backend version in place, instead of\ngoing through a snapshot export and import. Upgrades no longer depend on the\nsize of your local data, and no longer prompt about transferring it.\u003c/li\u003e\n\u003cli\u003eThe Convex MCP server (\u003ccode\u003enpx convex mcp\u003c/code\u003e) now supports the stateless MCP\nprotocol (\u003ccode\u003e2026-07-28\u003c/code\u003e MCP specification).\u003c/li\u003e\n\u003cli\u003eAdded a new \u003ccode\u003egetServiceToken\u003c/code\u003e function that generates service tokens for\nfirst-party Convex services. This will be used by the upcoming Convex AI\ngateway.\u003c/li\u003e\n\u003cli\u003eImproved the error message when \u003ccode\u003enpx convex export\u003c/code\u003e fails because a snapshot\nexport is already in progress.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/get-convex/convex-backend/commits/HEAD/npm-packages/convex\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `convex-helpers` from 0.1.123 to 0.1.124\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/get-convex/convex-helpers/blob/main/packages/convex-helpers/CHANGELOG.md\"\u003econvex-helpers's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.1.124\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003evalidate\u003c/code\u003e now normalizes system table ids (e.g. \u003ccode\u003ev.id(\u0026quot;_storage\u0026quot;)\u003c/code\u003e) with\n\u003ccode\u003edb.system.normalizeId\u003c/code\u003e instead of throwing when passed a real \u003ccode\u003edb\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/get-convex/convex-helpers/commit/cd7c2e4dcab2e8d3c2375ce4c0c99ed4cc6cd35f\"\u003e\u003ccode\u003ecd7c2e4\u003c/code\u003e\u003c/a\u003e npm 0.1.124\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/get-convex/convex-helpers/commit/3c4e0e7d545a34e54302b8b27c084ff6c526b364\"\u003e\u003ccode\u003e3c4e0e7\u003c/code\u003e\u003c/a\u003e fix validation of system table ids (\u003ca href=\"https://github.com/get-convex/convex-helpers/tree/HEAD/packages/convex-helpers/issues/1003\"\u003e#1003\u003c/a\u003e) (\u003ca href=\"https://github.com/get-convex/convex-helpers/tree/HEAD/packages/convex-helpers/issues/1004\"\u003e#1004\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/get-convex/convex-helpers/commits/npm/0.1.124/packages/convex-helpers\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ignore` from 7.0.6 to 7.0.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/kaelzhang/node-ignore/releases\"\u003eignore's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e7.0.8\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003ePATCH\u003c/strong\u003e Brings pattern matching closer to \u003ccode\u003egit\u003c/code\u003e:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ePATCH\u003c/strong\u003e A backslash now makes the next character a literal, exactly as \u003ccode\u003egit\u003c/code\u003e does: \u003ccode\u003e\\*\u003c/code\u003e matches a literal \u003ccode\u003e*\u003c/code\u003e rather than acting as a wildcard, \u003ccode\u003e\\?\u003c/code\u003e matches a literal \u003ccode\u003e?\u003c/code\u003e, and \u003ccode\u003e\\d\u003c/code\u003e, \u003ccode\u003e\\b\u003c/code\u003e, \u003ccode\u003e\\/\u003c/code\u003e and the like are the plain characters instead of regular-expression escapes.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePATCH\u003c/strong\u003e Only a trailing run of spaces is stripped from a pattern — never tabs or other whitespace — and a line of only tabs is treated as a pattern rather than a blank line, matching \u003ccode\u003egit\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAn upgrade is recommended for all dependents.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kaelzhang/node-ignore/commit/821765efdf7752b186a03ed0450d9ee013cee099\"\u003e\u003ccode\u003e821765e\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://redirect.github.com/kaelzhang/node-ignore/issues/166\"\u003e#166\u003c/a\u003e: bump version 7.0.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kaelzhang/node-ignore/commit/e00d35eaee5184cc0176309b680bd252d321c5eb\"\u003e\u003ccode\u003ee00d35e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/kaelzhang/node-ignore/issues/167\"\u003e#167\u003c/a\u003e from bentbrain/fix-bom-blank-line\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kaelzhang/node-ignore/commit/9b6481f88753fd5361ad6c4b945f90e556ea2a49\"\u003e\u003ccode\u003e9b6481f\u003c/code\u003e\u003c/a\u003e fix(ignore): reject BOM-only blank lines before compilation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kaelzhang/node-ignore/commit/20b802ae9e60c304e7fc71e77ffc246be1a02974\"\u003e\u003ccode\u003e20b802a\u003c/code\u003e\u003c/a\u003e bump version 7.0.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kaelzhang/node-ignore/commit/0414358a20becef81d1bcad99df5c8260a3fd8d1\"\u003e\u003ccode\u003e0414358\u003c/code\u003e\u003c/a\u003e build: require 100% coverage of index.js as an explicit gate\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kaelzhang/node-ignore/commit/968aee6885ab2511b0759c2e135b062a4831ee97\"\u003e\u003ccode\u003e968aee6\u003c/code\u003e\u003c/a\u003e compat: check compatibility by running old versions' test suites\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kaelzhang/node-ignore/commit/8e462205940765a6524c5415df281b7725a82e31\"\u003e\u003ccode\u003e8e46220\u003c/code\u003e\u003c/a\u003e build: run the compatibility gate as part of \u003ccode\u003enpm test\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kaelzhang/node-ignore/commit/6e81fb231c76325b35ced3df461c95b5350d729e\"\u003e\u003ccode\u003e6e81fb2\u003c/code\u003e\u003c/a\u003e tidy up how wildcards compile\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kaelzhang/node-ignore/commit/ea3d5ebbe9f47932a5b149675ef26fd54dde0ccd\"\u003e\u003ccode\u003eea3d5eb\u003c/code\u003e\u003c/a\u003e fix: a backslash quotes the next character, and only spaces are trimmed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kaelzhang/node-ignore/commit/01cfbbb2ecc11665192da960ec1fe908d8ad3a47\"\u003e\u003ccode\u003e01cfbbb\u003c/code\u003e\u003c/a\u003e docs: document the known, deliberate differences from git\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/kaelzhang/node-ignore/compare/7.0.6...7.0.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `jose` from 6.2.9 to 6.2.12\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/panva/jose/releases\"\u003ejose's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.2.12\u003c/h2\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eclarify and shorten public API guidance (\u003ca href=\"https://github.com/panva/jose/commit/be62530328431519950a2b6a09ccd1c7de8a38f9\"\u003ebe62530\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003esimplify JWS and JWE operation cores (\u003ca href=\"https://github.com/panva/jose/commit/92e9640290085dd37c152aeb7c4d5b22e9df96ab\"\u003e92e9640\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eavoid copying AES-GCM output (\u003ca href=\"https://github.com/panva/jose/commit/6925d43e05c7d05b0c801fda9eb1835bb8d334ef\"\u003e6925d43\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ededuplicate pending jwks key imports (\u003ca href=\"https://github.com/panva/jose/commit/bf5138b12bf9f8b7dc18f4b26ad1b7395e7e5dd6\"\u003ebf5138b\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eencode single-signature JWS input once (\u003ca href=\"https://github.com/panva/jose/commit/7bc9a3380a7436197bb5d6b377ca232094541c5c\"\u003e7bc9a33\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enormalize General JWE shared headers once (\u003ca href=\"https://github.com/panva/jose/commit/78637bd28031869df8a01cbcd82273c115860e35\"\u003e78637bd\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enormalize jwks selection metadata once (\u003ca href=\"https://github.com/panva/jose/commit/fd3ae3f06efd4760df2631f1b0a08eb4fc448efd\"\u003efd3ae3f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse native encoding for larger ASCII strings (\u003ca href=\"https://github.com/panva/jose/commit/b23a6f378b26e960900761c244a5f383af22dddc\"\u003eb23a6f3\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.2.11\u003c/h2\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003erender subpath indexes as tables (\u003ca href=\"https://github.com/panva/jose/commit/94589ee9efe6cf257a133765d753bbe8d55f6ed3\"\u003e94589ee\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eshorten API index descriptions (\u003ca href=\"https://github.com/panva/jose/commit/681482fcca7577c6a4b8df61c992f195f6e6ac1b\"\u003e681482f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003emodel JWE key management modes (\u003ca href=\"https://github.com/panva/jose/commit/e01dda65d5d272c8dd44710d0c70673c1530038e\"\u003ee01dda6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypes:\u003c/strong\u003e reduce declaration repetition (\u003ca href=\"https://github.com/panva/jose/commit/55b970fc08c9082041f40473470ee0fe0e8b0087\"\u003e55b970f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.2.10\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ejose:\u003c/strong\u003e consume serialization members once (\u003ca href=\"https://github.com/panva/jose/commit/9bee285a6bc356b495c29ae0a5e70b24e723568e\"\u003e9bee285\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejose:\u003c/strong\u003e reject empty protected and JWE AAD members (\u003ca href=\"https://github.com/panva/jose/commit/8da41453dce79967c6e3f47a787039a7f94de8fe\"\u003e8da4145\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejose:\u003c/strong\u003e validate serialized header values (\u003ca href=\"https://github.com/panva/jose/commit/b711d8fe223e3e85520d6c822d7a417cd872b718\"\u003eb711d8f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwe:\u003c/strong\u003e conceal invalid decrypted CEK lengths (\u003ca href=\"https://github.com/panva/jose/commit/41fafe035a62d85f4b313e166100004dd09b111f\"\u003e41fafe0\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwe:\u003c/strong\u003e enforce AES-GCM tag boundaries (\u003ca href=\"https://github.com/panva/jose/commit/9a5b74454bf145a106312d519efe95b8a9b53a87\"\u003e9a5b744\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwe:\u003c/strong\u003e validate explicit encryption parameters (\u003ca href=\"https://github.com/panva/jose/commit/7a02697126e40757ed9e02ae786ec9a2b180aa5c\"\u003e7a02697\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwk:\u003c/strong\u003e accept empty octet-sequence keys (\u003ca href=\"https://github.com/panva/jose/commit/3f871e7859c1ce51d1afcbfeff92c354b8e96dd9\"\u003e3f871e7\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwk:\u003c/strong\u003e normalize key resolution inputs (\u003ca href=\"https://github.com/panva/jose/commit/f54ee7bad8e21c975606bc5e47b352921ac0d890\"\u003ef54ee7b\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwks:\u003c/strong\u003e enforce verification key metadata (\u003ca href=\"https://github.com/panva/jose/commit/f9ba5101383154147780da7acf1aabc705f75aaf\"\u003ef9ba510\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwks:\u003c/strong\u003e order overlapping remote reloads (\u003ca href=\"https://github.com/panva/jose/commit/9a1a913983aa44d065a423692a92148b2a6a36c3\"\u003e9a1a913\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwks:\u003c/strong\u003e reject invalid remote duration values (\u003ca href=\"https://github.com/panva/jose/commit/7bdb9e56e6a74b833af582532c6fff5bc727ec1c\"\u003e7bdb9e5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwk:\u003c/strong\u003e validate ext and key_ops parameters (\u003ca href=\"https://github.com/panva/jose/commit/4d91c37fdd36241785cb172774fa017bb8854458\"\u003e4d91c37\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejws:\u003c/strong\u003e reject mixed payload encoding modes (\u003ca href=\"https://github.com/panva/jose/commit/dc69713081a55a3d6955dd1d8c2cf184905febad\"\u003edc69713\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejws:\u003c/strong\u003e validate unencoded payload strings (\u003ca href=\"https://github.com/panva/jose/commit/541f28234442c5cbfc5f843a95ccd18a721f3697\"\u003e541f282\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwt:\u003c/strong\u003e enforce explicit verification policies (\u003ca href=\"https://github.com/panva/jose/commit/b3471826b02589656eaf71843671922644cc60e2\"\u003eb347182\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwt:\u003c/strong\u003e prevent replacing protected headers (\u003ca href=\"https://github.com/panva/jose/commit/ae07d09bcbac91825e27cde9989b603af3495263\"\u003eae07d09\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwt:\u003c/strong\u003e reject invalid duration inputs (\u003ca href=\"https://github.com/panva/jose/commit/282f9aaa496e57f55417bca15e13c369b3f242fb\"\u003e282f9aa\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwt:\u003c/strong\u003e validate builder claim values (\u003ca href=\"https://github.com/panva/jose/commit/ea03f83d607fcaee6fc0778c8a4d40a2bbd75c9e\"\u003eea03f83\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/panva/jose/blob/main/CHANGELOG.md\"\u003ejose's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/panva/jose/compare/v6.2.11...v6.2.12\"\u003e6.2.12\u003c/a\u003e (2026-09-05)\u003c/h2\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eclarify and shorten public API guidance (\u003ca href=\"https://github.com/panva/jose/commit/be62530328431519950a2b6a09ccd1c7de8a38f9\"\u003ebe62530\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003esimplify JWS and JWE operation cores (\u003ca href=\"https://github.com/panva/jose/commit/92e9640290085dd37c152aeb7c4d5b22e9df96ab\"\u003e92e9640\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eavoid copying AES-GCM output (\u003ca href=\"https://github.com/panva/jose/commit/6925d43e05c7d05b0c801fda9eb1835bb8d334ef\"\u003e6925d43\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ededuplicate pending jwks key imports (\u003ca href=\"https://github.com/panva/jose/commit/bf5138b12bf9f8b7dc18f4b26ad1b7395e7e5dd6\"\u003ebf5138b\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eencode single-signature JWS input once (\u003ca href=\"https://github.com/panva/jose/commit/7bc9a3380a7436197bb5d6b377ca232094541c5c\"\u003e7bc9a33\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enormalize General JWE shared headers once (\u003ca href=\"https://github.com/panva/jose/commit/78637bd28031869df8a01cbcd82273c115860e35\"\u003e78637bd\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enormalize jwks selection metadata once (\u003ca href=\"https://github.com/panva/jose/commit/fd3ae3f06efd4760df2631f1b0a08eb4fc448efd\"\u003efd3ae3f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse native encoding for larger ASCII strings (\u003ca href=\"https://github.com/panva/jose/commit/b23a6f378b26e960900761c244a5f383af22dddc\"\u003eb23a6f3\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/panva/jose/compare/v6.2.10...v6.2.11\"\u003e6.2.11\u003c/a\u003e (2026-09-04)\u003c/h2\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003erender subpath indexes as tables (\u003ca href=\"https://github.com/panva/jose/commit/94589ee9efe6cf257a133765d753bbe8d55f6ed3\"\u003e94589ee\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eshorten API index descriptions (\u003ca href=\"https://github.com/panva/jose/commit/681482fcca7577c6a4b8df61c992f195f6e6ac1b\"\u003e681482f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003emodel JWE key management modes (\u003ca href=\"https://github.com/panva/jose/commit/e01dda65d5d272c8dd44710d0c70673c1530038e\"\u003ee01dda6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypes:\u003c/strong\u003e reduce declaration repetition (\u003ca href=\"https://github.com/panva/jose/commit/55b970fc08c9082041f40473470ee0fe0e8b0087\"\u003e55b970f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/panva/jose/compare/v6.2.9...v6.2.10\"\u003e6.2.10\u003c/a\u003e (2026-08-21)\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ejose:\u003c/strong\u003e consume serialization members once (\u003ca href=\"https://github.com/panva/jose/commit/9bee285a6bc356b495c29ae0a5e70b24e723568e\"\u003e9bee285\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejose:\u003c/strong\u003e reject empty protected and JWE AAD members (\u003ca href=\"https://github.com/panva/jose/commit/8da41453dce79967c6e3f47a787039a7f94de8fe\"\u003e8da4145\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejose:\u003c/strong\u003e validate serialized header values (\u003ca href=\"https://github.com/panva/jose/commit/b711d8fe223e3e85520d6c822d7a417cd872b718\"\u003eb711d8f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwe:\u003c/strong\u003e conceal invalid decrypted CEK lengths (\u003ca href=\"https://github.com/panva/jose/commit/41fafe035a62d85f4b313e166100004dd09b111f\"\u003e41fafe0\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwe:\u003c/strong\u003e enforce AES-GCM tag boundaries (\u003ca href=\"https://github.com/panva/jose/commit/9a5b74454bf145a106312d519efe95b8a9b53a87\"\u003e9a5b744\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwe:\u003c/strong\u003e validate explicit encryption parameters (\u003ca href=\"https://github.com/panva/jose/commit/7a02697126e40757ed9e02ae786ec9a2b180aa5c\"\u003e7a02697\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwk:\u003c/strong\u003e accept empty octet-sequence keys (\u003ca href=\"https://github.com/panva/jose/commit/3f871e7859c1ce51d1afcbfeff92c354b8e96dd9\"\u003e3f871e7\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwk:\u003c/strong\u003e normalize key resolution inputs (\u003ca href=\"https://github.com/panva/jose/commit/f54ee7bad8e21c975606bc5e47b352921ac0d890\"\u003ef54ee7b\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwks:\u003c/strong\u003e enforce verification key metadata (\u003ca href=\"https://github.com/panva/jose/commit/f9ba5101383154147780da7acf1aabc705f75aaf\"\u003ef9ba510\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwks:\u003c/strong\u003e order overlapping remote reloads (\u003ca href=\"https://github.com/panva/jose/commit/9a1a913983aa44d065a423692a92148b2a6a36c3\"\u003e9a1a913\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwks:\u003c/strong\u003e reject invalid remote duration values (\u003ca href=\"https://github.com/panva/jose/commit/7bdb9e56e6a74b833af582532c6fff5bc727ec1c\"\u003e7bdb9e5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwk:\u003c/strong\u003e validate ext and key_ops parameters (\u003ca href=\"https://github.com/panva/jose/commit/4d91c37fdd36241785cb172774fa017bb8854458\"\u003e4d91c37\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejws:\u003c/strong\u003e reject mixed payload encoding modes (\u003ca href=\"https://github.com/panva/jose/commit/dc69713081a55a3d6955dd1d8c2cf184905febad\"\u003edc69713\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejws:\u003c/strong\u003e validate unencoded payload strings (\u003ca href=\"https://github.com/panva/jose/commit/541f28234442c5cbfc5f843a95ccd18a721f3697\"\u003e541f282\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwt:\u003c/strong\u003e enforce explicit verification policies (\u003ca href=\"https://github.com/panva/jose/commit/b3471826b02589656eaf71843671922644cc60e2\"\u003eb347182\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/505a55b8f73536082367b2614cb77e927ba96ec1\"\u003e\u003ccode\u003e505a55b\u003c/code\u003e\u003c/a\u003e chore(release): 6.2.12\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/7bc9a3380a7436197bb5d6b377ca232094541c5c\"\u003e\u003ccode\u003e7bc9a33\u003c/code\u003e\u003c/a\u003e perf: encode single-signature JWS input once\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/78637bd28031869df8a01cbcd82273c115860e35\"\u003e\u003ccode\u003e78637bd\u003c/code\u003e\u003c/a\u003e perf: normalize General JWE shared headers once\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/bf5138b12bf9f8b7dc18f4b26ad1b7395e7e5dd6\"\u003e\u003ccode\u003ebf5138b\u003c/code\u003e\u003c/a\u003e perf: deduplicate pending jwks key imports\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/b23a6f378b26e960900761c244a5f383af22dddc\"\u003e\u003ccode\u003eb23a6f3\u003c/code\u003e\u003c/a\u003e perf: use native encoding for larger ASCII strings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/fd3ae3f06efd4760df2631f1b0a08eb4fc448efd\"\u003e\u003ccode\u003efd3ae3f\u003c/code\u003e\u003c/a\u003e perf: normalize jwks selection metadata once\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/6925d43e05c7d05b0c801fda9eb1835bb8d334ef\"\u003e\u003ccode\u003e6925d43\u003c/code\u003e\u003c/a\u003e perf: avoid copying AES-GCM output\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/be62530328431519950a2b6a09ccd1c7de8a38f9\"\u003e\u003ccode\u003ebe62530\u003c/code\u003e\u003c/a\u003e docs: clarify and shorten public API guidance\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/1b413121c71eed953852ac82a288f8a6b37f1343\"\u003e\u003ccode\u003e1b41312\u003c/code\u003e\u003c/a\u003e build: preserve README when generation fails\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/0b518296d441aa95e45268eee178b3ad22a78d49\"\u003e\u003ccode\u003e0b51829\u003c/code\u003e\u003c/a\u003e build: check tree-shaking for every public binding\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/panva/jose/compare/v6.2.9...v6.2.12\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `lucide-react` from 1.31.0 to 1.43.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lucide-icons/lucide/releases\"\u003elucide-react's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 1.43.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003etic-tac-toe\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4772\"\u003elucide-icons/lucide#4772\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): changed \u003ccode\u003eid-card\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4820\"\u003elucide-icons/lucide#4820\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): changed \u003ccode\u003eid-card-lanyard\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4819\"\u003elucide-icons/lucide#4819\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): delegate \u003ccode\u003ecarton\u003c/code\u003e/\u003ccode\u003ecarton-off\u003c/code\u003e from lab by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4818\"\u003elucide-icons/lucide#4818\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/lucide-icons/lucide/compare/1.42.0...1.43.0\"\u003ehttps://github.com/lucide-icons/lucide/compare/1.42.0...1.43.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 1.42.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(docs): added better contribution guide by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4746\"\u003elucide-icons/lucide#4746\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(site): fix HomeHeroIconsCard.data.ts by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4805\"\u003elucide-icons/lucide#4805\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): deprecated swiss franc icons by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4799\"\u003elucide-icons/lucide#4799\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): add gap-horizontal and gap-vertical by \u003ca href=\"https://github.com/samuelalake\"\u003e\u003ccode\u003e@​samuelalake\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4544\"\u003elucide-icons/lucide#4544\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003etrash-off\u003c/code\u003e icon by \u003ca href=\"https://github.com/lx3133584\"\u003e\u003ccode\u003e@​lx3133584\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4788\"\u003elucide-icons/lucide#4788\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003ecircle-dashed-check\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4796\"\u003elucide-icons/lucide#4796\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003eequal-approximately-not\u003c/code\u003e icon by \u003ca href=\"https://github.com/ryck\"\u003e\u003ccode\u003e@​ryck\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4802\"\u003elucide-icons/lucide#4802\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added dome icons by \u003ca href=\"https://github.com/swastik7805\"\u003e\u003ccode\u003e@​swastik7805\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4261\"\u003elucide-icons/lucide#4261\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(lucide-react): Add Lucide React integration tests by \u003ca href=\"https://github.com/ericfennis\"\u003e\u003ccode\u003e@​ericfennis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4804\"\u003elucide-icons/lucide#4804\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(packages): extract icon build logic into \u003ccode\u003e@lucide/shared\u003c/code\u003e by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4409\"\u003elucide-icons/lucide#4409\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): changed \u003ccode\u003ecomputer\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4607\"\u003elucide-icons/lucide#4607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(dependencies): Update dependencies by \u003ca href=\"https://github.com/ericfennis\"\u003e\u003ccode\u003e@​ericfennis\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4806\"\u003elucide-icons/lucide#4806\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): changed \u003ccode\u003etable-2\u003c/code\u003e icon by \u003ca href=\"https://github.com/jguddas\"\u003e\u003ccode\u003e@​jguddas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4810\"\u003elucide-icons/lucide#4810\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003euser-group\u003c/code\u003e icons by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4782\"\u003elucide-icons/lucide#4782\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lx3133584\"\u003e\u003ccode\u003e@​lx3133584\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4788\"\u003elucide-icons/lucide#4788\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ryck\"\u003e\u003ccode\u003e@​ryck\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4802\"\u003elucide-icons/lucide#4802\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/lucide-icons/lucide/compare/1.41.0...1.42.0\"\u003ehttps://github.com/lucide-icons/lucide/compare/1.41.0...1.42.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 1.41.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(icons): Add new icons \u003ccode\u003egerm\u003c/code\u003e and \u003ccode\u003egerm-off\u003c/code\u003e by \u003ca href=\"https://github.com/rrod497\"\u003e\u003ccode\u003e@​rrod497\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4056\"\u003elucide-icons/lucide#4056\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003edoor-stairwell\u003c/code\u003e icon \u0026amp; updated \u003ccode\u003edoor-*\u003c/code\u003e icons by \u003ca href=\"https://github.com/jguddas\"\u003e\u003ccode\u003e@​jguddas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/3554\"\u003elucide-icons/lucide#3554\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003ecredit-card-reader\u003c/code\u003e icon by \u003ca href=\"https://github.com/jguddas\"\u003e\u003ccode\u003e@​jguddas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4616\"\u003elucide-icons/lucide#4616\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added 'engine' icon by \u003ca href=\"https://github.com/benhaube\"\u003e\u003ccode\u003e@​benhaube\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4598\"\u003elucide-icons/lucide#4598\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): fixed \u003ccode\u003egerm\u003c/code\u003e \u0026amp; \u003ccode\u003egerm-off\u003c/code\u003e by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4789\"\u003elucide-icons/lucide#4789\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump the vue-deps group with 2 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4771\"\u003elucide-icons/lucide#4771\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003evirus\u003c/code\u003e/\u003ccode\u003evirus-off\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4765\"\u003elucide-icons/lucide#4765\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(copilot-reviews): Improve use-cases description. by \u003ca href=\"https://github.com/ericfennis\"\u003e\u003ccode\u003e@​ericfennis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4558\"\u003elucide-icons/lucide#4558\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): add \u003ccode\u003ecan-soda\u003c/code\u003e icon by \u003ca href=\"https://github.com/jaynewey\"\u003e\u003ccode\u003e@​jaynewey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4718\"\u003elucide-icons/lucide#4718\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003esquare-alert\u003c/code\u003e Icon by \u003ca href=\"https://github.com/viralcodex\"\u003e\u003ccode\u003e@​viralcodex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/3687\"\u003elucide-icons/lucide#3687\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(lab): Add label for lab icons by \u003ca href=\"https://github.com/ericfennis\"\u003e\u003ccode\u003e@​ericfennis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4793\"\u003elucide-icons/lucide#4793\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): changed \u003ccode\u003elab/bottle-toothbrush-comb\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4756\"\u003elucide-icons/lucide#4756\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(\u003ccode\u003e@​lucide/lab\u003c/code\u003e): Create automatic release flow for \u003ccode\u003e@lucide/lab\u003c/code\u003e by \u003ca href=\"https://github.com/ericfennis\"\u003e\u003ccode\u003e@​ericfennis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4792\"\u003elucide-icons/lucide#4792\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): removed \u003ccode\u003etrash\u003c/code\u003e icon in favour of \u003ccode\u003etrash-2\u003c/code\u003e by \u003ca href=\"https://github.com/jguddas\"\u003e\u003ccode\u003e@​jguddas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/3141\"\u003elucide-icons/lucide#3141\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): changed \u003ccode\u003eleaf\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4801\"\u003elucide-icons/lucide#4801\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lucide-icons/lucide/commit/94e4cb9d9db5907053ebf3636a97c45529cf776b\"\u003e\u003ccode\u003e94e4cb9\u003c/code\u003e\u003c/a\u003e chore(dependencies): Update dependencies (\u003ca href=\"https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4806\"\u003e#4806\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lucide-icons/lucide/commit/99d25bdee231922e73e19525f57a585d1682fab2\"\u003e\u003ccode\u003e99d25bd\u003c/code\u003e\u003c/a\u003e feat(packages): extract icon build logic into \u003ccode\u003e@lucide/shared\u003c/code\u003e (\u003ca href=\"https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4409\"\u003e#4409\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lucide-icons/lucide/commit/75b55160aa9edd7095dfed1a6e3d88e66fb2b153\"\u003e\u003ccode\u003e75b5516\u003c/code\u003e\u003c/a\u003e chore(dev): upgrade ESLint to latest compatible stack (v10) (\u003ca href=\"https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4378\"\u003e#4378\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/lucide-icons/lucide/commits/1.43.0/packages/lucide-react\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `mermaid` from 11.16.1 to 11.17.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mermaid-js/mermaid/releases\"\u003emermaid's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003emermaid@11.17.2\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/8125\"\u003e#8125\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/178d7c79fcbafcf0662b822ec34ed989372ee5c2\"\u003e\u003ccode\u003e178d7c7\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/knsv-bot\"\u003e\u003ccode\u003e@​knsv-bot\u003c/code\u003e\u003c/a\u003e! - fix: restore the \u003ccode\u003eedgePaths\u003c/code\u003e class on the edge group in rendered SVG, and point the flowchart, block and user journey stylesheets at it\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003emermaid@11.17.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/8092\"\u003e#8092\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/31ce60a596746c76dc932ab540d910a6c7fff8be\"\u003e\u003ccode\u003e31ce60a\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/pbrolin47\"\u003e\u003ccode\u003e@​pbrolin47\u003c/code\u003e\u003c/a\u003e! - fix(c4): wrap element labels to \u003ccode\u003ec4.width\u003c/code\u003e again\u003c/p\u003e\n\u003cp\u003eC4 element labels (\u003ccode\u003eSystem\u003c/code\u003e, \u003ccode\u003eContainer\u003c/code\u003e, \u003ccode\u003eComponent\u003c/code\u003e, \u003ccode\u003ePerson\u003c/code\u003e and their \u003ccode\u003e_Ext\u003c/code\u003e variants) stopped wrapping in 11.17.0, so long descriptions rendered on one unbroken line and the shape grew sideways well past the configured \u003ccode\u003ec4.width\u003c/code\u003e. The unified-shapes label helper gated wrapping on the root-level \u003ccode\u003ewrap\u003c/code\u003e option, which has no schema default and is therefore \u003ccode\u003eundefined\u003c/code\u003e; it now gates on \u003ccode\u003ec4.wrap\u003c/code\u003e (default \u003ccode\u003etrue\u003c/code\u003e), which is what the legacy renderer used.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/8088\"\u003e#8088\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/c66200bc2302006c908f77819c584109f50c06e7\"\u003e\u003ccode\u003ec66200b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ashishjain0512\"\u003e\u003ccode\u003e@​ashishjain0512\u003c/code\u003e\u003c/a\u003e! - fix: neo-look arrowheads and crow's-foot markers no longer fall back to default theme colours/stroke widths on the first render with \u003ccode\u003elayout: elk\u003c/code\u003e. State diagram arrowheads stayed dark on dark themes, and ER / requirement markers were drawn at the default stroke width, because markers were created from the layout package's own bundled copy of mermaid, whose config had not been initialized yet.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/8079\"\u003e#8079\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/281cd7b0705a7cdf4295bfd5e3171647dc809dfb\"\u003e\u003ccode\u003e281cd7b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ashishjain0512\"\u003e\u003ccode\u003e@​ashishjain0512\u003c/code\u003e\u003c/a\u003e! - fix(class): class diagram relation markers (composition, aggregation, extension, dependency, lollipop) no longer scale with the edge stroke width, so they stay outside the class box boundary in themes that set \u003ccode\u003estrokeWidth: 2\u003c/code\u003e (\u003ccode\u003eredux\u003c/code\u003e, \u003ccode\u003eredux-dark\u003c/code\u003e, \u003ccode\u003eredux-color\u003c/code\u003e, \u003ccode\u003eredux-dark-color\u003c/code\u003e, \u003ccode\u003eneo\u003c/code\u003e, \u003ccode\u003eneo-dark\u003c/code\u003e) with the default \u003ccode\u003eclassic\u003c/code\u003e look.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003emermaid@11.17.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/7842\"\u003e#7842\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/3670b4e2d99b27945240dd3fe71da9175fddcaec\"\u003e\u003ccode\u003e3670b4e\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/filipsajdak\"\u003e\u003ccode\u003e@​filipsajdak\u003c/code\u003e\u003c/a\u003e! - feat(c4): render C4 elements through the unified shape system, using the new person shape\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/7812\"\u003e#7812\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/cdfc0ea65f47bc8f9605a2a646ed87c25a692216\"\u003e\u003ccode\u003ecdfc0ea\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/knsv-bot\"\u003e\u003ccode\u003e@​knsv-bot\u003c/code\u003e\u003c/a\u003e! - feat(class): route \u003ccode\u003eclassDiagram\u003c/code\u003e to the unified (v2) renderer by default\u003c/p\u003e\n\u003cp\u003eSet \u003ccode\u003eclass: { defaultRenderer: 'dagre-d3' }\u003c/code\u003e in the config to restore the legacy renderer.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/7785\"\u003e#7785\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/c45cde9582ede4add658f62b771ba2a7efadde83\"\u003e\u003ccode\u003ec45cde9\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/knsv-bot\"\u003e\u003ccode\u003e@​knsv-bot\u003c/code\u003e\u003c/a\u003e! - feat(flowchart): add collapsible flowchart subgraphs via \u003ccode\u003esubgraphId@{ view: collapsed }\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/7828\"\u003e#7828\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/8eb3afc08c64e0f5d2b2447daac417250a202c13\"\u003e\u003ccode\u003e8eb3afc\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/knsv-bot\"\u003e\u003ccode\u003e@​knsv-bot\u003c/code\u003e\u003c/a\u003e! - feat(elk): add \u003ccode\u003eelk.keepEntryNodeOnTop\u003c/code\u003e config option to keep a recursive flow's entry node on top\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/7803\"\u003e#7803\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/74e44ebf86d293cee1f2314c8b8a163284ea3911\"\u003e\u003ccode\u003e74e44eb\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/knsv-bot\"\u003e\u003ccode\u003e@​knsv-bot\u003c/code\u003e\u003c/a\u003e! - feat(elk): add \u003ccode\u003eelk.nodePlacementAlignment\u003c/code\u003e config option\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/7792\"\u003e#7792\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/ea55b31bcfb36cfdfbc31a531058ee8c4ee53a4f\"\u003e\u003ccode\u003eea55b31\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/RodrigojndSantos\"\u003e\u003ccode\u003e@​RodrigojndSantos\u003c/code\u003e\u003c/a\u003e! - feat(er): add subgraph support to ER diagrams.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/7970\"\u003e#7970\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/a2c0fb6cdf8073b8feb10595ea3cccff0237049b\"\u003e\u003ccode\u003ea2c0fb6\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/filipsajdak\"\u003e\u003ccode\u003e@​filipsajdak\u003c/code\u003e\u003c/a\u003e! - feat(flowchart): add \u003ccode\u003efolder\u003c/code\u003e, \u003ccode\u003ebucket\u003c/code\u003e, \u003ccode\u003econsole\u003c/code\u003e (terminal window) and \u003ccode\u003ebrowser\u003c/code\u003e shapes\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/7842\"\u003e#7842\u003c/a\u003e \u003ca href=\"htt...\n\n_Description has been truncated_","html_url":"https://github.com/openclaw/clawhub/pull/3686","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/openclaw%2Fclawhub/issues/3686","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/3686/packages"},{"uuid":"5425590721","node_id":"PR_kwDOSI3MHs8AAAABDKHtvw","number":1197,"state":"open","title":"build(deps): Bump undici from 8.10.0 to 8.10.2 in the safe-updates group","user":"dependabot[bot]","labels":["documentation","dependencies","size/S"],"assignees":[],"locked":false,"comments_count":12,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T14:40:22.000Z","updated_at":"2026-09-11T14:45:33.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): Bump","packages":[{"name":"undici","old_version":"8.10.0","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"}],"path":"the safe-updates group","ecosystem":"npm"},"body":"Bumps the safe-updates group with 1 update: [undici](https://github.com/nodejs/undici).\n\nUpdates `undici` from 8.10.0 to 8.10.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm\"\u003eGHSA-vp8m-p9jh-q5pm\u003c/a\u003e: cache and deduplication interceptors could use caller-controlled request metadata instead of the authoritative dispatcher origin, enabling cross-origin cache poisoning and data disclosure. Undici now derives interceptor identities from the dispatcher origin and bypasses origin-dependent interceptors when no authoritative origin exists. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/caf6194d3dae989b731ed87ab85f182befe5eb80\"\u003ecaf6194d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e8f5868fb\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e66e12816\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6\"\u003e4411a238\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/662d0ea671fe64139e79533c913fce412765e1d7\"\u003e662d0ea6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003ecb75bbb3\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e7aac7f12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003ee905b5b8\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e2be07bf9\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e6d583124\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e0160a719\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps-dev): bump undici from 6.27.0 to 6.28.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5653\"\u003enodejs/undici#5653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump jest from 30.4.2 to 30.5.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5750\"\u003enodejs/undici#5750\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/analyze from 4.37.3 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5752\"\u003enodejs/undici#5752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5754\"\u003enodejs/undici#5754\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(h2): cover stream reset with NGHTTP2_INTERNAL_ERROR by \u003ca href=\"https://github.com/zeexzeex\"\u003e\u003ccode\u003e@​zeexzeex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5725\"\u003enodejs/undici#5725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): reject invalid resumed responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5724\"\u003enodejs/undici#5724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: make stale-while-revalidate cache update test deterministic by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5722\"\u003enodejs/undici#5722\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid unbounded recursion in Set-Cookie attribute parser by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5757\"\u003enodejs/undici#5757\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: honor SOCKS5 connection timeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5733\"\u003enodejs/undici#5733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(eventsource): validate Last-Event-ID on reconnect by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5746\"\u003enodejs/undici#5746\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid duplicate release attempts by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5745\"\u003enodejs/undici#5745\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(cache): refetch when 304 adds vary fields by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5732\"\u003enodejs/undici#5732\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etypes: expose PendingInterceptor and PendingInterceptorsFormatter on the MockAgent namespace by \u003ca href=\"https://github.com/RaphaelFakhri\"\u003e\u003ccode\u003e@​RaphaelFakhri\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5721\"\u003enodejs/undici#5721\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(codeql): align CodeQL action versions to v4.37.9 by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5759\"\u003enodejs/undici#5759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5760\"\u003enodejs/undici#5760\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(proxy-agent): guard Proxy-Authorization in iterable header containers by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5758\"\u003enodejs/undici#5758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: name the parameters these two blocks describe by \u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): fail the connection on a non-200 h2 extended CONNECT response by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(node-fetch): re-enable the set-cookie header combining test by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5730\"\u003enodejs/undici#5730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward rawHeaders writes through RetryController by \u003ca href=\"https://github.com/official-burak\"\u003e\u003ccode\u003e@​official-burak\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5727\"\u003enodejs/undici#5727\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5738\"\u003enodejs/undici#5738\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/5e541e0b9df7563e5766bbd469fbfe383d9ae6ca\"\u003e\u003ccode\u003e5e541e0\u003c/code\u003e\u003c/a\u003e Bumped v8.10.2 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5771\"\u003e#5771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/eb04cc39954e63e9b46bdf824e6efad9fff2e7b5\"\u003e\u003ccode\u003eeb04cc3\u003c/code\u003e\u003c/a\u003e fix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5738\"\u003e#5738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003e\u003ccode\u003ee905b5b\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e\u003ccode\u003e0160a71\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e\u003ccode\u003e66e1281\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e\u003ccode\u003e7aac7f1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003e\u003ccode\u003ecb75bbb\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e\u003ccode\u003e6d58312\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e\u003ccode\u003e8f5868f\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e\u003ccode\u003e2be07bf\u003c/code\u003e\u003c/a\u003e fix(cache): reject unsafe method response caching\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v8.10.0...v8.10.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=8.10.0\u0026new-version=8.10.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e\n\n\u003c!-- This is an auto-generated description by cubic. --\u003e\n---\n## Summary by cubic\nBumps `undici` from 8.10.0 to 8.10.2 in `dependencies` and `overrides` to address multiple security advisories, and updates the CVE remediation report accordingly. Patch-level update with no expected behavior changes.\n\n\u003csup\u003eWritten for commit 351ea311ed468890814931406e418f68c21b0729. Summary will update on new commits.\u003c/sup\u003e\n\n\u003ca href=\"https://cubic.dev/pr/Trancendos/Tranc3/pull/1197?utm_source=github\" target=\"_blank\" rel=\"noopener noreferrer\" data-no-image-dialog=\"true\"\u003e\u003cpicture\u003e\u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-light.svg\"\u003e\u003cimg alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003c/picture\u003e\u003c/a\u003e\n\n\u003c!-- End of auto-generated description by cubic. --\u003e\n\n","html_url":"https://github.com/Trancendos/Tranc3/pull/1197","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Trancendos%2FTranc3/issues/1197","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1197/packages"},{"uuid":"5425007069","node_id":"PR_kwDOQELycM8AAAABDJpvbg","number":199,"state":"open","title":"chore(deps): bump the npm_and_yarn group across 1 directory with 20 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T13:43:02.000Z","updated_at":"2026-09-11T13:44:47.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":20,"packages":[{"name":"next","old_version":"16.2.12","new_version":"16.3.3","repository_url":"https://github.com/vercel/next.js"},{"name":"sanitize-html","old_version":"2.17.0","new_version":"2.17.7","repository_url":"https://github.com/apostrophecms/apostrophe"},{"name":"fast-xml-parser","old_version":"5.9.3","new_version":"5.11.1","repository_url":"https://github.com/NaturalIntelligence/fast-xml-parser"},{"name":"@humanfs/node","old_version":"0.16.7","new_version":"0.16.8","repository_url":"https://github.com/humanwhocodes/humanfs"},{"name":"brace-expansion","old_version":"1.1.14","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"@tiptap/core","old_version":"3.13.0","new_version":"3.31.3","repository_url":"https://github.com/ueberdosis/tiptap"},{"name":"adm-zip","old_version":"0.5.17","new_version":"0.6.1","repository_url":"https://github.com/cthackers/adm-zip"},{"name":"baseline-browser-mapping","old_version":"2.10.43","new_version":"2.11.22","repository_url":"https://github.com/web-platform-dx/baseline-browser-mapping"},{"name":"browserslist","old_version":"4.28.1","new_version":"4.28.9","repository_url":"https://github.com/browserslist/browserslist"},{"name":"dompurify","old_version":"3.4.12","new_version":"3.4.15","repository_url":"https://github.com/cure53/DOMPurify"},{"name":"fast-uri","old_version":"3.1.3","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"hono","old_version":"4.12.30","new_version":"4.13.7","repository_url":"https://github.com/honojs/hono"},{"name":"ip-address","old_version":"10.2.0","new_version":"10.7.0","repository_url":"https://github.com/beaugunderson/ip-address"},{"name":"js-yaml","old_version":"5.2.1","new_version":"5.4.1","repository_url":"https://github.com/nodeca/js-yaml"},{"name":"qs","old_version":"6.15.3","new_version":"6.16.0","repository_url":"https://github.com/ljharb/qs"},{"name":"smol-toml","old_version":"1.7.0","new_version":"1.8.0","repository_url":"https://github.com/squirrelchat/smol-toml"},{"name":"undici","old_version":"7.28.0","new_version":"7.29.1","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 17 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [next](https://github.com/vercel/next.js) | `16.2.12` | `16.3.3` |\n| [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html) | `2.17.0` | `2.17.7` |\n| [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) | `5.9.3` | `5.11.1` |\n| [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node) | `0.16.7` | `0.16.8` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.14` | `1.1.18` |\n| [@tiptap/core](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core) | `3.13.0` | `3.31.3` |\n| [adm-zip](https://github.com/cthackers/adm-zip) | `0.5.17` | `0.6.1` |\n| [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) | `2.10.43` | `2.11.22` |\n| [browserslist](https://github.com/browserslist/browserslist) | `4.28.1` | `4.28.9` |\n| [dompurify](https://github.com/cure53/DOMPurify) | `3.4.12` | `3.4.15` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.3` | `3.1.7` |\n| [hono](https://github.com/honojs/hono) | `4.12.30` | `4.13.7` |\n| [ip-address](https://github.com/beaugunderson/ip-address) | `10.2.0` | `10.7.0` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `5.2.1` | `5.4.1` |\n| [qs](https://github.com/ljharb/qs) | `6.15.3` | `6.16.0` |\n| [smol-toml](https://github.com/squirrelchat/smol-toml) | `1.7.0` | `1.8.0` |\n| [undici](https://github.com/nodejs/undici) | `7.28.0` | `7.29.1` |\n\n\nUpdates `next` from 16.2.12 to 16.3.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003enext's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.3\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eCritical:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36\"\u003eUnauthenticated Remote Code Execution on windows-hosted servers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4\"\u003eUnauthenticated Remote Code Execution in Image Optimization API when AVIF files are used\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.2\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Scope app-entry export validation to files inside the app directory (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97357\"\u003e#97357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[backport] Fix catch-all index page being served for every other slug (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97416\"\u003e#97416\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: don't trace embedded WASM loader helpers (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97353\"\u003e#97353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97463\"\u003e#97463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: retain conditions when replacing resolve request keys (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97453\"\u003e#97453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Fix Turbopack worker chunk loading with asset prefix (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97419\"\u003e#97419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97603\"\u003e#97603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/lubieowoce\"\u003e\u003ccode\u003e@​lubieowoce\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[16.x] Turbopack: don't strip async-module runtime from shared runtime chunks by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96653\"\u003evercel/next.js#96653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] [turbopack] Add \u003ccode\u003eturbopack_ecmascript\u003c/code\u003e and \u003ccode\u003eturbopack_wasm\u003c/code\u003e's embeded FS to \u003ccode\u003einternal_assets_conditions\u003c/code\u003e by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96655\"\u003evercel/next.js#96655\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] [turbopack] Collapse nested promises in the analyzer by \u003ca href=\"https://github.com/sampoder\"\u003e\u003ccode\u003e@​sampoder\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96675\"\u003evercel/next.js#96675\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] fix(next/image): preserve image response after optimization by \u003ca href=\"https://github.com/styfle\"\u003e\u003ccode\u003e@​styfle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96733\"\u003evercel/next.js#96733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.3.x] Default deploy e2e tests to the repo next version by \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96900\"\u003evercel/next.js#96900\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Bump \u003ccode\u003e@​swc/helpers\u003c/code\u003e by \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96885\"\u003evercel/next.js#96885\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [turbopack] Raise registration calls in hoisted modules to the top by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97308\"\u003evercel/next.js#97308\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Fix missing styled-jsx styles in Pages Router SSR on adapter builds by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97302\"\u003evercel/next.js#97302\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [turbopack] Fix HMR for dynamic imports evaluated from layouts by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97317\"\u003evercel/next.js#97317\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Restore the live \u003ccode\u003eheaders()\u003c/code\u003e view of the incoming request by \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97311\"\u003evercel/next.js#97311\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Allow literal exports in \u003ccode\u003e'use cache'\u003c/code\u003e files by \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97312\"\u003evercel/next.js#97312\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Keep the dev validation worker alive across HMR updates by \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97315\"\u003evercel/next.js#97315\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Discard only cache entries that predate a tag revalidation, and reuse completed entries by \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97314\"\u003evercel/next.js#97314\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Encode the cache item name built by \u003ccode\u003eunstable_cache\u003c/code\u003e by \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97313\"\u003evercel/next.js#97313\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.3] [ci] Use OIDC tokens to read private preview builds by \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97258\"\u003evercel/next.js#97258\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [test] Compile the middleware redirect routes up front in dev by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97328\"\u003evercel/next.js#97328\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Fix Nav Inspector request loop on repeat captures by \u003ca href=\"https://github.com/acdlite\"\u003e\u003ccode\u003e@​acdlite\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97326\"\u003evercel/next.js#97326\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Fix: Optimistic routing bugs leading to repeated prefetch loops by \u003ca href=\"https://github.com/acdlite\"\u003e\u003ccode\u003e@​acdlite\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97325\"\u003evercel/next.js#97325\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Retain fewer stale cache versions and use a TTL, plus the mtime fallback by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97304\"\u003evercel/next.js#97304\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Revert i18n localization change for dynamic Pages API routes (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/94905\"\u003e#94905\u003c/a\u003e) by \u003ca href=\"https://github.com/gaojude\"\u003e\u003ccode\u003e@​gaojude\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97330\"\u003evercel/next.js#97330\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/vercel/next.js/compare/v16.3.0...v16.3.1\"\u003ehttps://github.com/vercel/next.js/compare/v16.3.0...v16.3.1\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/a9a1cb7859f178f830ad3773b303130c21b19586\"\u003e\u003ccode\u003ea9a1cb7\u003c/code\u003e\u003c/a\u003e v16.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/968b9fcb26bdeb8e0a861a9df05361474666d51b\"\u003e\u003ccode\u003e968b9fc\u003c/code\u003e\u003c/a\u003e [16.3.x] Fix ISR misses with backslashes in segments when deployed on Windows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/3a15b4ac6ac8e70b1a9b18ecc18e8434462899b3\"\u003e\u003ccode\u003e3a15b4a\u003c/code\u003e\u003c/a\u003e [16.3.x] [next/image]: disable avif image optimization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/7378b51ea05a6745d3676bee00cb4c63aac3dd16\"\u003e\u003ccode\u003e7378b51\u003c/code\u003e\u003c/a\u003e Backport/docs fixes 16.3 (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97649\"\u003e#97649\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/528c1cdfc36bdf8051992febdafe45f17f042010\"\u003e\u003ccode\u003e528c1cd\u003c/code\u003e\u003c/a\u003e [16.3.x] Stop generating error codes (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97780\"\u003e#97780\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/d0ac8828c2fe6026dd7d700488bfd8289711fde6\"\u003e\u003ccode\u003ed0ac882\u003c/code\u003e\u003c/a\u003e v16.3.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/81deb92859e26f8435cc0f37e244573c6638a955\"\u003e\u003ccode\u003e81deb92\u003c/code\u003e\u003c/a\u003e [16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/cd714d9fceae7aec9d467598792b0c844f710607\"\u003e\u003ccode\u003ecd714d9\u003c/code\u003e\u003c/a\u003e [16.3.x] Fix Turbopack worker chunk loading with asset prefix (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97419\"\u003e#97419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/5ac2327e62784eacdf6ab7db8629fd05c5f5fcdf\"\u003e\u003ccode\u003e5ac2327\u003c/code\u003e\u003c/a\u003e [16.3] Turbopack: retain conditions when replacing resolve request keys (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97453\"\u003e#97453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/0ccb3e7f5d6b55c5c9e215248b264a428aee7dcb\"\u003e\u003ccode\u003e0ccb3e7\u003c/code\u003e\u003c/a\u003e [16.3] Turbopack: don't trace embedded WASM loader helpers (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97353\"\u003e#97353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97463\"\u003e#97463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/compare/v16.2.12...v16.3.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `sanitize-html` from 2.17.0 to 2.17.7\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apostrophecms/apostrophe/blob/main/packages/sanitize-html/CHANGELOG.md\"\u003esanitize-html's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.17.7 (2026-08-13)\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an XSS / URL scheme policy bypass affecting configurations that allow the SVG animation elements (\u003ccode\u003eanimate\u003c/code\u003e, \u003ccode\u003eanimateColor\u003c/code\u003e, \u003ccode\u003eanimateMotion\u003c/code\u003e, \u003ccode\u003eanimateTransform\u003c/code\u003e or \u003ccode\u003eset\u003c/code\u003e) together with \u003ccode\u003eattributeName\u003c/code\u003e and one of the animation value attributes. The default configuration was not affected, as these elements are not in the default \u003ccode\u003eallowedTags\u003c/code\u003e. \u003ccode\u003eapostrophecms\u003c/code\u003e was not affected. Thanks to \u003ca href=\"https://github.com/koyokr\"\u003ekoyokr\u003c/a\u003e for responsibly disclosing the vulnerability (GHSA-g8qq-57p8-ggw5).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.17.6 (2026-07-10)\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAllow transformTags to emit text when textFilter is set, even if the tag is initially empty. This is consistent with the documentation. Thanks to \u003ca href=\"https://github.com/spokodev\"\u003espokodev\u003c/a\u003e for the fix.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an XSS/allowlist bypass in which the contents of a raw-text element (\u003ccode\u003etextarea\u003c/code\u003e or \u003ccode\u003exmp\u003c/code\u003e) nested inside an \u003ccode\u003esvg\u003c/code\u003e or \u003ccode\u003emath\u003c/code\u003e root were re-emitted without HTML-escaping. \u003ccode\u003esanitize-html\u003c/code\u003e treated that content as inert raw text because \u003ccode\u003ehtmlparser2\u003c/code\u003e 10.x classified raw-text elements by tag name and ignored the namespace, but a real HTML5 parser treats \u003ccode\u003etextarea\u003c/code\u003e/\u003ccode\u003exmp\u003c/code\u003e as ordinary foreign elements inside SVG/MathML and re-parses their contents as live markup. As a result, markup and event-handler attributes that the allowlist never permitted (for example \u003ccode\u003e\u0026lt;svg\u0026gt;\u0026lt;textarea\u0026gt;\u0026lt;img src=x onerror=alert(1)\u0026gt;\u003c/code\u003e) could survive sanitization and execute in the browser. This is now fixed on two fronts: \u003ccode\u003ehtmlparser2\u003c/code\u003e was upgraded to 12.x, which is namespace-aware and parses \u003ccode\u003etextarea\u003c/code\u003e/\u003ccode\u003exmp\u003c/code\u003e inside SVG/MathML as ordinary elements, so their non-allowlisted children (such as the injected \u003ccode\u003eimg\u003c/code\u003e) are dropped by the allowlist instead of being preserved as raw text; and any raw-text content \u003ccode\u003esanitize-html\u003c/code\u003e still emits for these tags (at HTML integration points such as \u003ccode\u003eforeignObject\u003c/code\u003e/\u003ccode\u003emtext\u003c/code\u003e, or outside foreign content) is always HTML-escaped. The default configuration is not affected; the precondition is an \u003ccode\u003eallowedTags\u003c/code\u003e that includes \u003ccode\u003esvg\u003c/code\u003e or \u003ccode\u003emath\u003c/code\u003e together with \u003ccode\u003etextarea\u003c/code\u003e or \u003ccode\u003exmp\u003c/code\u003e. Thanks to \u003ca href=\"https://github.com/khoadb175\"\u003ekhoadb175\u003c/a\u003e for responsibly disclosing the vulnerability.\u003c/li\u003e\n\u003cli\u003eFixed a mutation-XSS / \u003ccode\u003eallowedTags\u003c/code\u003e bypass affecting configurations that allow the \u003ccode\u003etextarea\u003c/code\u003e or \u003ccode\u003exmp\u003c/code\u003e raw-text tags. \u003ccode\u003ehtmlparser2\u003c/code\u003e 10.x did not recognize an end tag with a trailing solidus (e.g. \u003ccode\u003e\u0026lt;/textarea/\u0026gt;\u003c/code\u003e) as closing the element, so it kept the following markup as raw text, but a spec-compliant browser treats \u003ccode\u003e\u0026lt;/textarea/\u0026gt;\u003c/code\u003e as a valid close and parses that markup as a live element. Because raw-text content was re-emitted without escaping, a payload such as \u003ccode\u003e\u0026lt;textarea\u0026gt;\u0026lt;/textarea/\u0026gt;\u0026lt;img src=x onerror=...\u0026gt;\u003c/code\u003e could smuggle non-allowlisted, executable markup through the sanitizer. The default configuration was not affected. This is now defended at two layers: \u003ccode\u003ehtmlparser2\u003c/code\u003e was upgraded to 12.x, whose tokenizer closes these end tags correctly, and the raw text sanitize-html emits for these tags is always escaped so no \u003ccode\u003e\u0026lt;\u003c/code\u003e can reopen a tag when the output is re-parsed (\u003ccode\u003etextarea\u003c/code\u003e, an RCDATA element whose entities \u003ccode\u003ehtmlparser2\u003c/code\u003e decodes, is escaped like normal text, while \u003ccode\u003exmp\u003c/code\u003e, a raw-text element, has only its angle brackets escaped to avoid double-encoding already-encoded entities). Because \u003ccode\u003ehtmlparser2\u003c/code\u003e is ESM-only from version 11 onward, \u003ccode\u003esanitize-html\u003c/code\u003e now requires Node.js \u003ccode\u003e\u0026gt;=22.12.0\u003c/code\u003e (the first 22.x release in which \u003ccode\u003erequire()\u003c/code\u003e of an ES module is available unflagged). Thanks to \u003ca href=\"https://github.com/bibu123456\"\u003ebibu123456\u003c/a\u003e for reporting the vulnerability and \u003ca href=\"https://github.com/Kayiz-PT\"\u003eKayiz-PT\u003c/a\u003e for coordinating the disclosure (GHSA-jxwj-j7wr-gfrw).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.17.5 (2026-06-10)\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded a number of new attributes to be protected against unsafe URLs, e.g. \u003ccode\u003ejavascript:\u003c/code\u003e and similar. None of these are used in the default configuration of \u003ccode\u003esanitize-html\u003c/code\u003e or \u003ccode\u003eapostrophe\u003c/code\u003e or likely to be used there, and some attributes, like an \u003ccode\u003eaction\u003c/code\u003e for a \u003ccode\u003eform\u003c/code\u003e, are inherently unsafe to allow if XSS protection is your goal. Nevertheless it makes sense to block certain URL types where they are not appropriate. Some attributes are not supported at all by modern browsers but are included for completeness. Thanks to \u003ca href=\"https://github.com/crattack\"\u003ecrattack\u003c/a\u003e for reporting the vulnerability.\u003c/li\u003e\n\u003cli\u003eAddress a potential vulnerability when nonTextTags is configured in a nonstandard way. While it is never a good idea to remove known non-text tags from the standard list e.g. script, styles, etc., this change ensures that doing so does not result in nested tags being passed through without sanitization when they are not expressly allowed. (ApostropheCMS would never trigger this situation.) Thanks to \u003ca href=\"https://github.com/Dipanshusinghh\"\u003eDipanshu singh\u003c/a\u003e for pointing out the issue and contributing the fix.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.17.4\u003c/h2\u003e\n\u003ch3\u003eChanges\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003esanitize-html\u003c/code\u003e and \u003ccode\u003elaunder\u003c/code\u003e now share a single implementation of \u003ccode\u003enaughtyHref\u003c/code\u003e, based on that which previously existed in \u003ccode\u003esanitize-html\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity vulnerability: the xmp tag could be used to pass forbidden markup through sanitize-html, even when xmp itself is not explicitly allowed All users of sanitize-html should update immediately. Thanks to \u003ca href=\"https://github.com/sushi-gif\"\u003eVincenzo Turturro\u003c/a\u003e for reporting the vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.17.3 (2026-04-15)\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix vulnerability introduced in version 2.17.2 that allowed XSS attacks if the developer chose to permit \u003ccode\u003eoption\u003c/code\u003e tags. There was no vulnerability when not explicitly allowing \u003ccode\u003eoption\u003c/code\u003e tags.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.17.2 (2026-03-19)\u003c/h2\u003e\n\u003ch3\u003eChanges\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003ehtmlparser2\u003c/code\u003e from 8.x to 10.1.0. This improves security by correctly decoding zero-padded numeric character references (e.g., \u003ccode\u003e\u0026amp;[#0000001](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html/issues/0000001)\u003c/code\u003e) that previously bypassed \u003ccode\u003ejavascript:\u003c/code\u003e URL detection. Also fixes double-encoding of entities inside raw text elements like \u003ccode\u003etextarea\u003c/code\u003e and \u003ccode\u003eoption\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.17.1 (2026-02-18)\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apostrophecms/apostrophe/commit/72f4531e7b491738049eec423d0c1c2342828e5f\"\u003e\u003ccode\u003e72f4531\u003c/code\u003e\u003c/a\u003e Latest reconciliation q2 m3 2026 (\u003ca href=\"https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html/issues/5555\"\u003e#5555\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apostrophecms/apostrophe/commit/207846a3aec6b1914a2b9f4dc36d45daf6a4afb9\"\u003e\u003ccode\u003e207846a\u003c/code\u003e\u003c/a\u003e ready for 4.32.0 release (\u003ca href=\"https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html/issues/5513\"\u003e#5513\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apostrophecms/apostrophe/commit/f82003349abf4245babdb1afcb225255a9694979\"\u003e\u003ccode\u003ef820033\u003c/code\u003e\u003c/a\u003e Latest reconciliation q2 m2 (\u003ca href=\"https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html/issues/5511\"\u003e#5511\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apostrophecms/apostrophe/commit/24275081ab67f2060782e141dc3554721c1bae5a\"\u003e\u003ccode\u003e2427508\u003c/code\u003e\u003c/a\u003e release and changelog edits (\u003ca href=\"https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html/issues/5465\"\u003e#5465\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apostrophecms/apostrophe/commit/5a88e9630cbbdde33154ef8abe7557ddf7be418b\"\u003e\u003ccode\u003e5a88e96\u003c/code\u003e\u003c/a\u003e Latest security q2 (\u003ca href=\"https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html/issues/5464\"\u003e#5464\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apostrophecms/apostrophe/commit/958d16214ff4b94b9280fddd088060ff401ded0d\"\u003e\u003ccode\u003e958d162\u003c/code\u003e\u003c/a\u003e merge main to latest (\u003ca href=\"https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html/issues/5460\"\u003e#5460\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apostrophecms/apostrophe/commit/e9b0ab0849a5dfea0f75335fbdf99b5c6bf9e4b3\"\u003e\u003ccode\u003ee9b0ab0\u003c/code\u003e\u003c/a\u003e release only (changelogs formatted) (\u003ca href=\"https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html/issues/5408\"\u003e#5408\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apostrophecms/apostrophe/commit/f03fa5b7746132bf46244036ab961bba995b611d\"\u003e\u003ccode\u003ef03fa5b\u003c/code\u003e\u003c/a\u003e Latest security merge (\u003ca href=\"https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html/issues/5407\"\u003e#5407\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apostrophecms/apostrophe/commit/96cf174486e1387948e189786c2d574cf7c3f3d0\"\u003e\u003ccode\u003e96cf174\u003c/code\u003e\u003c/a\u003e For release only (\u003ca href=\"https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html/issues/5381\"\u003e#5381\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apostrophecms/apostrophe/commit/7ca2d16237c72718ef7e5c7ae0458e6027ac4f64\"\u003e\u003ccode\u003e7ca2d16\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apostrophecms/apostrophe/commits/sanitize-html@2.17.7/packages/sanitize-html\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-xml-parser` from 5.9.3 to 5.11.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/releases\"\u003efast-xml-parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.11.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump actions/checkout from 7.0.0 to 7.0.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/858\"\u003eNaturalIntelligence/fast-xml-parser#858\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump zizmorcore/zizmor-action from 0.5.7 to 0.6.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/856\"\u003eNaturalIntelligence/fast-xml-parser#856\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/setup-node from 6.4.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/854\"\u003eNaturalIntelligence/fast-xml-parser#854\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: fix two 404 documentation links by \u003ca href=\"https://github.com/rajanpanth\"\u003e\u003ccode\u003e@​rajanpanth\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/862\"\u003eNaturalIntelligence/fast-xml-parser#862\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rajanpanth\"\u003e\u003ccode\u003e@​rajanpanth\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/862\"\u003eNaturalIntelligence/fast-xml-parser#862\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.11.0...v5.11.1\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.11.0...v5.11.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.11.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eadd support for endIndex in node metadata (5.x edition) by \u003ca href=\"https://github.com/Wain-PC\"\u003e\u003ccode\u003e@​Wain-PC\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/850\"\u003eNaturalIntelligence/fast-xml-parser#850\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: don't crash on a closing tag with no matching opening tag by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/861\"\u003eNaturalIntelligence/fast-xml-parser#861\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Wain-PC\"\u003e\u003ccode\u003e@​Wain-PC\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/850\"\u003eNaturalIntelligence/fast-xml-parser#850\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/861\"\u003eNaturalIntelligence/fast-xml-parser#861\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.10.1...v5.11.0\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.10.1...v5.11.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.10.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.10.0...v5.10.1\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.10.0...v5.10.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.10.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump actions/checkout from 6.0.3 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/849\"\u003eNaturalIntelligence/fast-xml-parser#849\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump zizmorcore/zizmor-action from 0.5.6 to 0.5.7 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/848\"\u003eNaturalIntelligence/fast-xml-parser#848\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.3...v5.10.0\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.3...v5.10.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md\"\u003efast-xml-parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003eNote: If you find missing information about particular minor version, that version must have been changed without any functional change in this library.\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003cp\u003eNote: Due to some last quick changes on v4, detail of v4.5.3 \u0026amp; v4.5.4 are not updated here. v4.5.4x is the last tag of v4 in github repository. I'm extremely sorry for the confusion\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e5.11.1 / 2026-08-27\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efix: validator; Replace regex with a single-pass scanner for attribute tokens, eliminating quadratic behavior on long whitespace runs.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e5.11.0 / 2026-08-16\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efeat: support for endIndex in node metadata (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/850\"\u003e#850\u003c/a\u003e) [By \u003ca href=\"https://github.com/Wain-PC\"\u003ePavel Dranichnikov\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003efix: don't crash on a closing tag with no matching opening tag (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/861\"\u003e#861\u003c/a\u003e) [By \u003ca href=\"https://github.com/hdimer\"\u003eHaïm Dimer\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003efix: DOCTYPE to read SYSTEM/PUBLIC\u003c/li\u003e\n\u003cli\u003edeps: strnum v2.4.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e5.10.1 / 2026-07-17\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efix: multiple DOCTYPE declarations.\u003c/li\u003e\n\u003cli\u003edeps: \u003ccode\u003e@nodable/entities\u003c/code\u003e for treeshaking\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e5.10.0 / 2026-07-11\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eupgrade:\n\u003cul\u003e\n\u003cli\u003exml-naming v0.3.0: cache support\u003c/li\u003e\n\u003cli\u003ePEM v1.6.2: sibling bug fix\u003c/li\u003e\n\u003cli\u003eis-unsafe v2.0.0: tree shaking\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e*\u003cem\u003e5.9.3 / 2026-06-19\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eupdate strnum\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e*\u003cem\u003e5.9.2 / 2026-06-17\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003edummy release to test changes in github action\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e*\u003cem\u003e5.9.1 / 2026-06-17\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003edummy release to test release from github action\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e*\u003cem\u003e5.9.0 / 2026-06-15\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eupdate strnum to 2.3.0\n\u003cul\u003e\n\u003cli\u003eyou can set hex, binary, enotation, infinity, unicode\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003evalidate unsafe HTML or XML data in doctype entities unsing 'is-unsafe' library.\nUser can override rules by overriding EntityDecoder.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e*\u003cem\u003e5.8.0 / 2026-05-12\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eintegrate xml-naming to validate DOCTYPE entity name and notation name (using qname becaue of backward compatibility)\n\u003cul\u003e\n\u003cli\u003eThis will consider xml-version as well. '1.0' is default\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eupdate strnum to 2.3.0\n\u003cul\u003e\n\u003cli\u003eYou can set octal and binary parsing which is bydeault off\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eupdate fast-xml-builder to 1.2.0\n\u003cul\u003e\n\u003cli\u003ecan sanitize tag names if found invalid\u003c/li\u003e\n\u003cli\u003efix format output\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e5.7.3 / 2006-05-05\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efix: alwaysCreateTextNode should create text node when attributes are present for self closing node\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/3617550adfb280989f482d662b7e9ece55a32a34\"\u003e\u003ccode\u003e3617550\u003c/code\u003e\u003c/a\u003e 5.11.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/6021128c3251d4c1456d2c6cd8442a5005a1f39a\"\u003e\u003ccode\u003e6021128\u003c/code\u003e\u003c/a\u003e update for release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/6ddcb65f240005988457af6af6dd68fa0947acf5\"\u003e\u003ccode\u003e6ddcb65\u003c/code\u003e\u003c/a\u003e remove regex from validator\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/7d608151078d47040841e9804d490feb5c07dfe7\"\u003e\u003ccode\u003e7d60815\u003c/code\u003e\u003c/a\u003e docs: fix two 404 documentation links (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/862\"\u003e#862\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/4e3857b3ab78f0b8e37e70e5cd08f2bc1ac726a8\"\u003e\u003ccode\u003e4e3857b\u003c/code\u003e\u003c/a\u003e Bump actions/setup-node from 6.4.0 to 7.0.0 (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/854\"\u003e#854\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/fcc62fb8f6f620c95dd1c9ab7aac3061f0905592\"\u003e\u003ccode\u003efcc62fb\u003c/code\u003e\u003c/a\u003e Bump zizmorcore/zizmor-action from 0.5.7 to 0.6.1 (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/856\"\u003e#856\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/23a9019d1e481ad3d1b9aef5266194f4e366f14e\"\u003e\u003ccode\u003e23a9019\u003c/code\u003e\u003c/a\u003e Bump actions/checkout from 7.0.0 to 7.0.1 (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/858\"\u003e#858\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/f3c69ae2a9a1a1df4e4be9ca954ddcdf6563d16a\"\u003e\u003ccode\u003ef3c69ae\u003c/code\u003e\u003c/a\u003e 5.11.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/fdbd072e23fcc6ea1a4779aecdd7196620f432d7\"\u003e\u003ccode\u003efdbd072\u003c/code\u003e\u003c/a\u003e update for release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/c5fcb5b1f9178ed07a078b08f53382ee49268ba3\"\u003e\u003ccode\u003ec5fcb5b\u003c/code\u003e\u003c/a\u003e update lock files\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.3...v5.11.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.14 to 8.5.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8\"\u003e\u003ccode\u003e7beca13\u003c/code\u003e\u003c/a\u003e Does no load source map file without opts.from\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/decea51421682341401575b3740709fda0e12930\"\u003e\u003ccode\u003edecea51\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/c18e30d126395d42a0726aa00e03a8f1088985ae\"\u003e\u003ccode\u003ec18e30d\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/98a39ad73d163a90be924d5126c771262110f1fc\"\u003e\u003ccode\u003e98a39ad\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/a3e48c492ddec0e4879d513b8b995fee887af352\"\u003e\u003ccode\u003ea3e48c4\u003c/code\u003e\u003c/a\u003e Release 8.5.22 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f49d6911795f53b2cfe023bb686bf1144ec30618\"\u003e\u003ccode\u003ef49d691\u003c/code\u003e\u003c/a\u003e Fix custom property losing its semicolon before a comment (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2117\"\u003e#2117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/28e0daf8f2fe5ba9e19ea3f8c27c8fe176f9419e\"\u003e\u003ccode\u003e28e0daf\u003c/code\u003e\u003c/a\u003e Release 8.5.21 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3d2b4e43e38274f233b5609d09687cadad8215d9\"\u003e\u003ccode\u003e3d2b4e4\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.14...8.5.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nanoid` from 3.3.11 to 3.3.19\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/releases\"\u003enanoid's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed breaking Nano ID by requesting big ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/blob/main/CHANGELOG.md\"\u003enanoid's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID (by \u003ca href=\"https://github.com/geoffrey-diederichs\"\u003e\u003ccode\u003e@​geoffrey-diederichs\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed breaking Nano ID by requesting big ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/eb63bd6775188dc35d143bf24868be094f19b5ee\"\u003e\u003ccode\u003eeb63bd6\u003c/code\u003e\u003c/a\u003e Release 3.3.19 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9067e0361a643ab2c94ddd67606efbf275f6c0dd\"\u003e\u003ccode\u003e9067e03\u003c/code\u003e\u003c/a\u003e Sync CJS and ESM\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9ad98052b316c5e707f8098ace509d2ae165e54d\"\u003e\u003ccode\u003e9ad9805\u003c/code\u003e\u003c/a\u003e Release 3.3.18 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/55e50a0621ec084b4bb4000ea4e86e1191bd3da8\"\u003e\u003ccode\u003e55e50a0\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e10f8d40ce9d1ab47f66d65a16b48086432730d0\"\u003e\u003ccode\u003ee10f8d4\u003c/code\u003e\u003c/a\u003e Update index.native.js (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/606\"\u003e#606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/73d67168136b36fd3b644159b0cff149da4905d9\"\u003e\u003ccode\u003e73d6716\u003c/code\u003e\u003c/a\u003e Release 3.3.17 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/f9d13f150847d117877adee3460a46eceb0cf49b\"\u003e\u003ccode\u003ef9d13f1\u003c/code\u003e\u003c/a\u003e Sync 0 size behaviour with PostCSS 5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9760e112757cf7d46a79abd7a133bc4958757bb8\"\u003e\u003ccode\u003e9760e11\u003c/code\u003e\u003c/a\u003e Release 3.3.16 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66d\"\u003e\u003ccode\u003ee835c9b\u003c/code\u003e\u003c/a\u003e fix(non-secure): clamp negative size to prevent infinite loop (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/601\"\u003e#601\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/96dd086eb24396a275fa93ee78d73b2fece35809\"\u003e\u003ccode\u003e96dd086\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ai/nanoid/compare/3.3.11...3.3.19\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for nanoid since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@humanfs/node` from 0.16.7 to 0.16.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/humanwhocodes/humanfs/releases\"\u003e@​humanfs/node's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003enode: v0.16.8\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/compare/node-v0.16.7...node-v0.16.8\"\u003e0.16.8\u003c/a\u003e (2026-04-17)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eInclude type dependencies at runtime (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e956ce7a\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/humanwhocodes/humanfs/issues/145\"\u003e#145\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe following workspace dependencies were updated\n\u003cul\u003e\n\u003cli\u003edependencies\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​humanfs/core\u003c/code\u003e bumped from ^0.19.1 to ^0.19.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/humanwhocodes/humanfs/blob/main/packages/node/CHANGELOG.md\"\u003e@​humanfs/node's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/compare/node-v0.16.7...node-v0.16.8\"\u003e0.16.8\u003c/a\u003e (2026-04-17)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEnsure symlinks are copied as symlinks in \u003ccode\u003ecopy()\u003c/code\u003e and \u003ccode\u003ecopyAll()\u003c/code\u003e (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/22bbaa4487a3e6c1197ca619840de4615d0c3404\"\u003e22bbaa44\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eInclude type dependencies at runtime (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e956ce7a\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/humanwhocodes/humanfs/issues/145\"\u003e#145\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe following workspace dependencies were updated\n\u003cul\u003e\n\u003cli\u003edependencies\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​humanfs/core\u003c/code\u003e bumped from ^0.19.1 to ^0.19.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/e96070e897f017ae8abd2b0676d98d14e49665cc\"\u003e\u003ccode\u003ee96070e\u003c/code\u003e\u003c/a\u003e chore: release main (\u003ca href=\"https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node/issues/146\"\u003e#146\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/22bbaa4487a3e6c1197ca619840de4615d0c3404\"\u003e\u003ccode\u003e22bbaa4\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e\u003ccode\u003e956ce7a\u003c/code\u003e\u003c/a\u003e fix: Include type dependencies at runtime\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/humanwhocodes/humanfs/commits/node-v0.16.8/packages/node\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.14 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24\"\u003e\u003ccode\u003e2203f4f\u003c/code\u003e\u003c/a\u003e 1.1.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd\"\u003e\u003ccode\u003e0b09384\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@tiptap/core` from 3.13.0 to 3.31.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ueberdosis/tiptap/releases\"\u003e@​tiptap/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.31.3\u003c/h2\u003e\n\u003ch3\u003e\u003ccode\u003e@​tiptap/extension-collaboration-caret\u003c/code\u003e\u003c/h3\u003e\n\u003ch4\u003ePatch Changes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug which allowed potentially unsafe color values being sent by other clients. Those unsafe colors received from collaboration users are now ignored.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e\u003ccode\u003e@​tiptap/react\u003c/code\u003e\u003c/h3\u003e\n\u003ch4\u003ePatch Changes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eFix a TypeScript error (TS2694) in the shipped type declarations when \u003ccode\u003eskipLibCheck\u003c/code\u003e is turned off.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.31.2\u003c/h2\u003e\n\u003ch3\u003e\u003ccode\u003e@​tiptap/pm\u003c/code\u003e\u003c/h3\u003e\n\u003ch4\u003ePatch Changes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003eprosemirror-view\u003c/code\u003e to \u003ccode\u003e^1.42.3\u003c/code\u003e, which fixes an XSS vulnerability where pasting crafted HTML could run arbitrary JavaScript (GHSA-c8x8-7fp4-3x9w).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.31.1\u003c/h2\u003e\n\u003ch3\u003e\u003ccode\u003e@​tiptap/core\u003c/code\u003e\u003c/h3\u003e\n\u003ch4\u003ePatch Changes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eFix freezes in framework-based node views on iOS and Android\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.31.0\u003c/h2\u003e\n\u003ch3\u003e\u003ccode\u003e@​tiptap/react\u003c/code\u003e\u003c/h3\u003e\n\u003ch4\u003eMinor Changes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003ee7bf804: Align \u003ccode\u003eselected\u003c/code\u003e with ProseMirror node selections by default, expose text selections through \u003ccode\u003eselectionInside\u003c/code\u003e, and keep \u003ccode\u003eselectedOnTextSelection\u003c/code\u003e compatible.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.30.6\u003c/h2\u003e\n\u003ch3\u003e\u003ccode\u003e@​tiptap/core\u003c/code\u003e\u003c/h3\u003e\n\u003ch4\u003ePatch Changes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eNested lists exported to Markdown now keep their hierarchy when the file is read back by other Markdown tools.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e\u003ccode\u003e@​tiptap/extension-list\u003c/code\u003e\u003c/h3\u003e\n\u003ch4\u003ePatch Changes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eNested lists exported to Markdown now keep their hierarchy when the file is read back by other Markdown tools.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e\u003ccode\u003e@​tiptap/extension-youtube\u003c/code\u003e\u003c/h3\u003e\n\u003ch4\u003ePatch Changes\u003c/h4\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ueberdosis/tiptap/blob/v3.31.3/packages/core/CHANGELOG.md\"\u003e@​tiptap/core's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.31.3\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tiptap/pm\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.31.3\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.31.2\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies [c56b4c9]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tiptap/pm\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.31.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.31.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecd32a2f: Fix freezes in framework-based node views on iOS and Android\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tiptap/pm\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.31.1\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.31.0\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tiptap/pm\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.31.0\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.30.6\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e9f844ab: Nested lists exported to Markdown now keep their hierarchy when the file is read back by other Markdown tools.\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tiptap/pm\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.30.6\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.30.5\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ed0d499b: Fix a denial-of-service risk where crafted block or inline Markdown attributes could consume excessive CPU and block the browser or server event loop.\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tiptap/pm\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.30.5\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.30.4\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e01d7af8: Prevent untrusted HTML attributes from changing an object's prototype when merged with \u003ccode\u003emergeAttributes\u003c/code\u003e.\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tiptap/pm\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.30.4\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.30.3\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ueberdosis/tiptap/commit/35d2110ecb118a2d80f2b5823b7e4f629d948894\"\u003e\u003ccode\u003e35d2110\u003c/code\u003e\u003c/a\u003e chore(release): release new stable release (\u003ca href=\"https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core/issues/8311\"\u003e#8311\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ueberdosis/tiptap/commit/f38fec0a4cc520ff2181411360b83ca987808268\"\u003e\u003ccode\u003ef38fec0\u003c/code\u003e\u003c/a\u003e chore(release): release new stable release (\u003ca href=\"https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core/issues/8304\"\u003e#8304\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ueberdosis/tiptap/commit/bd35333232c9378302f9c3af83d7d1b6756ad6ee\"\u003e\u003ccode\u003ebd35333\u003c/code\u003e\u003c/a\u003e chore(release): release new stable release (\u003ca href=\"https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core/issues/8297\"\u003e#8297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ueberdosis/tiptap/commit/cd32a2fa058a32bfce9f2505f32e72fb9cbef8ee\"\u003e\u003ccode\u003ecd32a2f\u003c/code\u003e\u003c/a\u003e fix: ignore iOS chrome mutations outside contentDOM (\u003ca href=\"https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core/issues/8221\"\u003e#8221\u003c/a\u003e) (\u003ca href=\"https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core/issues/8296\"\u003e#8296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ueberdosis/tiptap/commit/0280f4a161d2fbf56e92d8b4e216c6792fde7146\"\u003e\u003ccode\u003e0280f4a\u003c/code\u003e\u003c/a\u003e chore(release): release new stable release (\u003ca href=\"https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core/issues/8292\"\u003e#8292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ueberdosis/tiptap/commit/e7bf804f8d37b4b69bcd8a410023a37f8a9818b7\"\u003e\u003ccode\u003ee7bf804\u003c/code\u003e\u003c/a\u003e fix: linting\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ueberdosis/tiptap/commit/5302fda4748a439b395e6be81bd1e825dbfcc08e\"\u003e\u003ccode\u003e5302fda\u003c/code\u003e\u003c/a\u003e chore(release): release new stable release (\u003ca href=\"https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core/issues/8264\"\u003e#8264\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ueberdosis/tiptap/commit/9f844ab7f3068ec3efee6f211343f0eae3c10699\"\u003e\u003ccode\u003e9f844ab\u003c/code\u003e\u003c/a\u003e fix(markdown): indent nested list content to the parent marker (\u003ca href=\"https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core/issues/8219\"\u003e#8219\u003c/a\u003e) (\u003ca href=\"https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core/issues/8274\"\u003e#8274\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ueberdosis/tiptap/commit/b0c188b1bc919b204beace074de36f5cb2a2d961\"\u003e\u003ccode\u003eb0c188b\u003c/code\u003e\u003c/a\u003e chore(release): release new stable release (\u003ca href=\"https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core/issues/8261\"\u003e#8261\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ueberdosis/tiptap/commit/d0d499be3cce633cf54ca9aa9f3d8a5a1f98bd74\"\u003e\u003ccode\u003ed0d499b\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ueberdosis/tiptap/commits/v3.31.3/packages/core\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​tiptap/core\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `adm-zip` from 0.5.17 to 0.6.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cthackers/adm-zip/releases\"\u003eadm-zip's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.6.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cthackers/adm-zip/compare/v0.6.0...v0.6.1\"\u003ehttps://github.com/cthackers/adm-zip/compare/v0.6.0...v0.6.1\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dev dependencies\u003c/li\u003e\n\u003cli\u003eFixed uncaught crash in async decompression on malformed DEFLATE data\u003c/li\u003e\n\u003cli\u003eFixed addLocalFolder following symlinks out of the archived folder\u003c/li\u003e\n\u003cli\u003eStripped setuid/setgid/sticky bits from extracted file permissions\u003c/li\u003e\n\u003cli\u003eEnforced the decompression size cap on the async path and for size 0\u003c/li\u003e\n\u003cli\u003eRejected archives with duplicate entry names\u003c/li\u003e\n\u003cli\u003eBlocked extraction from writing through symlinks inside the target\u003c/li\u003e\n\u003cli\u003eRouted malformed-header parse errors through the async callback\u003c/li\u003e\n\u003cli\u003eRejected zip entries whose declared data extent runs past the buffer\u003c/li\u003e\n\u003cli\u003eFixed addLocalFolderPromise hanging on empty folders and swallowing errors\u003c/li\u003e\n\u003cli\u003eFixed addLocalFolderAsync2 mangling local paths on Windows\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.6.0\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cthackers/adm-zip/compare/v0.5.18...v0.6.0\"\u003ehttps://github.com/cthackers/adm-zip/compare/v0.5.18...v0.6.0\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eThis release fixes a security vulnerability (CVE-2026-39244), resolves several long-standing bugs, ships built-in TypeScript types, and includes two behavior changes worth reading before you upgrade.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eextractEntryTo(dirEntry, target, maintainEntryPath = false) now preserves subdirectories instead of flattening files into the target folder by basename (which also silently overwrote same-named files). (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/306\"\u003e#306\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eExtraction no longer fails when the modification time can't be set — utimes is now best-effort. (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/379\"\u003e#379\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMinimum Node.js is now 14 (the code already required it; engines was incorrectly \u0026gt;=12).\u003c/li\u003e\n\u003cli\u003eCVE-2026-39244 — a crafted archive declaring a huge uncompressed size could force an unbounded Buffer.alloc and OOM the process; allocation is now bounded by the data actually present. Reported by Daniel Púa (devploit), Anh Hong, and José Antonio Zamudio Amaya. (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/568\"\u003e#568\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHardened entry-name lookup against object injection (\u003cstrong\u003eproto\u003c/strong\u003e names). Prototype-less table.\u003c/li\u003e\n\u003cli\u003eData-descriptor regression rejecting valid archives (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/548\"\u003e#548\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/533\"\u003e#533\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/554\"\u003e#554\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDirectory permissions not restored on extract (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/530\"\u003e#530\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eInfinite recursion on symlink loops in addLocalFolder (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/541\"\u003e#541\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUncaught process crash in writeFileToAsync on write failure (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/470\"\u003e#470\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/459\"\u003e#459\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/402\"\u003e#402\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEmpty name on directory entries (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/466\"\u003e#466\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etest() always returned false for archives with files\u003c/li\u003e\n\u003cli\u003e~6× faster entry sorting for large archives\u003c/li\u003e\n\u003cli\u003eBuilt-in TypeScript definitions (types.d.ts) — you can drop \u003ccode\u003e@​types/adm-zip\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.5.18\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 4.3.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/pull/566\"\u003ecthackers/adm-zip#566\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix corrupted zip when round-tripping entries with a data descriptor (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/555\"\u003e#555\u003c/a\u003e) by \u003ca href=\"https://github.com/JohnJunior\"\u003e\u003ccode\u003e@​JohnJunior\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/pull/564\"\u003ecthackers/adm-zip#564\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eprevent crashes when process.versions is an empty object by \u003ca href=\"https://github.com/matt-fidd\"\u003e\u003ccode\u003e@​matt-fidd\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/pull/551\"\u003ecthackers/adm-zip#551\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003esupport for writing zip64 by \u003ca href=\"https://github.com/mielverkerken\"\u003e\u003ccode\u003e@​mielverkerken\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/pull/562\"\u003ecthackers/adm-zip#562\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix Archive Utility failure on zips with empty directories (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/558\"\u003e#558\u003c/a\u003e) by \u003ca href=\"https://github.com/JohnJunior\"\u003e\u003ccode\u003e@​JohnJunior\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/pull/563\"\u003ecthackers/adm-zip#563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JohnJunior\"\u003e\u003ccode\u003e@​JohnJunior\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/pull/564\"\u003ecthackers/adm-zip#564\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/matt-fidd\"\u003e\u003ccode\u003e@​matt-fidd\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/pull/551\"\u003ecthackers/adm-zip#551\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mielverkerken\"\u003e\u003ccode\u003e@​mielverkerken\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/pull/562\"\u003ecthackers/adm-zip#562\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cthackers/adm-zip/compare/v0.5.17...v0.5.18\"\u003ehttps://github.com/cthackers/adm-zip/compare/v0.5.17...v0.5.18\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cthackers/adm-zip/blob/master/history.md\"\u003eadm-zip's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e0.6.0 / 2026-07-10\u003c/h1\u003e\n\u003cp\u003eSecurity\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed CVE-2026-39244: a crafted archive declaring a huge uncompressed size could force an unbounded \u003ccode\u003eBuffer.alloc\u003c/code\u003e (memory exhaustion / DoS) before any validation. Allocation is now bounded by the data actually present — STORED output is sized from the real bytes, DEFLATED output is grown by the inflater and capped at the declared size (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/568\"\u003e#568\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHardened the internal entry-name lookup table against object injection: entry names come from untrusted archives, and a name such as \u003ccode\u003e__proto__\u003c/code\u003e previously resolved to \u003ccode\u003eObject.prototype\u003c/code\u003e, crashing \u003ccode\u003eaddFile\u003c/code\u003e and hiding the entry from \u003ccode\u003egetEntry\u003c/code\u003e/\u003ccode\u003ereadFile\u003c/code\u003e. The table is now prototype-less\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eBug fixes\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a regression (0.5.15) that rejected valid archives using a data descriptor (general-purpose bit 3). The payload is now validated against the authoritative central-directory CRC instead of requiring/parsing the trailing descriptor (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/548\"\u003e#548\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/533\"\u003e#533\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/554\"\u003e#554\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eextractAllTo\u003c/code\u003e/\u003ccode\u003eextractAllToAsync\u003c/code\u003e not restoring directory permissions with \u003ccode\u003ekeepOriginalPermission\u003c/code\u003e; directory modes are applied after their contents are written, deepest path first, and no longer lock the extractor out of a restrictive directory (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/530\"\u003e#530\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed infinite recursion in \u003ccode\u003eaddLocalFolder\u003c/code\u003e when a folder contains a symlink pointing back to an ancestor (e.g. workspace \u003ccode\u003enode_modules\u003c/code\u003e); the walk now tracks resolved real paths and skips already-visited directories (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/541\"\u003e#541\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed an uncaught exception (\u003ccode\u003eERR_INVALID_ARG_TYPE\u003c/code\u003e) that crashed the process when \u003ccode\u003ewriteFileToAsync\u003c/code\u003e could not open the target file (bad permissions, invalid filename, exhausted file descriptors); write failures are now reported through the callback and write errors are no longer silently swallowed (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/470\"\u003e#470\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/459\"\u003e#459\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/402\"\u003e#402\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed directory entries reporting an empty \u003ccode\u003ename\u003c/code\u003e (e.g. \u003ccode\u003ea/b/c/\u003c/code\u003e now returns \u003ccode\u003ec\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/466\"\u003e#466\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eextractEntryTo\u003c/code\u003e flattening subdirectories when \u003ccode\u003emaintainEntryPath\u003c/code\u003e is false; the structure below the extracted directory is now preserved instead of collapsing (and overwriting) files by basename (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/306\"\u003e#306\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a failed \u003ccode\u003eutimes\u003c/code\u003e aborting extraction; setting the modification time is now best-effort and never fails extraction of already-written content (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/379\"\u003e#379\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003etest()\u003c/code\u003e always returning false for any archive containing a file (it indexed the entries array with an entry object instead of reading the entry); it now correctly verifies each entry's CRC\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003ePerformance\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFaster entry sorting when writing archives with many entries: names are decoded once instead of on every comparison (about 6× faster sort for large archives)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAdded\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eBundled TypeScript type definitions (\u003ccode\u003etypes.d.ts\u003c/code\u003e), so \u003ccode\u003e@types/adm-zip\u003c/code\u003e is no longer required\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNotes\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eBehavior change: \u003ccode\u003eextractEntryTo(dir, target, /* maintainEntryPath */ false)\u003c/code\u003e now preserves subdirectories beneath the extracted directory rather than flattening them\u003c/li\u003e\n\u003cli\u003eBehavior change: extraction no longer fails when the modification time cannot be set\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e0.5.4 / 2021-03-08\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eFixed relative paths\u003c/li\u003e\n\u003cli\u003eAdded zipcrypto encryption\u003c/li\u003e\n\u003cli\u003eLower verMade...\n\n_Description has been truncated_","html_url":"https://github.com/koreyba/EverFreeNote/pull/199","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/koreyba%2FEverFreeNote/issues/199","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/199/packages"},{"uuid":"5424304200","node_id":"PR_kwDOLRRzl88AAAABDJFsRA","number":59,"state":"open","title":"build(deps): bump the npm_and_yarn group across 1 directory with 16 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":4,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T12:29:42.000Z","updated_at":"2026-09-11T12:31:00.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"npm_and_yarn","update_count":16,"packages":[{"name":"undici","old_version":"6.24.0","new_version":"6.28.0","repository_url":"https://github.com/nodejs/undici"},{"name":"vite","old_version":"7.3.1","new_version":"7.3.5","repository_url":"https://github.com/vitejs/vite"},{"name":"@babel/core","old_version":"7.26.0","new_version":"7.29.7","repository_url":"https://github.com/babel/babel"},{"name":"@babel/plugin-transform-modules-systemjs","old_version":"7.25.9","new_version":"7.29.8","repository_url":"https://github.com/babel/babel"},{"name":"brace-expansion","old_version":"1.1.11","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"browserslist","old_version":"4.24.4","new_version":"4.28.9","repository_url":"https://github.com/browserslist/browserslist"},{"name":"follow-redirects","old_version":"1.15.6","new_version":"1.16.0","repository_url":"https://github.com/follow-redirects/follow-redirects"},{"name":"form-data","old_version":"4.0.5","new_version":"4.0.6","repository_url":"https://github.com/form-data/form-data"},{"name":"joi","old_version":"17.6.3","new_version":"17.13.7","repository_url":"https://github.com/hapijs/joi"},{"name":"lodash","old_version":"4.17.21","new_version":"4.18.1","repository_url":"https://github.com/lodash/lodash"},{"name":"nanoid","old_version":"3.3.11","new_version":"3.3.19","repository_url":"https://github.com/ai/nanoid"},{"name":"postcss","old_version":"8.5.6","new_version":"8.5.28","repository_url":"https://github.com/postcss/postcss"},{"name":"qs","old_version":"6.14.1","new_version":"6.16.0","repository_url":"https://github.com/ljharb/qs"},{"name":"seroval","old_version":"1.5.1","new_version":"1.5.6","repository_url":"https://github.com/lxsmnsyc/seroval"},{"name":"tmp","old_version":"0.2.5","new_version":"0.2.7","repository_url":"https://github.com/raszi/node-tmp"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 15 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [undici](https://github.com/nodejs/undici) | `6.24.0` | `6.28.0` |\n| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `7.3.1` | `7.3.5` |\n| [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) | `7.26.0` | `7.29.7` |\n| [@babel/plugin-transform-modules-systemjs](https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs) | `7.25.9` | `7.29.8` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.11` | `1.1.18` |\n| [browserslist](https://github.com/browserslist/browserslist) | `4.24.4` | `4.28.9` |\n| [follow-redirects](https://github.com/follow-redirects/follow-redirects) | `1.15.6` | `1.16.0` |\n| [form-data](https://github.com/form-data/form-data) | `4.0.5` | `4.0.6` |\n| [joi](https://github.com/hapijs/joi) | `17.6.3` | `17.13.7` |\n| [lodash](https://github.com/lodash/lodash) | `4.17.21` | `4.18.1` |\n| [nanoid](https://github.com/ai/nanoid) | `3.3.11` | `3.3.19` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.6` | `8.5.28` |\n| [qs](https://github.com/ljharb/qs) | `6.14.1` | `6.16.0` |\n| [seroval](https://github.com/lxsmnsyc/seroval) | `1.5.1` | `1.5.6` |\n| [tmp](https://github.com/raszi/node-tmp) | `0.2.5` | `0.2.7` |\n\n\nUpdates `undici` from 6.24.0 to 6.28.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.28.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e740a0b7c\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003ecba3a52a\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e4fd5a0c6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003eaf748404\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e and \u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e affect the cache interceptor in Undici v7 and v8; Undici v6 is not in their affected version ranges.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ehttps://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.27.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e4 security advisories\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 6.27.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^6.27.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on patched version:\u003c/strong\u003e the v6 fixes shipped in \u003cstrong\u003ev6.27.0\u003c/strong\u003e, not \u003ccode\u003e6.26.0\u003c/code\u003e\n— \u003ccode\u003ev6.26.0\u003c/code\u003e contains only the chunked-EOF fix (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5308\"\u003e#5308\u003c/a\u003e) and the version bump, none\nof the security fixes below.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe v6 line is \u003cstrong\u003enot\u003c/strong\u003e affected by the SOCKS5 advisories (GHSA-vmh5-mc38-953g,\nGHSA-hm92-r4w5-c3mj), the shared-cache disclosure (GHSA-pr7r-676h-xcf6), or the\n8.x-only WebSocket regression (GHSA-38rv-x7px-6hhq).\u003c/p\u003e\n\u003ch2\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAdvisory\u003c/th\u003e\n\u003cth\u003eCVE\u003c/th\u003e\n\u003cth\u003eSeverity (CVSS)\u003c/th\u003e\n\u003cth\u003eFixed in\u003c/th\u003e\n\u003cth\u003eFix commit\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-12151\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b7f252e7\"\u003e\u003ccode\u003eb7f252e7\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv\"\u003eGHSA-p88m-4jfj-68fv\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9679\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/25efa447\"\u003e\u003ccode\u003e25efa447\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m\"\u003eGHSA-g8m3-5g58-fq7m\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-11525\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/25efa447\"\u003e\u003ccode\u003e25efa447\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52\"\u003eGHSA-35p6-xmwp-9g52\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6733\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f4c31d60\"\u003e\u003ccode\u003ef4c31d60\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003chr /\u003e\n\u003ch2\u003eHigh severity\u003c/h2\u003e\n\u003ch3\u003eWebSocket DoS via fragment count bypass — CVE-2026-12151\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/strong\u003e · CWE-400, CWE-770\n\u003cstrong\u003eFix:\u003c/strong\u003e \u003ca href=\"https://github.com/nodejs/undici/commit/b7f252e7\"\u003e\u003ccode\u003eb7f252e7\u003c/code\u003e\u003c/a\u003e \u003cem\u003eBackport WebSocket maxPayloadSize fixes\u003c/em\u003e (\u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5423\"\u003e#5423\u003c/a\u003e, backported to v6 in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5428\"\u003e#5428\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eA malicious WebSocket server can stream a large number of small or empty\ncontinuation frames. Undici enforced a limit on cumulative payload size but did\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/01a912e49a50c48009ed2639d2a457a6ec26752a\"\u003e\u003ccode\u003e01a912e\u003c/code\u003e\u003c/a\u003e Bumped v6.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5591\"\u003e#5591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/481ecfc3280292ab7eb0abbc4d0139219126f15e\"\u003e\u003ccode\u003e481ecfc\u003c/code\u003e\u003c/a\u003e Use Node 22 and npm 11 to release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e\u003ccode\u003e740a0b7\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2698e492ed22c9ec704b5df573d612bdd03f6ca0\"\u003e\u003ccode\u003e2698e49\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e\u003ccode\u003e4fd5a0c\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003e\u003ccode\u003ecba3a52\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003e\u003ccode\u003eaf74840\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/551138cbc1742c92242a68216167761075e8a82c\"\u003e\u003ccode\u003e551138c\u003c/code\u003e\u003c/a\u003e Bumped v6.27.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5431\"\u003e#5431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b7f252e7c0841418fb9d95cd297bdd9fad9d2a53\"\u003e\u003ccode\u003eb7f252e\u003c/code\u003e\u003c/a\u003e Backport WebSocket maxPayloadSize fixes to v7.x (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5423\"\u003e#5423\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5428\"\u003e#5428\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/25efa447997f74d5881edd144525c3fd7db945a4\"\u003e\u003ccode\u003e25efa44\u003c/code\u003e\u003c/a\u003e fix(cookies): preserve values and parse SameSite strictly\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v6.24.0...v6.28.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `vite` from 7.3.1 to 7.3.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/releases\"\u003evite's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.3.5\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.5/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.3.3\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.3/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.3.2\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.2/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.5/packages/vite/CHANGELOG.md\"\u003evite's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.3...v7.3.5\"\u003e7.3.5\u003c/a\u003e (2026-06-01)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ebackport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22572\"\u003e#22572\u003c/a\u003e, reject windows alternate paths (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22574\"\u003e#22574\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8c1855607b7c9884c4565d897ee98899a008a2d0\"\u003e8c18556\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e backport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22571\"\u003e#22571\u003c/a\u003e, reject UNC paths for launch-editor-middleware (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22573\"\u003e#22573\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/f20d64bef6e0ef1e4fa7a9783281c7bba0ce5292\"\u003ef20d64b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMiscellaneous Chores\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eskip v7.3.4 release (\u003ca href=\"https://github.com/vitejs/vite/commit/8a6a0c9fc734dbfe293ac33a4954506ee50430e1\"\u003e8a6a0c9\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.3...v7.3.4\"\u003e7.3.4\u003c/a\u003e (2026-06-01)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ebackport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22572\"\u003e#22572\u003c/a\u003e, reject windows alternate paths (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22574\"\u003e#22574\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8c1855607b7c9884c4565d897ee98899a008a2d0\"\u003e8c18556\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e backport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22571\"\u003e#22571\u003c/a\u003e, reject UNC paths for launch-editor-middleware (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22573\"\u003e#22573\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/f20d64bef6e0ef1e4fa7a9783281c7bba0ce5292\"\u003ef20d64b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.2...v7.3.3\"\u003e7.3.3\u003c/a\u003e (2026-05-07)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eavoid destructure lowering for newer safari (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22346\"\u003e#22346\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/5ab51c0f76f0896175e02ad797c1f5fe116d02f4\"\u003e5ab51c0\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.1...v7.3.2\"\u003e7.3.2\u003c/a\u003e (2026-04-06)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eavoid path traversal with optimize deps sourcemap handler (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22161\"\u003e#22161\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/09d8c903bde12fee2710314d3b42bc789c686df7\"\u003e09d8c90\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ebackport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22159\"\u003e#22159\u003c/a\u003e, apply server.fs check to env transport (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22162\"\u003e#22162\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/19db0f29c3a3ac4e64cc95c270716c77fd223ad1\"\u003e19db0f2\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echeck \u003ccode\u003eserver.fs\u003c/code\u003e after stripping query as well (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22160\"\u003e#22160\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/f8103cc946f137a54e395fe3f5d08e8209231ed6\"\u003ef8103cc\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/077945cb60df372a52cf999b6e532ba70fac7423\"\u003e\u003ccode\u003e077945c\u003c/code\u003e\u003c/a\u003e release: v7.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/8a6a0c9fc734dbfe293ac33a4954506ee50430e1\"\u003e\u003ccode\u003e8a6a0c9\u003c/code\u003e\u003c/a\u003e chore: skip v7.3.4 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/8c1855607b7c9884c4565d897ee98899a008a2d0\"\u003e\u003ccode\u003e8c18556\u003c/code\u003e\u003c/a\u003e fix: backport \u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22572\"\u003e#22572\u003c/a\u003e, reject windows alternate paths (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22574\"\u003e#22574\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/f20d64bef6e0ef1e4fa7a9783281c7bba0ce5292\"\u003e\u003ccode\u003ef20d64b\u003c/code\u003e\u003c/a\u003e fix(deps): backport \u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22571\"\u003e#22571\u003c/a\u003e, reject UNC paths for launch-editor-middleware (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/2\"\u003e#2\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/ca31424cccb075c88131132b929a63527d0e2b69\"\u003e\u003ccode\u003eca31424\u003c/code\u003e\u003c/a\u003e release: v7.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/5ab51c0f76f0896175e02ad797c1f5fe116d02f4\"\u003e\u003ccode\u003e5ab51c0\u003c/code\u003e\u003c/a\u003e fix: avoid destructure lowering for newer safari (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22346\"\u003e#22346\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/cc383e07b66d4c5a9768fcb570e0af812cb8d999\"\u003e\u003ccode\u003ecc383e0\u003c/code\u003e\u003c/a\u003e release: v7.3.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/09d8c903bde12fee2710314d3b42bc789c686df7\"\u003e\u003ccode\u003e09d8c90\u003c/code\u003e\u003c/a\u003e fix: avoid path traversal with optimize deps sourcemap handler (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22161\"\u003e#22161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/f8103cc946f137a54e395fe3f5d08e8209231ed6\"\u003e\u003ccode\u003ef8103cc\u003c/code\u003e\u003c/a\u003e fix: check \u003ccode\u003eserver.fs\u003c/code\u003e after stripping query as well (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22160\"\u003e#22160\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/19db0f29c3a3ac4e64cc95c270716c77fd223ad1\"\u003e\u003ccode\u003e19db0f2\u003c/code\u003e\u003c/a\u003e fix: backport \u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22159\"\u003e#22159\u003c/a\u003e, apply server.fs check to env transport (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22162\"\u003e#22162\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/vitejs/vite/commits/v7.3.5/packages/vite\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@babel/core` from 7.26.0 to 7.29.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/babel/babel/releases\"\u003e@​babel/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.7 (2026-05-25)\u003c/h2\u003e\n\u003cp\u003eRe-release all packages with npm provenance attestations\u003c/p\u003e\n\u003ch2\u003ev7.29.6 (2026-05-25)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18014\"\u003e#18014\u003c/a\u003e Catchup source map position in preserveFormat (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18001\"\u003e#18001\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e, \u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17998\"\u003e#17998\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 3\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMateusz Burzyński (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.5 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:house:  Internal\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@babel/*\u003c/code\u003e dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.4 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17974\"\u003e#17974\u003c/a\u003e [7.x backport]fix(systemjs): improve module string name support (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 1\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.3 (2026-04-30)\u003c/h2\u003e\n\u003ch4\u003e:eyeglasses: Spec Compliance\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17923\"\u003e#17923\u003c/a\u003e Support flow extends bound (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-helper-create-class-features-plugin\u003c/code\u003e, \u003ccode\u003ebabel-plugin-proposal-decorators\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17931\"\u003e#17931\u003c/a\u003e fix(decorators): replace super within all removed static elements (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-register\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17915\"\u003e#17915\u003c/a\u003e Fix thread synchronization issues in \u003ccode\u003e@babel/register\u003c/code\u003e (\u003ca href=\"https://github.com/liuxingbaoyu\"\u003e\u003ccode\u003e@​liuxingbaoyu\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-compat-data\u003c/code\u003e, \u003ccode\u003ebabel-plugin-bugfix-safari-rest-destructuring-rhs-array\u003c/code\u003e, \u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17788\"\u003e#17788\u003c/a\u003e Add bugfix plugin for Safari array rest destructuring bug (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:nail_care: Polish\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/4fba7541180bf5f58256d8e358b544e3831ad090\"\u003e\u003ccode\u003e4fba754\u003c/code\u003e\u003c/a\u003e v7.29.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/04ea6b27fdac8f40c3481aec2080ac9678779509\"\u003e\u003ccode\u003e04ea6b2\u003c/code\u003e\u003c/a\u003e v7.29.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/99f498a9b9fa0b900d603fbe8f6601bb3b9e42bb\"\u003e\u003ccode\u003e99f498a\u003c/code\u003e\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/18001\"\u003e#18001\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/feba0a3654c596bd369d1ef1231f5d56666d56dc\"\u003e\u003ccode\u003efeba0a3\u003c/code\u003e\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17998\"\u003e#17998\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/aa8394e454337d118ac3d40bfa3ee1a3cb3f3ed2\"\u003e\u003ccode\u003eaa8394e\u003c/code\u003e\u003c/a\u003e v7.29.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/ad0d03f0c92404a60ec6b1c12f15febd38e2397a\"\u003e\u003ccode\u003ead0d03f\u003c/code\u003e\u003c/a\u003e [7.x backport] feat: Allow specifying startLine in code frame (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17739\"\u003e#17739\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/d7f400889567ae18ef9ac41b024b5120f6060e17\"\u003e\u003ccode\u003ed7f4008\u003c/code\u003e\u003c/a\u003e v7.28.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/e130225028e93e106135586f344cfa44c4aac847\"\u003e\u003ccode\u003ee130225\u003c/code\u003e\u003c/a\u003e Polish(standalone): improve message on invalid preset/plugin (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17606\"\u003e#17606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/99dcba5e71de3bd81ce14077cfa5b6df58e9b177\"\u003e\u003ccode\u003e99dcba5\u003c/code\u003e\u003c/a\u003e chore: enable some ts-eslint rules (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17592\"\u003e#17592\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/c92c4919771105140015167f25f7bacac77c90d9\"\u003e\u003ccode\u003ec92c491\u003c/code\u003e\u003c/a\u003e Improve Unicode handling in code-frame tokenizer (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17589\"\u003e#17589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/babel/babel/commits/v7.29.7/packages/babel-core\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​babel/core\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@babel/plugin-transform-modules-systemjs` from 7.25.9 to 7.29.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/babel/babel/releases\"\u003e@​babel/plugin-transform-modules-systemjs's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.8 (2026-07-31)\u003c/h2\u003e\n\u003ch4\u003e:eyeglasses: Spec Compliance\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e, \u003ccode\u003ebabel-parser\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-spread\u003c/code\u003e, \u003ccode\u003ebabel-traverse\u003c/code\u003e, \u003ccode\u003ebabel-types\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17871\"\u003e#17871\u003c/a\u003e Disallow super call after new (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18046\"\u003e#18046\u003c/a\u003e fix(generator): improve new callee parens check (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-node\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18044\"\u003e#18044\u003c/a\u003e fix(systemjs): support \u003ccode\u003e__proto__\u003c/code\u003e as an export name (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 2\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.7 (2026-05-25)\u003c/h2\u003e\n\u003cp\u003eRe-release all packages with npm provenance attestations\u003c/p\u003e\n\u003ch2\u003ev7.29.6 (2026-05-25)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18014\"\u003e#18014\u003c/a\u003e Catchup source map position in preserveFormat (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18001\"\u003e#18001\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e, \u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17998\"\u003e#17998\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 3\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMateusz Burzyński (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.5 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:house:  Internal\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@babel/*\u003c/code\u003e dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.4 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17974\"\u003e#17974\u003c/a\u003e [7.x backport]fix(systemjs): improve module string name support (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 1\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/5de11ca9234379b78ef95df72aebbec93f28bf45\"\u003e\u003ccode\u003e5de11ca\u003c/code\u003e\u003c/a\u003e v7.29.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/f08d4342e1f189a56e7cee46e60a1817af96219e\"\u003e\u003ccode\u003ef08d434\u003c/code\u003e\u003c/a\u003e fix(systemjs): support \u003cstrong\u003eproto\u003c/strong\u003e as an export name (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs/issues/18044\"\u003e#18044\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/4fba7541180bf5f58256d8e358b544e3831ad090\"\u003e\u003ccode\u003e4fba754\u003c/code\u003e\u003c/a\u003e v7.29.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/a458f66074b97d54773db8159af673d23b26079b\"\u003e\u003ccode\u003ea458f66\u003c/code\u003e\u003c/a\u003e v7.29.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/32ebd5aaf2526ddd176fd6a3d1e3dc594abdc8d9\"\u003e\u003ccode\u003e32ebd5a\u003c/code\u003e\u003c/a\u003e [7.x backport]fix(systemjs): improve module string name support (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs/issues/17974\"\u003e#17974\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/aa8394e454337d118ac3d40bfa3ee1a3cb3f3ed2\"\u003e\u003ccode\u003eaa8394e\u003c/code\u003e\u003c/a\u003e v7.29.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/0053db620c05acf0036f593b5aaf4e372daa79d0\"\u003e\u003ccode\u003e0053db6\u003c/code\u003e\u003c/a\u003e Update polyfill packages (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs/issues/17727\"\u003e#17727\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/61647ae2397c82c3c71f077b5ab109106a5cac0f\"\u003e\u003ccode\u003e61647ae\u003c/code\u003e\u003c/a\u003e v7.28.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/a177d551adba99773f4ff00ea9bf46550def6132\"\u003e\u003ccode\u003ea177d55\u003c/code\u003e\u003c/a\u003e [Babel 8] Use \u003ccode\u003et.traverseFast\u003c/code\u003e to replace some \u003ccode\u003epath.traverse\u003c/code\u003e (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs/issues/17518\"\u003e#17518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/eebd3a06021c13d335b5b0bd79734df3abbea678\"\u003e\u003ccode\u003eeebd3a0\u003c/code\u003e\u003c/a\u003e v7.27.1\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/babel/babel/commits/v7.29.8/packages/babel-plugin-transform-modules-systemjs\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​babel/plugin-transform-modules-systemjs\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.11 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.1.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003epkg: publish on tag 1.x  c460dbd\u003c/li\u003e\n\u003cli\u003efmt  ccb8ac6\u003c/li\u003e\n\u003cli\u003eFix potential ReDoS Vulnerability or Inefficient Regular Expression (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/65\"\u003e#65\u003c/a\u003e)  c3c73c8\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.11...v1.1.12\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.11...v1.1.12\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24\"\u003e\u003ccode\u003e2203f4f\u003c/code\u003e\u003c/a\u003e 1.1.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd\"\u003e\u003ccode\u003e0b09384\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/10c05fcf3699b1a29ef5e611c011af3d3c97e6e3\"\u003e\u003ccode\u003e10c05fc\u003c/code\u003e\u003c/a\u003e 1.1.14\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/1.1.11...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `browserslist` from 4.24.4 to 4.28.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/releases\"\u003ebrowserslist's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eincluding kaios\u003c/code\u003e in baseline queries (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved parsing performance.\u003c/li\u003e\n\u003cli\u003eFixed unbounded memory growth (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed prototype write issue (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Electron version queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003e\u0026gt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;=\u003c/code\u003e queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eSyntaxError\u003c/code\u003e regression of 4.28.3.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed baseline query case-insensitivity (by \u003ca href=\"https://github.com/swwind\"\u003e\u003ccode\u003e@​swwind\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix prototype pollution (by \u003ca href=\"https://github.com/chluo1997\"\u003e\u003ccode\u003e@​chluo1997\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved Baseline warning since we have it own warning.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.27.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003eBROWSERSLIST_TRACE_WARNING\u003c/code\u003e environment variable.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003ethrowOnMissing\u003c/code\u003e with \u003ccode\u003eextends\u003c/code\u003e query (by \u003ca href=\"https://github.com/alexander-akait\"\u003e\u003ccode\u003e@​alexander-akait\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003ebaseline-browser-mapping\u003c/code\u003e version requirement.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated Firefox ESR.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded Baseline queries (by \u003ca href=\"https://github.com/tonypconway\"\u003e\u003ccode\u003e@​tonypconway\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.25.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Windows support for custom stats (by \u003ca href=\"https://github.com/torgeilo\"\u003e\u003ccode\u003e@​torgeilo\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.25.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed ReDoS (by \u003ca href=\"https://github.com/ericcornelissen\"\u003e\u003ccode\u003e@​ericcornelissen\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md\"\u003ebrowserslist's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eincluding kaios\u003c/code\u003e in baseline queries (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved parsing performance.\u003c/li\u003e\n\u003cli\u003eFixed unbounded memory growth (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed prototype write issue (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Electron version queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003e\u0026gt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;=\u003c/code\u003e queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eSyntaxError\u003c/code\u003e regression of 4.28.3.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed baseline query case-insensitivity (by \u003ca href=\"https://github.com/swwind\"\u003e\u003ccode\u003e@​swwind\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix prototype pollution (by \u003ca href=\"https://github.com/chluo1997\"\u003e\u003ccode\u003e@​chluo1997\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved Baseline warning since we have it own warning.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.48.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003efirefox \u0026gt;= esr\u003c/code\u003e query support (by \u003ca href=\"https://github.com/SethFalco\"\u003e\u003ccode\u003e@​SethFalco\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/SethFalco\"\u003e\u003ccode\u003e@​SethFalco\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.27.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003eBROWSERSLIST_TRACE_WARNING\u003c/code\u003e environment variable.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003ethrowOnMissing\u003c/code\u003e with \u003ccode\u003eextends\u003c/code\u003e query (by \u003ca href=\"https://github.com/alexander-akait\"\u003e\u003ccode\u003e@​alexander-akait\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/12ed5252dabc14fee4e97b465894b2f90910ca62\"\u003e\u003ccode\u003e12ed525\u003c/code\u003e\u003c/a\u003e Release 4.28.9 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/b1d8cf9d7a7dc76f6585425a8360218289194297\"\u003e\u003ccode\u003eb1d8cf9\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/21517b651c915cdbbfb8c122268bc36f5cabb7ef\"\u003e\u003ccode\u003e21517b6\u003c/code\u003e\u003c/a\u003e Improve \u003ccode\u003eor\u003c/code\u003e parsing performance\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/f2f2e6cfb01bb4942941d328737546f4e2ae41ad\"\u003e\u003ccode\u003ef2f2e6c\u003c/code\u003e\u003c/a\u003e Release 4.28.8 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/d0787c88fa29ba895fea51cfe921232c7b5d1377\"\u003e\u003ccode\u003ed0787c8\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/fcf8fa9857b30ccdf801a548f5d09d3c4ff0d43f\"\u003e\u003ccode\u003efcf8fa9\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/browserslist/browserslist/issues/939\"\u003e#939\u003c/a\u003e from Jaybhade/fix/baseline-kaios-without-downstream\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/57ecd64454e9252afdd6a7e76926e13dda48a38c\"\u003e\u003ccode\u003e57ecd64\u003c/code\u003e\u003c/a\u003e fix: support \u0026quot;including kaios\u0026quot; without downstream\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/093a0f67bb0becda55235d767b134df3197c54a1\"\u003e\u003ccode\u003e093a0f6\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/b637868045806d2fba4c24eb0060e4cc8b1db276\"\u003e\u003ccode\u003eb637868\u003c/code\u003e\u003c/a\u003e Release 4.28.7 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/313f4659b9f985ade89d1d6a54a860371c41cc46\"\u003e\u003ccode\u003e313f465\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/browserslist/browserslist/compare/4.24.4...4.28.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for browserslist since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `follow-redirects` from 1.15.6 to 1.16.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/follow-redirects/follow-redirects/commit/0c23a223067201c368035e82954c11eb2578a33b\"\u003e\u003ccode\u003e0c23a22\u003c/code\u003e\u003c/a\u003e Release version 1.16.0 of the npm package.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/follow-redirects/follow-redirects/commit/844c4d302ac963d29bdb5dc1754ec7df3d70d7f9\"\u003e\u003ccode\u003e844c4d3\u003c/code\u003e\u003c/a\u003e Add sensitiveHeaders option.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/follow-redirects/follow-redirects/commit/5e8b8d024e2c76f804a284258e585ecb49a575be\"\u003e\u003ccode\u003e5e8b8d0\u003c/code\u003e\u003c/a\u003e ci: add Node.js 24.x to the CI matrix\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/follow-redirects/follow-redirects/commit/7953e2255aa0b93602eed3804f3bc5e6923a03af\"\u003e\u003ccode\u003e7953e22\u003c/code\u003e\u003c/a\u003e ci: upgrade GitHub Actions to use setup-node@v6 and checkout@v6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/follow-redirects/follow-redirects/commit/86dc1f86e4b56bcd642c78384d51f10f123aea75\"\u003e\u003ccode\u003e86dc1f8\u003c/code\u003e\u003c/a\u003e Sanitizing input.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/follow-redirects/follow-redirects/commit/21ef28a544c5e57f4c34b8476d75f2144609a1eb\"\u003e\u003ccode\u003e21ef28a\u003c/code\u003e\u003c/a\u003e Release version 1.15.11 of the npm package.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/follow-redirects/follow-redirects/commit/7c88135da3bd0681a7e156ee66b16b2f6f98b480\"\u003e\u003ccode\u003e7c88135\u003c/code\u003e\u003c/a\u003e Roll back tree shaking.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/follow-redirects/follow-redirects/commit/6e389ba094beec211a8847788a146917a16c1bdb\"\u003e\u003ccode\u003e6e389ba\u003c/code\u003e\u003c/a\u003e Release version 1.15.10 of the npm package.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/follow-redirects/follow-redirects/commit/5bc496e0229abda823221e0c6267926a3f93f262\"\u003e\u003ccode\u003e5bc496e\u003c/code\u003e\u003c/a\u003e Shake me up before you go-go.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/follow-redirects/follow-redirects/commit/694d6b47a42bc8377e5ef1480394de451e16bd5b\"\u003e\u003ccode\u003e694d6b4\u003c/code\u003e\u003c/a\u003e Bump minimist from 1.2.5 to 1.2.8\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/follow-redirects/follow-redirects/compare/v1.15.6...v1.16.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `form-data` from 4.0.5 to 4.0.6\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/form-data/form-data/blob/master/CHANGELOG.md\"\u003eform-data's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/form-data/form-data/compare/v4.0.5...v4.0.6\"\u003ev4.0.6\u003c/a\u003e - 2026-06-12\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] escape CR, LF, and \u003ccode\u003e\u0026quot;\u003c/code\u003e in field names and filenames \u003ca href=\"https://github.com/form-data/form-data/commit/8dff42c6da654ed4e7ad4acb7f8ccd3831217c99\"\u003e\u003ccode\u003e8dff42c\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003etape\u003c/code\u003e \u003ca href=\"https://github.com/form-data/form-data/commit/f31d21ef10bf46e46344c3ee4f99acbef6be43e1\"\u003e\u003ccode\u003ef31d21e\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Deps] update \u003ccode\u003ehasown\u003c/code\u003e, \u003ccode\u003emime-types\u003c/code\u003e \u003ca href=\"https://github.com/form-data/form-data/commit/92ae0eb5da94d6f01925d5f4fcffb2a1e50ed7cd\"\u003e\u003ccode\u003e92ae0eb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003ejs-randomness-predictor\u003c/code\u003e \u003ca href=\"https://github.com/form-data/form-data/commit/67b0f65c2e0b065a511d42227d35e4d367644e97\"\u003e\u003ccode\u003e67b0f65\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/form-data/form-data/commit/64190db548c0179e37206858e39f27cf513e9435\"\u003e\u003ccode\u003e64190db\u003c/code\u003e\u003c/a\u003e v4.0.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/form-data/form-data/commit/92ae0eb5da94d6f01925d5f4fcffb2a1e50ed7cd\"\u003e\u003ccode\u003e92ae0eb\u003c/code\u003e\u003c/a\u003e [Deps] update \u003ccode\u003ehasown\u003c/code\u003e, \u003ccode\u003emime-types\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/form-data/form-data/commit/f31d21ef10bf46e46344c3ee4f99acbef6be43e1\"\u003e\u003ccode\u003ef31d21e\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003etape\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/form-data/form-data/commit/8dff42c6da654ed4e7ad4acb7f8ccd3831217c99\"\u003e\u003ccode\u003e8dff42c\u003c/code\u003e\u003c/a\u003e [Fix] escape CR, LF, and \u003ccode\u003e\u0026quot;\u003c/code\u003e in field names and filenames\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/form-data/form-data/commit/67b0f65c2e0b065a511d42227d35e4d367644e97\"\u003e\u003ccode\u003e67b0f65\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003ejs-randomness-predictor\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/form-data/form-data/compare/v4.0.5...v4.0.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `joi` from 17.6.3 to 17.13.7\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/ed9d7cdd11ef5f7751fd46886f38dc605c9c3995\"\u003e\u003ccode\u003eed9d7cd\u003c/code\u003e\u003c/a\u003e 17.13.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/f2729f71839c57c94ac500b4be9e4b5b26d4e637\"\u003e\u003ccode\u003ef2729f7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hapijs/joi/issues/3145\"\u003e#3145\u003c/a\u003e from hapijs/backport/isodate-timeshift-v17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/c43fc964799c9b5f0c6921bf788162b67066ae81\"\u003e\u003ccode\u003ec43fc96\u003c/code\u003e\u003c/a\u003e chore: add regression test for \u003ca href=\"https://redirect.github.com/hapijs/joi/issues/3143\"\u003e#3143\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/115e7b58d5eaaecc5e9b7093d41899ad6fb053ec\"\u003e\u003ccode\u003e115e7b5\u003c/code\u003e\u003c/a\u003e fix(isoDate): pad a bare-hour timeshift with a colon, not just zeros\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/850be1ee24be8d548bb09359bdb0cf9fe41635ff\"\u003e\u003ccode\u003e850be1e\u003c/code\u003e\u003c/a\u003e 17.13.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/9faeecc48b18ec40e3881467645ae9074f0dfa3c\"\u003e\u003ccode\u003e9faeecc\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hapijs/joi/issues/3139\"\u003e#3139\u003c/a\u003e from hapijs/chore/backport-messages-proto\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/8d0b808f3e874d28f9078f61b7742290989afb36\"\u003e\u003ccode\u003e8d0b808\u003c/code\u003e\u003c/a\u003e fix: prevent messages proto injection\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/566e73fa58e72f0a1dcbb3b110ee2f49f33aece3\"\u003e\u003ccode\u003e566e73f\u003c/code\u003e\u003c/a\u003e 17.13.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/3f3907cd944257e143b22f3bf3f05e71478fa1b1\"\u003e\u003ccode\u003e3f3907c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hapijs/joi/issues/3135\"\u003e#3135\u003c/a\u003e from hapijs/chore/backport-rename-proto\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/172ececa192feda532b743d77bc9d3e523d19b01\"\u003e\u003ccode\u003e172ecec\u003c/code\u003e\u003c/a\u003e fix: prevent proto on renames\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hapijs/joi/compare/v17.6.3...v17.13.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `lodash` from 4.17.21 to 4.18.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lodash/lodash/releases\"\u003elodash's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.18.1\u003c/h2\u003e\n\u003ch2\u003eBugs\u003c/h2\u003e\n\u003cp\u003eFixes a \u003ccode\u003eReferenceError\u003c/code\u003e issue in \u003ccode\u003elodash\u003c/code\u003e \u003ccode\u003elodash-es\u003c/code\u003e \u003ccode\u003elodash-amd\u003c/code\u003e and \u003ccode\u003elodash.template\u003c/code\u003e when using the \u003ccode\u003etemplate\u003c/code\u003e and \u003ccode\u003efromPairs\u003c/code\u003e functions from the modular builds. See \u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6167#issuecomment-4165269769\"\u003elodash/lodash#6167\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eThese defects were related to how lodash distributions are built from the main branch using \u003ca href=\"https://github.com/lodash-archive/lodash-cli\"\u003ehttps://github.com/lodash-archive/lodash-cli\u003c/a\u003e. When internal dependencies change inside lodash functions, equivalent updates need to be made to a mapping in the lodash-cli. (hey, it was ahead of its time once upon a time!). We know this, but we missed it in the last release. It's the kind of thing that passes in CI, but fails bc the build is not the same thing you tested.\u003c/p\u003e\n\u003cp\u003eThere is no diff on main for this, but you can see the diffs for each of the npm packages on their respective branches:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elodash\u003c/code\u003e: \u003ca href=\"https://github.com/lodash/lodash/compare/4.18.0-npm...4.18.1-npm\"\u003ehttps://github.com/lodash/lodash/compare/4.18.0-npm...4.18.1-npm\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elodash-es\u003c/code\u003e: \u003ca href=\"https://github.com/lodash/lodash/compare/4.18.0-es...4.18.1-es\"\u003ehttps://github.com/lodash/lodash/compare/4.18.0-es...4.18.1-es\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elodash-amd\u003c/code\u003e: \u003ca href=\"https://github.com/lodash/lodash/compare/4.18.0-amd...4.18.1-amd\"\u003ehttps://github.com/lodash/lodash/compare/4.18.0-amd...4.18.1-amd\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elodash.template\u003c/code\u003e\u003ca href=\"https://github.com/lodash/lodash/compare/4.18.0-npm-packages...4.18.1-npm-packages\"\u003ehttps://github.com/lodash/lodash/compare/4.18.0-npm-packages...4.18.1-npm-packages\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.18.0\u003c/h2\u003e\n\u003ch2\u003ev4.18.0\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/lodash/lodash/compare/4.17.23...4.18.0\"\u003ehttps://github.com/lodash/lodash/compare/4.17.23...4.18.0\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ccode\u003e_.unset\u003c/code\u003e / \u003ccode\u003e_.omit\u003c/code\u003e\u003c/strong\u003e: Fixed prototype pollution via \u003ccode\u003econstructor\u003c/code\u003e/\u003ccode\u003eprototype\u003c/code\u003e path traversal (\u003ca href=\"https://github.com/lodash/lodash/security/advisories/GHSA-f23m-r3pf-42rh\"\u003eGHSA-f23m-r3pf-42rh\u003c/a\u003e, \u003ca href=\"https://github.com/lodash/lodash/commit/fe8d32eda854377349a4f922ab7655c8e5df9a0b\"\u003efe8d32e\u003c/a\u003e). Previously, array-wrapped path segments and primitive roots could bypass the existing guards, allowing deletion of properties from built-in prototypes. Now \u003ccode\u003econstructor\u003c/code\u003e and \u003ccode\u003eprototype\u003c/code\u003e are blocked unconditionally as non-terminal path keys, matching \u003ccode\u003ebaseSet\u003c/code\u003e. Calls that previously returned \u003ccode\u003etrue\u003c/code\u003e and deleted the property now return \u003ccode\u003efalse\u003c/code\u003e and leave the target untouched.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ccode\u003e_.template\u003c/code\u003e\u003c/strong\u003e: Fixed code injection via \u003ccode\u003eimports\u003c/code\u003e keys (\u003ca href=\"https://github.com/lodash/lodash/security/advisories/GHSA-r5fr-rjxr-66jc\"\u003eGHSA-r5fr-rjxr-66jc\u003c/a\u003e, CVE-2026-4800, \u003ca href=\"https://github.com/lodash/lodash/commit/879aaa93132d78c2f8d20c60279da9f8b21576d6\"\u003e879aaa9\u003c/a\u003e). Fixes an incomplete patch for CVE-2021-23337. The \u003ccode\u003evariable\u003c/code\u003e option was validated against \u003ccode\u003ereForbiddenIdentifierChars\u003c/code\u003e but \u003ccode\u003eimportsKeys\u003c/code\u003e was left unguarded, allowing code injection via the same \u003ccode\u003eFunction()\u003c/code\u003e constructor sink. \u003ccode\u003eimports\u003c/code\u003e keys containing forbidden identifier characters now throw \u003ccode\u003e\u0026quot;Invalid imports option passed into _.template\u0026quot;\u003c/code\u003e.\u003c/p\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd security notice for \u003ccode\u003e_.template\u003c/code\u003e in threat model and API docs (\u003ca href=\"https://redirect.github.com/lodash/lodash/pull/6099\"\u003e#6099\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDocument \u003ccode\u003elower \u0026gt; upper\u003c/code\u003e behavior in \u003ccode\u003e_.random\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/lodash/lodash/pull/6115\"\u003e#6115\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix quotes in \u003ccode\u003e_.compact\u003c/code\u003e jsdoc (\u003ca href=\"https://redirect.github.com/lodash/lodash/pull/6090\"\u003e#6090\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e\u003ccode\u003elodash.*\u003c/code\u003e modular packages\u003c/h3\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/lodash/lodash/pull/6157\"\u003eDiff\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eWe have also regenerated and published a select number of the \u003ccode\u003elodash.*\u003c/code\u003e modular packages.\u003c/p\u003e\n\u003cp\u003eThese modular packages had fallen out of sync significantly from the minor/patch updates to lodash. Specifically, we have brought the following packages up to parity w/ the latest lodash release because they have had CVEs on them in the past:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.orderby\"\u003elodash.orderby\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.tonumber\"\u003elodash.tonumber\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.trim\"\u003elodash.trim\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.trimend\"\u003elodash.trimend\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.sortedindexby\"\u003elodash.sortedindexby\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.zipobjectdeep\"\u003elodash.zipobjectdeep\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.unset\"\u003elodash.unset\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.omit\"\u003elodash.omit\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.template\"\u003elodash.template\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/cb0b9b9212521c08e3eafe7c8cb0af1b42b6649e\"\u003e\u003ccode\u003ecb0b9b9\u003c/code\u003e\u003c/a\u003e release(patch): bump main to 4.18.1 (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6177\"\u003e#6177\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/75535f57883b7225adb96de1cfc1cd4169cfcb51\"\u003e\u003ccode\u003e75535f5\u003c/code\u003e\u003c/a\u003e chore: prune stale advisory refs (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6170\"\u003e#6170\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/62e91bc6a39c98d85b9ada8c44d40593deaf82a4\"\u003e\u003ccode\u003e62e91bc\u003c/code\u003e\u003c/a\u003e docs: remove n_ Node.js \u0026lt; 6 REPL note from README (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6165\"\u003e#6165\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/59be2de61f8aa9461c7856533b51d31b7d8babc4\"\u003e\u003ccode\u003e59be2de\u003c/code\u003e\u003c/a\u003e release(minor): bump to 4.18.0 (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6161\"\u003e#6161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/af634573030f979194871da7c68f79420992f53d\"\u003e\u003ccode\u003eaf63457\u003c/code\u003e\u003c/a\u003e fix: broken tests for _.template 879aaa9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/1073a7693e1727e0cf3641e5f71f75ddcf8de7c0\"\u003e\u003ccode\u003e1073a76\u003c/code\u003e\u003c/a\u003e fix: linting issues\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/879aaa93132d78c2f8d20c60279da9f8b21576d6\"\u003e\u003ccode\u003e879aaa9\u003c/code\u003e\u003c/a\u003e fix: validate imports keys in _.template\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/fe8d32eda854377349a4f922ab7655c8e5df9a0b\"\u003e\u003ccode\u003efe8d32e\u003c/code\u003e\u003c/a\u003e fix: block prototype pollution in baseUnset via constructor/prototype traversal\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/18ba0a32f42fd02117f096b032f89c984173462d\"\u003e\u003ccode\u003e18ba0a3\u003c/code\u003e\u003c/a\u003e refactor(fromPairs): use baseAssignValue for consistent assignment (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6153\"\u003e#6153\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/b8190803d48d60b8c80ad45d39125f32fa618cb2\"\u003e\u003ccode\u003eb819080\u003c/code\u003e\u003c/a\u003e ci: add dist sync validation workflow (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6137\"\u003e#6137\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/lodash/lodash/compare/4.17.21...4.18.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nanoid` from 3.3.11 to 3.3.19\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/releases\"\u003enanoid's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed breaking Nano ID by requesting big ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/blob/main/CHANGELOG.md\"\u003enanoid's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID (by \u003ca href=\"https://github.com/geoffrey-diederichs\"\u003e\u003ccode\u003e@​geoffrey-diederichs\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed breaking Nano ID by requesting big ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/eb63bd6775188dc35d143bf24868be094f19b5ee\"\u003e\u003ccode\u003eeb63bd6\u003c/code\u003e\u003c/a\u003e Release 3.3.19 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9067e0361a643ab2c94ddd67606efbf275f6c0dd\"\u003e\u003ccode\u003e9067e03\u003c/code\u003e\u003c/a\u003e Sync CJS and ESM\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9ad98052b316c5e707f8098ace509d2ae165e54d\"\u003e\u003ccode\u003e9ad9805\u003c/code\u003e\u003c/a\u003e Release 3.3.18 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/55e50a0621ec084b4bb4000ea4e86e1191bd3da8\"\u003e\u003ccode\u003e55e50a0\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e10f8d40ce9d1ab47f66d65a16b48086432730d0\"\u003e\u003ccode\u003ee10f8d4\u003c/code\u003e\u003c/a\u003e Update index.native.js (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/606\"\u003e#606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/73d67168136b36fd3b644159b0cff149da4905d9\"\u003e\u003ccode\u003e73d6716\u003c/code\u003e\u003c/a\u003e Release 3.3.17 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/f9d13f150847d117877adee3460a46eceb0cf49b\"\u003e\u003ccode\u003ef9d13f1\u003c/code\u003e\u003c/a\u003e Sync 0 size behaviour with PostCSS 5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9760e112757cf7d46a79abd7a133bc4958757bb8\"\u003e\u003ccode\u003e9760e11\u003c/code\u003e\u003c/a\u003e Release 3.3.16 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66d\"\u003e\u003ccode\u003ee835c9b\u003c/code\u003e\u003c/a\u003e fix(non-secure): clamp negative size to prevent infinite loop (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/601\"\u003e#601\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/96dd086eb24396a275fa93ee78d73b2fece35809\"\u003e\u003ccode\u003e96dd086\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ai/nanoid/compare/3.3.11...3.3.19\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for nanoid since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.6 to 8.5.28\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.28\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes types regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed removing any comments starting with \u003ccode\u003e/*#\u003c/code\u003e (by \u003ca href=\"https://github.com/dylanpulver\"\u003e\u003ccode\u003e@​dylanpulver\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e*\u003c/code\u003e hack before a comment in Custom Properties (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed empty values in the middle of \u003ccode\u003elist.comma()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed whitespace-only values in \u003ccode\u003elist.space()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed rule’s end position on space before semicolon (by \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/romainmenke\"\u003e\u003ccode\u003e@​romainmenke\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed Chinese text in deprecation warning (by \u003ca href=\"https://github.com/Jesse205\"\u003e\u003ccode\u003e@​Jesse205\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.28\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes types regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed removing any comments starting with \u003ccode\u003e/*#\u003c/code\u003e (by \u003ca href=\"https://github.com/dylanpulver\"\u003e\u003ccode\u003e@​dylanpulver\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e*\u003c/code\u003e hack before a comment in Custom Properties (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed empty values in the middle of \u003ccode\u003elist.comma()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed whitespace-only values in \u003ccode\u003elist.space()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed rule’s end position on space before semicolon (by \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/romainmenke\"\u003e\u003ccode\u003e@​romainmenke\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed Chinese text in deprecation warning (by \u003ca href=\"https://github.com/Jesse205\"\u003e\u003ccode\u003e@​Jesse205\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/e544bffc4f4b3966d8ec69c41744b3ed65afc64a\"\u003e\u003ccode\u003ee544bff\u003c/code\u003e\u003c/a\u003e Release 8.5.28 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f8fc2525717a6a7216659f7be43c525f60c6a15a\"\u003e\u003ccode\u003ef8fc252\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/5039fd78962d285abea5d7b3aebef32f053781ce\"\u003e\u003ccode\u003e5039fd7\u003c/code\u003e\u003c/a\u003e Add missed release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/ae40ca499cf6a9afdbb264c0ec09e71fe934e2af\"\u003e\u003ccode\u003eae40ca4\u003c/code\u003e\u003c/a\u003e Release 8.5.27 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/62b1626bb7fbb28eda616d002cbd525d239b18ba\"\u003e\u003ccode\u003e62b1626\u003c/code\u003e\u003c/a\u003e Fix linter\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/1dba9384515a2dbc64517697c2f738b6d5c3f9a4\"\u003e\u003ccode\u003e1dba938\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3e82edc9f037faa41647342dceceba9b841f9881\"\u003e\u003ccode\u003e3e82edc\u003c/code\u003e\u003c/a\u003e Keep non-annotation comments when the processor has no plugins (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2150\"\u003e#2150\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/6d23bc362203118478bc8051b81f2910907ebe6e\"\u003e\u003ccode\u003e6d23bc3\u003c/code\u003e\u003c/a\u003e Fix link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/508e9976be81536292e7666741e1c35e876b9a6a\"\u003e\u003ccode\u003e508e997\u003c/code\u003e\u003c/a\u003e Add GitHub Sponsors link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/e993739dc49b6055f7dfc59b161d75702f0b2b8b\"\u003e\u003ccode\u003ee993739\u003c/code\u003e\u003c/a\u003e Add CodeRabbit sponsor (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2145\"\u003e#2145\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.6...8.5.28\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `qs` from 6.14.1 to 6.16.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com...\n\n_Description has been truncated_","html_url":"https://github.com/hashim21223445/Andoka-now-44/pull/59","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/hashim21223445%2FAndoka-now-44/issues/59","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/59/packages"},{"uuid":"5424162332","node_id":"PR_kwDORtkDrM8AAAABDI-fgA","number":172,"state":"closed","title":"build(deps): bump undici from 7.28.0 to 7.29.1 in /apps/frontend","user":"dependabot[bot]","labels":["dependencies","javascript","released"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-11T12:15:40.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-11T12:14:16.000Z","updated_at":"2026-09-11T14:54:09.000Z","time_to_close":84,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps)","packages":[{"name":"undici","old_version":"7.28.0","new_version":"7.29.1","repository_url":"https://github.com/nodejs/undici"}],"path":"/apps/frontend","ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 7.28.0 to 7.29.1.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.1\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/f690157d728508652fef14673630c71515123e96\"\u003ef690157d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6615e0175e9b635bcd2e3e87a47daa82f6f5b728\"\u003e6615e017\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/63cf698b611fecc6ee0a17b185b930051e4b982f\"\u003e63cf698b\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1858656ebb1e919311c1f31613dfd581b7214349\"\u003e1858656e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/b6c5a00252c37da9dd2db9bead053bb843e1f988\"\u003eb6c5a002\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2c7d7e1227043c644c4c32cfd1e276f4fd4fcb11\"\u003e2c7d7e12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3c6726599cea8646384dde846c97d630da472a74\"\u003e3c672659\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/b61d9432bac7caac51273ad209862e4c0bf935ae\"\u003eb61d9432\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/21693f406f0142f3504192e9f9b022dcf84782ae\"\u003e21693f40\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cd8af90b38ae33c2838d54a2d629774122effe95\"\u003ecd8af90b\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[v7.x] drop: remove Node.js 26 from shared-builtin CI build by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5592\"\u003enodejs/undici#5592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): honour headersTimeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5604\"\u003enodejs/undici#5604\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): keep the connection ref'd while requests are outstanding by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5605\"\u003enodejs/undici#5605\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: increase Windows workflow timeout on v7.x by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5621\"\u003enodejs/undici#5621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): retire the request that completed, not the head of the queue by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5618\"\u003enodejs/undici#5618\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): settle a request whose stream is cancelled by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5607\"\u003enodejs/undici#5607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: reduce EventSourceStream parser allocations (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5032\"\u003e#5032\u003c/a\u003e) by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5646\"\u003enodejs/undici#5646\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): handle GOAWAY for CONNECT streams by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5640\"\u003enodejs/undici#5640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v7.x] perf(h1): drop idle-socket timer floor with a ref'd setImmediate (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5707\"\u003e#5707\u003c/a\u003e) by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5769\"\u003enodejs/undici#5769\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.29.0...v7.29.1\"\u003ehttps://github.com/nodejs/undici/compare/v7.29.0...v7.29.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d39a83e7b0d631590c3b85b5cc0dbeab66c3a1d8\"\u003e\u003ccode\u003ed39a83e\u003c/code\u003e\u003c/a\u003e Bumped v7.29.1 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5772\"\u003e#5772\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0d88464876d02bdb9cf27015d9d66500a8aaa782\"\u003e\u003ccode\u003e0d88464\u003c/code\u003e\u003c/a\u003e fix(test): remove unused EventEmitter import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f57411b894d45b89964252971497507500c32bc1\"\u003e\u003ccode\u003ef57411b\u003c/code\u003e\u003c/a\u003e perf(h1): drop idle-socket timer floor with a ref'd setImmediate (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5707\"\u003e#5707\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5769\"\u003e#5769\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3c6726599cea8646384dde846c97d630da472a74\"\u003e\u003ccode\u003e3c67265\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cd8af90b38ae33c2838d54a2d629774122effe95\"\u003e\u003ccode\u003ecd8af90\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6615e0175e9b635bcd2e3e87a47daa82f6f5b728\"\u003e\u003ccode\u003e6615e01\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2c7d7e1227043c644c4c32cfd1e276f4fd4fcb11\"\u003e\u003ccode\u003e2c7d7e1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b6c5a00252c37da9dd2db9bead053bb843e1f988\"\u003e\u003ccode\u003eb6c5a00\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/21693f406f0142f3504192e9f9b022dcf84782ae\"\u003e\u003ccode\u003e21693f4\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f690157d728508652fef14673630c71515123e96\"\u003e\u003ccode\u003ef690157\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=7.28.0\u0026new-version=7.29.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/venkatesh-singamsetty/cricscore/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/venkatesh-singamsetty/cricscore/pull/172","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/venkatesh-singamsetty%2Fcricscore/issues/172","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/172/packages"},{"uuid":"5424035437","node_id":"PR_kwDOR_3Bw88AAAABDI3_hg","number":59,"state":"closed","title":"build(deps): bump undici from 7.25.0 to 7.29.1","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-11T12:11:51.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-11T11:59:40.000Z","updated_at":"2026-09-11T12:11:53.000Z","time_to_close":731,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps)","packages":[{"name":"undici","old_version":"7.25.0","new_version":"7.29.1","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 7.25.0 to 7.29.1.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.1\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/f690157d728508652fef14673630c71515123e96\"\u003ef690157d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6615e0175e9b635bcd2e3e87a47daa82f6f5b728\"\u003e6615e017\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/63cf698b611fecc6ee0a17b185b930051e4b982f\"\u003e63cf698b\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1858656ebb1e919311c1f31613dfd581b7214349\"\u003e1858656e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/b6c5a00252c37da9dd2db9bead053bb843e1f988\"\u003eb6c5a002\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2c7d7e1227043c644c4c32cfd1e276f4fd4fcb11\"\u003e2c7d7e12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3c6726599cea8646384dde846c97d630da472a74\"\u003e3c672659\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/b61d9432bac7caac51273ad209862e4c0bf935ae\"\u003eb61d9432\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/21693f406f0142f3504192e9f9b022dcf84782ae\"\u003e21693f40\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cd8af90b38ae33c2838d54a2d629774122effe95\"\u003ecd8af90b\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[v7.x] drop: remove Node.js 26 from shared-builtin CI build by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5592\"\u003enodejs/undici#5592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): honour headersTimeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5604\"\u003enodejs/undici#5604\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): keep the connection ref'd while requests are outstanding by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5605\"\u003enodejs/undici#5605\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: increase Windows workflow timeout on v7.x by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5621\"\u003enodejs/undici#5621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): retire the request that completed, not the head of the queue by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5618\"\u003enodejs/undici#5618\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): settle a request whose stream is cancelled by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5607\"\u003enodejs/undici#5607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: reduce EventSourceStream parser allocations (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5032\"\u003e#5032\u003c/a\u003e) by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5646\"\u003enodejs/undici#5646\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): handle GOAWAY for CONNECT streams by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5640\"\u003enodejs/undici#5640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v7.x] perf(h1): drop idle-socket timer floor with a ref'd setImmediate (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5707\"\u003e#5707\u003c/a\u003e) by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5769\"\u003enodejs/undici#5769\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.29.0...v7.29.1\"\u003ehttps://github.com/nodejs/undici/compare/v7.29.0...v7.29.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d39a83e7b0d631590c3b85b5cc0dbeab66c3a1d8\"\u003e\u003ccode\u003ed39a83e\u003c/code\u003e\u003c/a\u003e Bumped v7.29.1 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5772\"\u003e#5772\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0d88464876d02bdb9cf27015d9d66500a8aaa782\"\u003e\u003ccode\u003e0d88464\u003c/code\u003e\u003c/a\u003e fix(test): remove unused EventEmitter import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f57411b894d45b89964252971497507500c32bc1\"\u003e\u003ccode\u003ef57411b\u003c/code\u003e\u003c/a\u003e perf(h1): drop idle-socket timer floor with a ref'd setImmediate (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5707\"\u003e#5707\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5769\"\u003e#5769\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3c6726599cea8646384dde846c97d630da472a74\"\u003e\u003ccode\u003e3c67265\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cd8af90b38ae33c2838d54a2d629774122effe95\"\u003e\u003ccode\u003ecd8af90\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6615e0175e9b635bcd2e3e87a47daa82f6f5b728\"\u003e\u003ccode\u003e6615e01\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2c7d7e1227043c644c4c32cfd1e276f4fd4fcb11\"\u003e\u003ccode\u003e2c7d7e1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b6c5a00252c37da9dd2db9bead053bb843e1f988\"\u003e\u003ccode\u003eb6c5a00\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/21693f406f0142f3504192e9f9b022dcf84782ae\"\u003e\u003ccode\u003e21693f4\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f690157d728508652fef14673630c71515123e96\"\u003e\u003ccode\u003ef690157\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.25.0...v7.29.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=7.25.0\u0026new-version=7.29.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/trashmans/hello-fresh-trash-app/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/trashmans/hello-fresh-trash-app/pull/59","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/trashmans%2Fhello-fresh-trash-app/issues/59","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/59/packages"},{"uuid":"5424022568","node_id":"PR_kwDOIU25788AAAABDI3Vbw","number":259,"state":"open","title":"deps(deps): bump the other-dependencies group across 1 directory with 47 updates","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T11:58:07.000Z","updated_at":"2026-09-11T11:59:39.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"deps(deps): bump","group_name":"other-dependencies","update_count":47,"packages":[{"name":"@types/node","old_version":"26.4.1","new_version":"26.5.0","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"@asamuzakjp/css-color","old_version":"6.0.5","new_version":"6.0.7","repository_url":"https://github.com/asamuzaK/cssColor"},{"name":"@asamuzakjp/dom-selector","old_version":"8.3.0","new_version":"8.3.2","repository_url":"https://github.com/asamuzaK/domSelector"},{"name":"@babel/types","old_version":"7.29.7","new_version":"7.29.8","repository_url":"https://github.com/babel/babel"},{"name":"@babel/parser","old_version":"7.29.7","new_version":"7.29.8","repository_url":"https://github.com/babel/babel"},{"name":"@csstools/color-helpers","old_version":"6.1.0","new_version":"6.1.1","repository_url":"https://github.com/csstools/postcss-plugins"},{"name":"@csstools/css-color-parser","old_version":"4.1.10","new_version":"4.2.2","repository_url":"https://github.com/csstools/postcss-plugins"},{"name":"@csstools/css-syntax-patches-for-csstree","old_version":"1.1.7","new_version":"1.1.13","repository_url":"https://github.com/csstools/postcss-plugins"},{"name":"@inquirer/ansi","old_version":"2.0.7","new_version":"2.0.8","repository_url":"https://github.com/SBoudrias/Inquirer.js"},{"name":"@inquirer/checkbox","old_version":"5.2.1","new_version":"5.2.5","repository_url":"https://github.com/SBoudrias/Inquirer.js"},{"name":"@inquirer/editor","old_version":"5.2.2","new_version":"5.3.3","repository_url":"https://github.com/SBoudrias/Inquirer.js"},{"name":"@inquirer/expand","old_version":"5.1.1","new_version":"5.1.5","repository_url":"https://github.com/SBoudrias/Inquirer.js"},{"name":"@inquirer/input","old_version":"5.1.2","new_version":"5.1.6","repository_url":"https://github.com/SBoudrias/Inquirer.js"},{"name":"@inquirer/number","old_version":"4.1.1","new_version":"4.2.3","repository_url":"https://github.com/SBoudrias/Inquirer.js"},{"name":"@inquirer/password","old_version":"5.1.1","new_version":"5.2.2","repository_url":"https://github.com/SBoudrias/Inquirer.js"},{"name":"@inquirer/rawlist","old_version":"5.3.1","new_version":"5.3.5","repository_url":"https://github.com/SBoudrias/Inquirer.js"},{"name":"@inquirer/search","old_version":"4.2.1","new_version":"4.3.3","repository_url":"https://github.com/SBoudrias/Inquirer.js"},{"name":"@inquirer/select","old_version":"5.2.1","new_version":"5.2.5","repository_url":"https://github.com/SBoudrias/Inquirer.js"},{"name":"@jridgewell/sourcemap-codec","old_version":"1.5.5","new_version":"1.6.0","repository_url":"https://github.com/jridgewell/sourcemaps"},{"name":"@napi-rs/wasm-runtime","old_version":"1.2.2","new_version":"1.2.4","repository_url":"https://github.com/napi-rs/napi-rs"},{"name":"ansi-regex","old_version":"6.2.2","new_version":"6.3.0","repository_url":"https://github.com/chalk/ansi-regex"},{"name":"ast-v8-to-istanbul","old_version":"1.0.5","new_version":"1.0.6","repository_url":"https://github.com/AriPerkkio/ast-v8-to-istanbul"},{"name":"axios","old_version":"1.19.0","new_version":"1.20.0","repository_url":"https://github.com/axios/axios"},{"name":"baseline-browser-mapping","old_version":"2.11.8","new_version":"2.11.22","repository_url":"https://github.com/web-platform-dx/baseline-browser-mapping"},{"name":"bidi-js","old_version":"1.0.3","new_version":"1.1.0","repository_url":"https://github.com/lojjic/bidi-js"},{"name":"browserslist","old_version":"4.28.7","new_version":"4.28.9","repository_url":"https://github.com/browserslist/browserslist"},{"name":"chromedriver","old_version":"152.0.2","new_version":"153.0.0","repository_url":"https://github.com/giggio/node-chromedriver"},{"name":"express-rate-limit","old_version":"8.6.2","new_version":"8.7.0","repository_url":"https://github.com/express-rate-limit/express-rate-limit"},{"name":"hono","old_version":"4.13.5","new_version":"4.13.7","repository_url":"https://github.com/honojs/hono"},{"name":"ip-address","old_version":"10.4.0","new_version":"10.7.0","repository_url":"https://github.com/beaugunderson/ip-address"},{"name":"jose","old_version":"6.2.10","new_version":"6.2.12","repository_url":"https://github.com/panva/jose"},{"name":"postcss","old_version":"8.5.25","new_version":"8.5.28","repository_url":"https://github.com/postcss/postcss"},{"name":"postcss-safe-parser","old_version":"7.0.1","new_version":"7.1.0","repository_url":"https://github.com/postcss/postcss-safe-parser"},{"name":"readdirp","old_version":"5.0.0","new_version":"5.1.1","repository_url":"https://github.com/paulmillr/readdirp"},{"name":"socks","old_version":"2.8.9","new_version":"2.8.10","repository_url":"https://github.com/JoshGlazebrook/socks"},{"name":"tldts","old_version":"7.4.10","new_version":"7.4.12","repository_url":"https://github.com/remusao/tldts"},{"name":"undici","old_version":"8.9.0","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"},{"name":"ws","old_version":"8.21.1","new_version":"8.21.3","repository_url":"https://github.com/websockets/ws"}],"path":null,"ecosystem":"npm"},"body":"Bumps the other-dependencies group with 38 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.4.1` | `26.5.0` |\n| [@asamuzakjp/css-color](https://github.com/asamuzaK/cssColor) | `6.0.5` | `6.0.7` |\n| [@asamuzakjp/dom-selector](https://github.com/asamuzaK/domSelector) | `8.3.0` | `8.3.2` |\n| [@babel/types](https://github.com/babel/babel/tree/HEAD/packages/babel-types) | `7.29.7` | `7.29.8` |\n| [@babel/parser](https://github.com/babel/babel/tree/HEAD/packages/babel-parser) | `7.29.7` | `7.29.8` |\n| [@csstools/color-helpers](https://github.com/csstools/postcss-plugins/tree/HEAD/packages/color-helpers) | `6.1.0` | `6.1.1` |\n| [@csstools/css-color-parser](https://github.com/csstools/postcss-plugins/tree/HEAD/packages/css-color-parser) | `4.1.10` | `4.2.2` |\n| [@csstools/css-syntax-patches-for-csstree](https://github.com/csstools/postcss-plugins/tree/HEAD/packages/css-syntax-patches-for-csstree) | `1.1.7` | `1.1.13` |\n| [@inquirer/ansi](https://github.com/SBoudrias/Inquirer.js) | `2.0.7` | `2.0.8` |\n| [@inquirer/checkbox](https://github.com/SBoudrias/Inquirer.js) | `5.2.1` | `5.2.5` |\n| [@inquirer/editor](https://github.com/SBoudrias/Inquirer.js) | `5.2.2` | `5.3.3` |\n| [@inquirer/expand](https://github.com/SBoudrias/Inquirer.js) | `5.1.1` | `5.1.5` |\n| [@inquirer/input](https://github.com/SBoudrias/Inquirer.js) | `5.1.2` | `5.1.6` |\n| [@inquirer/number](https://github.com/SBoudrias/Inquirer.js) | `4.1.1` | `4.2.3` |\n| [@inquirer/password](https://github.com/SBoudrias/Inquirer.js) | `5.1.1` | `5.2.2` |\n| [@inquirer/rawlist](https://github.com/SBoudrias/Inquirer.js) | `5.3.1` | `5.3.5` |\n| [@inquirer/search](https://github.com/SBoudrias/Inquirer.js) | `4.2.1` | `4.3.3` |\n| [@inquirer/select](https://github.com/SBoudrias/Inquirer.js) | `5.2.1` | `5.2.5` |\n| [@jridgewell/sourcemap-codec](https://github.com/jridgewell/sourcemaps/tree/HEAD/packages/sourcemap-codec) | `1.5.5` | `1.6.0` |\n| [@napi-rs/wasm-runtime](https://github.com/napi-rs/napi-rs/tree/HEAD/wasm-runtime) | `1.2.2` | `1.2.4` |\n| [ansi-regex](https://github.com/chalk/ansi-regex) | `6.2.2` | `6.3.0` |\n| [ast-v8-to-istanbul](https://github.com/AriPerkkio/ast-v8-to-istanbul) | `1.0.5` | `1.0.6` |\n| [axios](https://github.com/axios/axios) | `1.19.0` | `1.20.0` |\n| [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) | `2.11.8` | `2.11.22` |\n| [bidi-js](https://github.com/lojjic/bidi-js) | `1.0.3` | `1.1.0` |\n| [browserslist](https://github.com/browserslist/browserslist) | `4.28.7` | `4.28.9` |\n| [chromedriver](https://github.com/giggio/node-chromedriver) | `152.0.2` | `153.0.0` |\n| [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) | `8.6.2` | `8.7.0` |\n| [hono](https://github.com/honojs/hono) | `4.13.5` | `4.13.7` |\n| [ip-address](https://github.com/beaugunderson/ip-address) | `10.4.0` | `10.7.0` |\n| [jose](https://github.com/panva/jose) | `6.2.10` | `6.2.12` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.25` | `8.5.28` |\n| [postcss-safe-parser](https://github.com/postcss/postcss-safe-parser) | `7.0.1` | `7.1.0` |\n| [readdirp](https://github.com/paulmillr/readdirp) | `5.0.0` | `5.1.1` |\n| [socks](https://github.com/JoshGlazebrook/socks) | `2.8.9` | `2.8.10` |\n| [tldts](https://github.com/remusao/tldts) | `7.4.10` | `7.4.12` |\n| [undici](https://github.com/nodejs/undici) | `8.9.0` | `8.10.2` |\n| [ws](https://github.com/websockets/ws) | `8.21.1` | `8.21.3` |\n\n\nUpdates `@types/node` from 26.4.1 to 26.5.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@asamuzakjp/css-color` from 6.0.5 to 6.0.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/asamuzaK/cssColor/releases\"\u003e@​asamuzakjp/css-color's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.0.7\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd sortMathFnTerms function by \u003ca href=\"https://github.com/asamuzaK\"\u003e\u003ccode\u003e@​asamuzaK\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/asamuzaK/cssColor/pull/118\"\u003easamuzaK/cssColor#118\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/asamuzaK/cssColor/compare/v6.0.6...v6.0.7\"\u003ehttps://github.com/asamuzaK/cssColor/compare/v6.0.6...v6.0.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.0.6\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix min/max functions in calc expressions by \u003ca href=\"https://github.com/asamuzaK\"\u003e\u003ccode\u003e@​asamuzaK\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/asamuzaK/cssColor/pull/116\"\u003easamuzaK/cssColor#116\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix math() functions and sort calc() args by \u003ca href=\"https://github.com/asamuzaK\"\u003e\u003ccode\u003e@​asamuzaK\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/asamuzaK/cssColor/pull/117\"\u003easamuzaK/cssColor#117\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/asamuzaK/cssColor/compare/v6.0.5...v6.0.6\"\u003ehttps://github.com/asamuzaK/cssColor/compare/v6.0.5...v6.0.6\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/cssColor/commit/e637b110301d5d8c869b5d2ad15bc31d8fe8103c\"\u003e\u003ccode\u003ee637b11\u003c/code\u003e\u003c/a\u003e v6.0.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/cssColor/commit/4d849a149334fad12fe88214f2de3d2e72e42c4d\"\u003e\u003ccode\u003e4d849a1\u003c/code\u003e\u003c/a\u003e Add sortMathFnTerms function (\u003ca href=\"https://redirect.github.com/asamuzaK/cssColor/issues/118\"\u003e#118\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/cssColor/commit/87ce8ae21ab081611427752e0e7e2c18c6f3b778\"\u003e\u003ccode\u003e87ce8ae\u003c/code\u003e\u003c/a\u003e v6.0.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/cssColor/commit/45df517257c3a4f6b36f1a0e83c395b8b85843f1\"\u003e\u003ccode\u003e45df517\u003c/code\u003e\u003c/a\u003e Fix math-function detection\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/cssColor/commit/0d521956ec0225435e9a53b0507b1b942b31e1a3\"\u003e\u003ccode\u003e0d52195\u003c/code\u003e\u003c/a\u003e Fix math() functions and sort calc() args (\u003ca href=\"https://redirect.github.com/asamuzaK/cssColor/issues/117\"\u003e#117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/cssColor/commit/5df35737f31d337f2433663cab54299c366c69d9\"\u003e\u003ccode\u003e5df3573\u003c/code\u003e\u003c/a\u003e Fix min/max functions in calc expressions (\u003ca href=\"https://redirect.github.com/asamuzaK/cssColor/issues/116\"\u003e#116\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/cssColor/commit/d1e11135df8e5f15d19375b1503611a705361544\"\u003e\u003ccode\u003ed1e1113\u003c/code\u003e\u003c/a\u003e Update dependencies and devDependencies\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/asamuzaK/cssColor/compare/v6.0.5...v6.0.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@asamuzakjp/dom-selector` from 8.3.0 to 8.3.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/asamuzaK/domSelector/releases\"\u003e@​asamuzakjp/dom-selector's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.3.2\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/asamuzaK/domSelector/compare/v8.3.1...v8.3.2\"\u003ehttps://github.com/asamuzaK/domSelector/compare/v8.3.1...v8.3.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev8.3.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/asamuzaK/domSelector/compare/v8.3.0...v8.3.1\"\u003ehttps://github.com/asamuzaK/domSelector/compare/v8.3.0...v8.3.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/domSelector/commit/3a8c5e0ecb2ac69c6ed600da73f819fd3a367902\"\u003e\u003ccode\u003e3a8c5e0\u003c/code\u003e\u003c/a\u003e v8.3.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/domSelector/commit/2780b0a0f3399351f4ddd2789f99b5337f454645\"\u003e\u003ccode\u003e2780b0a\u003c/code\u003e\u003c/a\u003e Match common attribute selectors in validation (\u003ca href=\"https://redirect.github.com/asamuzaK/domSelector/issues/301\"\u003e#301\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/domSelector/commit/3288d3b16ca54cdb9fa3d14c529a9657f9714ac5\"\u003e\u003ccode\u003e3288d3b\u003c/code\u003e\u003c/a\u003e v8.3.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/domSelector/commit/a52bf29317b180913225e0cba23ad57dbcb81b6d\"\u003e\u003ccode\u003ea52bf29\u003c/code\u003e\u003c/a\u003e Fix attribute selectors case-insensitivity (\u003ca href=\"https://redirect.github.com/asamuzaK/domSelector/issues/300\"\u003e#300\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/asamuzaK/domSelector/compare/v8.3.0...v8.3.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@babel/types` from 7.29.7 to 7.29.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/babel/babel/releases\"\u003e@​babel/types's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.8 (2026-07-31)\u003c/h2\u003e\n\u003ch4\u003e:eyeglasses: Spec Compliance\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e, \u003ccode\u003ebabel-parser\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-spread\u003c/code\u003e, \u003ccode\u003ebabel-traverse\u003c/code\u003e, \u003ccode\u003ebabel-types\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17871\"\u003e#17871\u003c/a\u003e Disallow super call after new (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18046\"\u003e#18046\u003c/a\u003e fix(generator): improve new callee parens check (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-node\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18044\"\u003e#18044\u003c/a\u003e fix(systemjs): support \u003ccode\u003e__proto__\u003c/code\u003e as an export name (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 2\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/5de11ca9234379b78ef95df72aebbec93f28bf45\"\u003e\u003ccode\u003e5de11ca\u003c/code\u003e\u003c/a\u003e v7.29.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/64c37e53529ba4a24ba1f074fdce3d439c6b29ba\"\u003e\u003ccode\u003e64c37e5\u003c/code\u003e\u003c/a\u003e Disallow super call after new (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-types/issues/17871\"\u003e#17871\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/babel/babel/commits/v7.29.8/packages/babel-types\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@babel/parser` from 7.29.7 to 7.29.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/babel/babel/releases\"\u003e@​babel/parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.8 (2026-07-31)\u003c/h2\u003e\n\u003ch4\u003e:eyeglasses: Spec Compliance\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e, \u003ccode\u003ebabel-parser\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-spread\u003c/code\u003e, \u003ccode\u003ebabel-traverse\u003c/code\u003e, \u003ccode\u003ebabel-types\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17871\"\u003e#17871\u003c/a\u003e Disallow super call after new (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18046\"\u003e#18046\u003c/a\u003e fix(generator): improve new callee parens check (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-node\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18044\"\u003e#18044\u003c/a\u003e fix(systemjs): support \u003ccode\u003e__proto__\u003c/code\u003e as an export name (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 2\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/5de11ca9234379b78ef95df72aebbec93f28bf45\"\u003e\u003ccode\u003e5de11ca\u003c/code\u003e\u003c/a\u003e v7.29.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/64c37e53529ba4a24ba1f074fdce3d439c6b29ba\"\u003e\u003ccode\u003e64c37e5\u003c/code\u003e\u003c/a\u003e Disallow super call after new (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-parser/issues/17871\"\u003e#17871\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/babel/babel/commits/v7.29.8/packages/babel-parser\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@csstools/color-helpers` from 6.1.0 to 6.1.1\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/csstools/postcss-plugins/blob/main/packages/color-helpers/CHANGELOG.md\"\u003e@​csstools/color-helpers's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch3\u003e6.1.1\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eAugust 15, 2026\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated: gamut mapping algorithm\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/csstools/postcss-plugins/commits/HEAD/packages/color-helpers\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@csstools/css-color-parser` from 4.1.10 to 4.2.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/csstools/postcss-plugins/blob/main/packages/css-color-parser/CHANGELOG.md\"\u003e@​csstools/css-color-parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch3\u003e4.2.2\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eAugust 30, 2026\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eNormalize hue in \u003ccode\u003ecomputedValue()\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e4.2.1\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eAugust 25, 2026\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve powerless hue in \u003ccode\u003ecolor-mix()\u003c/code\u003e when the input color space equals the interpolation color space, matching relative color syntax.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e4.2.0\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eAugust 15, 2026\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003ecomputedValue()\u003c/code\u003e serialization function for color data.\u003c/li\u003e\n\u003cli\u003eMandatory \u003ccode\u003ealpha\u003c/code\u003e in the relative \u003ccode\u003ealpha()\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eUpdated \u003ca href=\"https://github.com/csstools/postcss-plugins/tree/main/packages/color-helpers\"\u003e\u003ccode\u003e@csstools/color-helpers\u003c/code\u003e\u003c/a\u003e to \u003ca href=\"https://github.com/csstools/postcss-plugins/tree/main/packages/color-helpers/CHANGELOG.md#611\"\u003e\u003ccode\u003e6.1.1\u003c/code\u003e\u003c/a\u003e (patch)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/csstools/postcss-plugins/commits/HEAD/packages/css-color-parser\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@csstools/css-syntax-patches-for-csstree` from 1.1.7 to 1.1.13\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/csstools/postcss-plugins/blob/main/packages/css-syntax-patches-for-csstree/CHANGELOG.md\"\u003e@​csstools/css-syntax-patches-for-csstree's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch3\u003e1.1.13\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eSeptember 10, 2026\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@webref/css\u003c/code\u003e to \u003ca href=\"https://github.com/w3c/webref/releases/tag/%40webref%2Fcss%408.7.4\"\u003e\u003ccode\u003ev8.7.4\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e1.1.12\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eAugust 31, 2026\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003e@import\u003c/code\u003e prelude syntax definition\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e1.1.11\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eAugust 31, 2026\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd at-rule preludes\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e1.1.10\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eAugust 30, 2026\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@webref/css\u003c/code\u003e to \u003ca href=\"https://github.com/w3c/webref/releases/tag/%40webref%2Fcss%408.7.3\"\u003e\u003ccode\u003ev8.7.3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e1.1.9\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eAugust 25, 2026\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@webref/css\u003c/code\u003e to \u003ca href=\"https://github.com/w3c/webref/releases/tag/%40webref%2Fcss%408.7.2\"\u003e\u003ccode\u003ev8.7.2\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e1.1.8\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eAugust 15, 2026\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@webref/css\u003c/code\u003e to \u003ca href=\"https://github.com/w3c/webref/releases/tag/%40webref%2Fcss%408.7.1\"\u003e\u003ccode\u003ev8.7.1\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/csstools/postcss-plugins/commits/HEAD/packages/css-syntax-patches-for-csstree\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/ansi` from 2.0.7 to 2.0.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/ansi's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/figures\u003c/code\u003e\u003ca href=\"https://github.com/2\"\u003e\u003ccode\u003e@​2\u003c/code\u003e\u003c/a\u003e.0.8\u003c/h2\u003e\n\u003cp\u003eNo source changes. Bumped to keep in lockstep with the \u003ccode\u003e@inquirer/*\u003c/code\u003e release train.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/5748bd9966b5e175ddf5995ee4cdce6f60c4272e\"\u003e\u003ccode\u003e5748bd9\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/269ae73ca9dd7ac738cd35f7d0222b3522021ad9\"\u003e\u003ccode\u003e269ae73\u003c/code\u003e\u003c/a\u003e fix: pin \u003ccode\u003e@​inquirer/type\u003c/code\u003e exactly in published manifests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/927d6dda59aacf8c4088d43df68da5062757cd6d\"\u003e\u003ccode\u003e927d6dd\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/testing\u003c/code\u003e): keep keypress simulation working under TERM=dumb\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2d813b145b9ce2a531d7ba6eafb8f7451594b004\"\u003e\u003ccode\u003e2d813b1\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.6 to 0.16.8 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2245\"\u003e#2245\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7affbc9bef22adcb059325c7e8450e3da64bd6fa\"\u003e\u003ccode\u003e7affbc9\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump turbo from 2.10.9 to 2.10.11 in the build group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2243\"\u003e#2243\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/56db98993c3c5c55864e5b1b7f458b1bb9c59e65\"\u003e\u003ccode\u003e56db989\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2242\"\u003e#2242\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8e6bc3cec6b88bbd08ff49b0f01fc5dabc5f6bb2\"\u003e\u003ccode\u003e8e6bc3c\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 2 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2241\"\u003e#2241\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/427b7a1f55d1947dd6876ce026706ae2369db313\"\u003e\u003ccode\u003e427b7a1\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the testing group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2240\"\u003e#2240\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/51ac389603405e8f9f315ce49416153d95c5fefe\"\u003e\u003ccode\u003e51ac389\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0f1718e9db1a129ad07c61a0d530f00dc4362740\"\u003e\u003ccode\u003e0f1718e\u003c/code\u003e\u003c/a\u003e feat(\u003ccode\u003e@​inquirer/password\u003c/code\u003e): add ctrl+t toggle to reveal password\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/ansi@2.0.7...@inquirer/ansi@2.0.8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/ansi\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/checkbox` from 5.2.1 to 5.2.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/checkbox's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/checkbox\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.2.3\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.1\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/type\u003c/code\u003e bumped to \u003ccode\u003e^4.1.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/checkbox\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.2.2\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.0\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/figures\u003c/code\u003e bumped to \u003ccode\u003e^2.0.8\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/cbdb34bfc6c245941d80ef88493c50b3d6dbfce6\"\u003e\u003ccode\u003ecbdb34b\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8340d2dd764d4b11d4e200412b614f9964ae0691\"\u003e\u003ccode\u003e8340d2d\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): clear hook effects before settling prompts\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2475e07186d824d52504095c71c2272d9e7338fe\"\u003e\u003ccode\u003e2475e07\u003c/code\u003e\u003c/a\u003e test(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): cover hook cleanup error semantics\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/15cd8d3b53bfc270633072073c24d6be6ce3d83b\"\u003e\u003ccode\u003e15cd8d3\u003c/code\u003e\u003c/a\u003e fix(confirm): ignore surrounding whitespace in answers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/9cb0da6c187346c955ab0b788fa1a88c897f16da\"\u003e\u003ccode\u003e9cb0da6\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/1c750bc55ab4fac310d70db84a7a6ada76c0e854\"\u003e\u003ccode\u003e1c750bc\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the build group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2251\"\u003e#2251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/81f1525110990603e9796d48eecde0f8c2d2fc98\"\u003e\u003ccode\u003e81f1525\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump \u003ccode\u003e@​types/node\u003c/code\u003e in the types group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2252\"\u003e#2252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7c27f26606a16b6e8f55b51e4431c72658c674c5\"\u003e\u003ccode\u003e7c27f26\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2249\"\u003e#2249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/6119088a4e07ec59460c3cd44d06817de97bfdac\"\u003e\u003ccode\u003e6119088\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2250\"\u003e#2250\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0d167c0aface3f5cf95132ada9bfec7946dd5b74\"\u003e\u003ccode\u003e0d167c0\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 4 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2248\"\u003e#2248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/checkbox@5.2.1...@inquirer/checkbox@5.2.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/checkbox\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/editor` from 5.2.2 to 5.3.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/editor's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/editor\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.3.1\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.1\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/type\u003c/code\u003e bumped to \u003ccode\u003e^4.1.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/editor\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.3.0\u003c/h2\u003e\n\u003ch3\u003eWhat's fixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAccept explicit \u003ccode\u003eundefined\u003c/code\u003e as the default value (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/pull/2182\"\u003e#2182\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.0\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/external-editor\u003c/code\u003e bumped to \u003ccode\u003e^3.0.4\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/cbdb34bfc6c245941d80ef88493c50b3d6dbfce6\"\u003e\u003ccode\u003ecbdb34b\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8340d2dd764d4b11d4e200412b614f9964ae0691\"\u003e\u003ccode\u003e8340d2d\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): clear hook effects before settling prompts\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2475e07186d824d52504095c71c2272d9e7338fe\"\u003e\u003ccode\u003e2475e07\u003c/code\u003e\u003c/a\u003e test(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): cover hook cleanup error semantics\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/15cd8d3b53bfc270633072073c24d6be6ce3d83b\"\u003e\u003ccode\u003e15cd8d3\u003c/code\u003e\u003c/a\u003e fix(confirm): ignore surrounding whitespace in answers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/9cb0da6c187346c955ab0b788fa1a88c897f16da\"\u003e\u003ccode\u003e9cb0da6\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/1c750bc55ab4fac310d70db84a7a6ada76c0e854\"\u003e\u003ccode\u003e1c750bc\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the build group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2251\"\u003e#2251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/81f1525110990603e9796d48eecde0f8c2d2fc98\"\u003e\u003ccode\u003e81f1525\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump \u003ccode\u003e@​types/node\u003c/code\u003e in the types group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2252\"\u003e#2252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7c27f26606a16b6e8f55b51e4431c72658c674c5\"\u003e\u003ccode\u003e7c27f26\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2249\"\u003e#2249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/6119088a4e07ec59460c3cd44d06817de97bfdac\"\u003e\u003ccode\u003e6119088\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2250\"\u003e#2250\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0d167c0aface3f5cf95132ada9bfec7946dd5b74\"\u003e\u003ccode\u003e0d167c0\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 4 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2248\"\u003e#2248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/editor@5.2.2...@inquirer/editor@5.3.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/editor\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/expand` from 5.1.1 to 5.1.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/expand's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/expand\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.1.3\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.1\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/type\u003c/code\u003e bumped to \u003ccode\u003e^4.1.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/expand\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.1.2\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/cbdb34bfc6c245941d80ef88493c50b3d6dbfce6\"\u003e\u003ccode\u003ecbdb34b\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8340d2dd764d4b11d4e200412b614f9964ae0691\"\u003e\u003ccode\u003e8340d2d\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): clear hook effects before settling prompts\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2475e07186d824d52504095c71c2272d9e7338fe\"\u003e\u003ccode\u003e2475e07\u003c/code\u003e\u003c/a\u003e test(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): cover hook cleanup error semantics\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/15cd8d3b53bfc270633072073c24d6be6ce3d83b\"\u003e\u003ccode\u003e15cd8d3\u003c/code\u003e\u003c/a\u003e fix(confirm): ignore surrounding whitespace in answers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/9cb0da6c187346c955ab0b788fa1a88c897f16da\"\u003e\u003ccode\u003e9cb0da6\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/1c750bc55ab4fac310d70db84a7a6ada76c0e854\"\u003e\u003ccode\u003e1c750bc\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the build group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2251\"\u003e#2251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/81f1525110990603e9796d48eecde0f8c2d2fc98\"\u003e\u003ccode\u003e81f1525\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump \u003ccode\u003e@​types/node\u003c/code\u003e in the types group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2252\"\u003e#2252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7c27f26606a16b6e8f55b51e4431c72658c674c5\"\u003e\u003ccode\u003e7c27f26\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2249\"\u003e#2249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/6119088a4e07ec59460c3cd44d06817de97bfdac\"\u003e\u003ccode\u003e6119088\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2250\"\u003e#2250\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0d167c0aface3f5cf95132ada9bfec7946dd5b74\"\u003e\u003ccode\u003e0d167c0\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 4 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2248\"\u003e#2248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/expand@5.1.1...@inquirer/expand@5.1.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/expand\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/external-editor` from 3.0.3 to 3.0.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/external-editor's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/external-editor\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.0.4\u003c/h2\u003e\n\u003cp\u003eNo source changes. Bumped to keep in lockstep with the \u003ccode\u003e@inquirer/*\u003c/code\u003e release train.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/5748bd9966b5e175ddf5995ee4cdce6f60c4272e\"\u003e\u003ccode\u003e5748bd9\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/269ae73ca9dd7ac738cd35f7d0222b3522021ad9\"\u003e\u003ccode\u003e269ae73\u003c/code\u003e\u003c/a\u003e fix: pin \u003ccode\u003e@​inquirer/type\u003c/code\u003e exactly in published manifests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/927d6dda59aacf8c4088d43df68da5062757cd6d\"\u003e\u003ccode\u003e927d6dd\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/testing\u003c/code\u003e): keep keypress simulation working under TERM=dumb\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2d813b145b9ce2a531d7ba6eafb8f7451594b004\"\u003e\u003ccode\u003e2d813b1\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.6 to 0.16.8 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2245\"\u003e#2245\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7affbc9bef22adcb059325c7e8450e3da64bd6fa\"\u003e\u003ccode\u003e7affbc9\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump turbo from 2.10.9 to 2.10.11 in the build group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2243\"\u003e#2243\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/56db98993c3c5c55864e5b1b7f458b1bb9c59e65\"\u003e\u003ccode\u003e56db989\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2242\"\u003e#2242\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8e6bc3cec6b88bbd08ff49b0f01fc5dabc5f6bb2\"\u003e\u003ccode\u003e8e6bc3c\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 2 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2241\"\u003e#2241\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/427b7a1f55d1947dd6876ce026706ae2369db313\"\u003e\u003ccode\u003e427b7a1\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the testing group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2240\"\u003e#2240\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/51ac389603405e8f9f315ce49416153d95c5fefe\"\u003e\u003ccode\u003e51ac389\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0f1718e9db1a129ad07c61a0d530f00dc4362740\"\u003e\u003ccode\u003e0f1718e\u003c/code\u003e\u003c/a\u003e feat(\u003ccode\u003e@​inquirer/password\u003c/code\u003e): add ctrl+t toggle to reveal password\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/external-editor@3.0.3...@inquirer/external-editor@3.0.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/external-editor\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/figures` from 2.0.7 to 2.0.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/figures's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/figures\u003c/code\u003e\u003ca href=\"https://github.com/2\"\u003e\u003ccode\u003e@​2\u003c/code\u003e\u003c/a\u003e.0.8\u003c/h2\u003e\n\u003cp\u003eNo source changes. Bumped to keep in lockstep with the \u003ccode\u003e@inquirer/*\u003c/code\u003e release train.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/5748bd9966b5e175ddf5995ee4cdce6f60c4272e\"\u003e\u003ccode\u003e5748bd9\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/269ae73ca9dd7ac738cd35f7d0222b3522021ad9\"\u003e\u003ccode\u003e269ae73\u003c/code\u003e\u003c/a\u003e fix: pin \u003ccode\u003e@​inquirer/type\u003c/code\u003e exactly in published manifests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/927d6dda59aacf8c4088d43df68da5062757cd6d\"\u003e\u003ccode\u003e927d6dd\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/testing\u003c/code\u003e): keep keypress simulation working under TERM=dumb\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2d813b145b9ce2a531d7ba6eafb8f7451594b004\"\u003e\u003ccode\u003e2d813b1\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.6 to 0.16.8 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2245\"\u003e#2245\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7affbc9bef22adcb059325c7e8450e3da64bd6fa\"\u003e\u003ccode\u003e7affbc9\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump turbo from 2.10.9 to 2.10.11 in the build group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2243\"\u003e#2243\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/56db98993c3c5c55864e5b1b7f458b1bb9c59e65\"\u003e\u003ccode\u003e56db989\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2242\"\u003e#2242\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8e6bc3cec6b88bbd08ff49b0f01fc5dabc5f6bb2\"\u003e\u003ccode\u003e8e6bc3c\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 2 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2241\"\u003e#2241\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/427b7a1f55d1947dd6876ce026706ae2369db313\"\u003e\u003ccode\u003e427b7a1\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the testing group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2240\"\u003e#2240\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/51ac389603405e8f9f315ce49416153d95c5fefe\"\u003e\u003ccode\u003e51ac389\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0f1718e9db1a129ad07c61a0d530f00dc4362740\"\u003e\u003ccode\u003e0f1718e\u003c/code\u003e\u003c/a\u003e feat(\u003ccode\u003e@​inquirer/password\u003c/code\u003e): add ctrl+t toggle to reveal password\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/figures@2.0.7...@inquirer/figures@2.0.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/figures\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/input` from 5.1.2 to 5.1.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/input's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/input\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.1.4\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.1\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/type\u003c/code\u003e bumped to \u003ccode\u003e^4.1.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/input\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.1.3\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/cbdb34bfc6c245941d80ef88493c50b3d6dbfce6\"\u003e\u003ccode\u003ecbdb34b\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8340d2dd764d4b11d4e200412b614f9964ae0691\"\u003e\u003ccode\u003e8340d2d\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): clear hook effects before settling prompts\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2475e07186d824d52504095c71c2272d9e7338fe\"\u003e\u003ccode\u003e2475e07\u003c/code\u003e\u003c/a\u003e test(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): cover hook cleanup error semantics\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/15cd8d3b53bfc270633072073c24d6be6ce3d83b\"\u003e\u003ccode\u003e15cd8d3\u003c/code\u003e\u003c/a\u003e fix(confirm): ignore surrounding whitespace in answers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/9cb0da6c187346c955ab0b788fa1a88c897f16da\"\u003e\u003ccode\u003e9cb0da6\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/1c750bc55ab4fac310d70db84a7a6ada76c0e854\"\u003e\u003ccode\u003e1c750bc\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the build group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2251\"\u003e#2251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/81f1525110990603e9796d48eecde0f8c2d2fc98\"\u003e\u003ccode\u003e81f1525\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump \u003ccode\u003e@​types/node\u003c/code\u003e in the types group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2252\"\u003e#2252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7c27f26606a16b6e8f55b51e4431c72658c674c5\"\u003e\u003ccode\u003e7c27f26\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2249\"\u003e#2249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/6119088a4e07ec59460c3cd44d06817de97bfdac\"\u003e\u003ccode\u003e6119088\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2250\"\u003e#2250\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0d167c0aface3f5cf95132ada9bfec7946dd5b74\"\u003e\u003ccode\u003e0d167c0\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 4 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2248\"\u003e#2248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/input@5.1.2...@inquirer/input@5.1.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/input\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/number` from 4.1.1 to 4.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/number's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/number\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.2.1\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.1\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/type\u003c/code\u003e bumped to \u003ccode\u003e^4.1.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/number\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.2.0\u003c/h2\u003e\n\u003ch3\u003eWhat's fixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid floating-point step errors by scaling value/step/min to exact decimal integers before the remainder check (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/pull/2166\"\u003e#2166\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAccept explicit \u003ccode\u003eundefined\u003c/code\u003e as the default value (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/pull/2182\"\u003e#2182\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/cbdb34bfc6c245941d80ef88493c50b3d6dbfce6\"\u003e\u003ccode\u003ecbdb34b\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8340d2dd764d4b11d4e200412b614f9964ae0691\"\u003e\u003ccode\u003e8340d2d\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): clear hook effects before settling prompts\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2475e07186d824d52504095c71c2272d9e7338fe\"\u003e\u003ccode\u003e2475e07\u003c/code\u003e\u003c/a\u003e test(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): cover hook cleanup error semantics\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/15cd8d3b53bfc270633072073c24d6be6ce3d83b\"\u003e\u003ccode\u003e15cd8d3\u003c/code\u003e\u003c/a\u003e fix(confirm): ignore surrounding whitespace in answers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/9cb0da6c187346c955ab0b788fa1a88c897f16da\"\u003e\u003ccode\u003e9cb0da6\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/1c750bc55ab4fac310d70db84a7a6ada76c0e854\"\u003e\u003ccode\u003e1c750bc\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the build group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2251\"\u003e#2251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/81f1525110990603e9796d48eecde0f8c2d2fc98\"\u003e\u003ccode\u003e81f1525\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump \u003ccode\u003e@​types/node\u003c/code\u003e in the types group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2252\"\u003e#2252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7c27f26606a16b6e8f55b51e4431c72658c674c5\"\u003e\u003ccode\u003e7c27f26\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2249\"\u003e#2249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/6119088a4e07ec59460c3cd44d06817de97bfdac\"\u003e\u003ccode\u003e6119088\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2250\"\u003e#2250\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0d167c0aface3f5cf95132ada9bfec7946dd5b74\"\u003e\u003ccode\u003e0d167c0\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 4 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2248\"\u003e#2248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/number@4.1.1...@inquirer/number@4.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/number\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/password` from 5.1.1 to 5.2.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/password's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/password\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.2.0\u003c/h2\u003e\n\u003ch3\u003eWhat's new\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded a \u003ccode\u003etoggleMask\u003c/code\u003e option to temporarily reveal the typed value with \u003ccode\u003ectrl+t\u003c/code\u003e, with a themed, i18n-able help tip for discoverability. Defaults to \u003ccode\u003etrue\u003c/code\u003e; set to \u003ccode\u003efalse\u003c/code\u003e to disable both the shortcut and its help line.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.1\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/type\u003c/code\u003e bumped to \u003ccode\u003e^4.1.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/password\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.1.2\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/cbdb34bfc6c245941d80ef88493c50b3d6dbfce6\"\u003e\u003ccode\u003ecbdb34b\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8340d2dd764d4b11d4e200412b614f9964ae0691\"\u003e\u003ccode\u003e8340d2d\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): clear hook effects before settling prompts\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2475e07186d824d52504095c71c2272d9e7338fe\"\u003e\u003ccode\u003e2475e07\u003c/code\u003e\u003c/a\u003e test(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): cover hook cleanup error semantics\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/15cd8d3b53bfc270633072073c24d6be6ce3d83b\"\u003e\u003ccode\u003e15cd8d3\u003c/code\u003e\u003c/a\u003e fix(confirm): ignore surrounding whitespace in answers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/9cb0da6c187346c955ab0b788fa1a88c897f16da\"\u003e\u003ccode\u003e9cb0da6\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/1c750bc55ab4fac310d70db84a7a6ada76c0e854\"\u003e\u003ccode\u003e1c750bc\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the build group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2251\"\u003e#2251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/81f1525110990603e9796d48eecde0f8c2d2fc98\"\u003e\u003ccode\u003e81f1525\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump \u003ccode\u003e@​types/node\u003c/code\u003e in the types group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2252\"\u003e#2252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7c27f26606a16b6e8f55b51e4431c72658c674c5\"\u003e\u003ccode\u003e7c27f26\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2249\"\u003e#2249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/6119088a4e07ec59460c3cd44d06817de97bfdac\"\u003e\u003ccode\u003e6119088\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2250\"\u003e#2250\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0d167c0aface3f5cf95132ada9bfec7946dd5b74\"\u003e\u003ccode\u003e0d167c0\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 4 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2248\"\u003e#2248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/password@5.1.1...@inquirer/password@5.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/password\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/rawlist` from 5.3.1 to 5.3.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/rawlist's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/rawlist\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.3.3\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.1\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/type\u003c/code\u003e bumped to \u003ccode\u003e^4.1.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/rawlist\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.3.2\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/cbdb34bfc6c245941d80ef88493c50b3d6dbfce6\"\u003e\u003ccode\u003ecbdb34b\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8340d2dd764d4b11d4e200412b614f9964ae0691\"\u003e\u003ccode\u003e8340d2d\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): clear hook effects before settling prompts\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2475e07186d824d52504095c71c2272d9e7338fe\"\u003e\u003ccode\u003e2475e07\u003c/code\u003e\u003c/a\u003e test(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): cover hook cleanup error semantics\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/15cd8d3b53bfc270633072073c24d6be6ce3d83b\"\u003e\u003ccode\u003e15cd8d3\u003c/code\u003e\u003c/a\u003e fix(confirm): ignore surrounding whitespace in answers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/9cb0da6c187346c955ab0b788fa1a88c897f16da\"\u003e\u003ccode\u003e9cb0da6\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/1c750bc55ab4fac310d70db84a7a6ada76c0e854\"\u003e\u003ccode\u003e1c750bc\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the build group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2251\"\u003e#2251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/81f1525110990603e9796d48eecde0f8c2d2fc98\"\u003e\u003ccode\u003e81f1525\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump \u003ccode\u003e@​types/node\u003c/code\u003e in the types group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2252\"\u003e#2252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7c27f26606a16b6e8f55b51e4431c72658c674c5\"\u003e\u003ccode\u003e7c27f26\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2249\"\u003e#2249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/6119088a4e07ec59460c3cd44d06817de97bfdac\"\u003e\u003ccode\u003e6119088\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2250\"\u003e#2250\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0d167c0aface3f5cf95132ada9bfec7946dd5b74\"\u003e\u003ccode\u003e0d167c0\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 4 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2248\"\u003e#2248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/rawlist@5.3.1...@inquirer/rawlist@5.3.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/rawlist\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/search` from 4.2.1 to 4.3.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/search's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/search\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.3.1\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.1\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/type\u003c/code\u003e bumped to \u003ccode\u003e^4.1.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/search\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.3.0\u003c/h2\u003e\n\u003ch3\u003eWhat's new\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eNew \u003ccode\u003einitialValue?: string\u003c/code\u003e option to pre-fill the search input (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/pull/2205\"\u003e#2205\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.0\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/figures\u003c/code\u003e bumped to \u003ccode\u003e^2.0.8\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/cbdb34bfc6c245941d80ef88493c50b3d6dbfce6\"\u003e\u003ccode\u003ecbdb34b\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8340d2dd764d4b11d4e200412b614f9964ae0691\"\u003e\u003ccode\u003e8340d2d\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): clear hook effects before settling prompts\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2475e07186d824d52504095c71c2272d9e7338fe\"\u003e\u003ccode\u003e2475e07\u003c/code\u003e\u003c/a\u003e test(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): cover hook cleanup error semantics\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/15cd8d3b53bfc270633072073c24d6be6ce3d83b\"\u003e\u003ccode\u003e15cd8d3\u003c/code\u003e\u003c/a\u003e fix(confirm): ignore surrounding whitespace in answers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/9cb0da6c187346c955ab0b788fa1a88c897f16da\"\u003e\u003ccode\u003e9cb0da6\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/1c750bc55ab4fac310d70db84a7a6ada76c0e854\"\u003e\u003ccode\u003e1c750bc\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the build group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2251\"\u003e#2251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/81f1525110990603e9796d48eecde0f8c2d2fc98\"\u003e\u003ccode\u003e81f1525\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump \u003ccode\u003e@​types/node\u003c/code\u003e in the types group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2252\"\u003e#2252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7c27f26606a16b6e8f55b51e4431c72658c674c5\"\u003e\u003ccode\u003e7c27f26\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2249\"\u003e#2249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/6119088a4e07ec59460c3cd44d06817de97bfdac\"\u003e\u003ccode\u003e6119088\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2250\"\u003e#2250\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0d167c0aface3f5cf95132ada9bfec7946dd5b74\"\u003e\u003ccode\u003e0d167c0\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 4 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2248\"\u003e#2248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/search@4.2.1...@inquirer/search@4.3.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/search\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/select` from 5.2.1 to 5.2.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/select's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/select\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.2.3\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.1\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/type\u003c/code\u003e bumped to \u003ccode\u003e^4.1.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/select\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.2.2\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.0\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/figures\u003c/code\u003e bumped to \u003ccode\u003e^2.0.8\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/cbdb34bfc6c245941d80ef88493c50b3d6dbfce6\"\u003e\u003ccode\u003ecbdb34b\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8340d2dd764d4b11d4e200412b614f9964ae0691\"\u003e\u003ccode\u003e8340d2d\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): clear hook effects before settling prompts\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2475e07186d824d52504095c71c2272d9e7338fe\"\u003e\u003ccode\u003e2475e07\u003c/code\u003e\u003c/a\u003e test(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): cover hook cleanup error semantics\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/15cd8d3b53bfc270633072073c24d6be6ce3d83b\"\u003e\u003ccode\u003e15cd8d3\u003c/code\u003e\u003c/a\u003e fix(confirm): ignore surrounding whitespace in answers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/9cb0da6c187346c955ab0b788fa1a88c897f16da\"\u003e\u003ccode\u003e9cb0da6\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/1c750bc55ab4fac310d70db84a7a6ada76c0e854\"\u003e\u003ccode\u003e1c750bc\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the build group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2251\"\u003e#2251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/81f1525110990603e9796d48eecde0f8c2d2fc98\"\u003e\u003ccode\u003e81f1525\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump \u003ccode\u003e@​types/node\u003c/code\u003e in the types group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2252\"\u003e#2252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7c27f26606a16b6e8f55b51e4431c72658c674c5\"\u003e\u003ccode\u003e7c27f26\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2249\"\u003e#2249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/6119088a4e07ec59460c3cd44d06817de97bfdac\"\u003e\u003ccode\u003e6119088\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2250\"\u003e#2250\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0d167c0aface3f5cf95132ada9bfec7946dd5b74\"\u003e\u003ccode\u003e0d167c0\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 4 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2248\"\u003e#2248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/select@5.2.1...@inquirer/select@5.2.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/select\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/type` from 4.0.7 to 4.1.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/type's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/type\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.1.0\u003c/h2\u003e\n\u003ch3\u003eWhat's new\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ePrettify\u003c/code\u003e is now recursive, so \u003ccode\u003emakeTheme\u003c/code\u003e returns a fully flattened theme type (nested style intersections merged into one object) for better IDE display (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/pull/2239\"\u003e#2239\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/5748bd9966b5e175ddf5995ee4cdce6f60c4272e\"\u003e\u003ccode\u003e5748bd9\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/269ae73ca9dd7ac738cd35f7d0222b3522021ad9\"\u003e\u003ccode\u003e269ae73\u003c/code\u003e\u003c/a\u003e fix: pin \u003ccode\u003e@​inquirer/type\u003c/code\u003e exactly in published manifests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/927d6dda59aacf8c4088d43df68da5062757cd6d\"\u003e\u003ccode\u003e927d6dd\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/testing\u003c/code\u003e): keep keypress simulation working under TERM=dumb\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2d813b145b9ce2a531d7ba6eafb8f7451594b004\"\u003e\u003ccode\u003e2d813b1\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.6 to 0.16.8 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2245\"\u003e#2245\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7affbc9bef22adcb059325c7e8450e3da64bd6fa\"\u003e\u003ccode\u003e7affbc9\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump turbo from 2.10.9 to 2.10.11 in the build group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2243\"\u003e#2243\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/56db98993c3c5c55864e5b1b7f458b1bb9c59e65\"\u003e\u003ccode\u003e56db989\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2242\"\u003e#2242\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8e6bc3cec6b88bbd08ff49b0f01fc5dabc5f6bb2\"\u003e\u003ccode\u003e8e6bc3c\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 2 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2241\"\u003e#2241\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/427b7a1f55d1947dd6876ce026706ae2369db313\"\u003e\u003ccode\u003e427b7a1\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the testing group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2240\"\u003e#2240\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/51ac389603405e8f9f315ce49416153d95c5fefe\"\u003e\u003ccode\u003e51ac389\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0f1718e9db1a129ad07c61a0d530f00dc4362740\"\u003e\u003ccode\u003e0f1718e\u003c/code\u003e\u003c/a\u003e feat(\u003ccode\u003e@​inquirer/password\u003c/code\u003e): add ctrl+t toggle to reveal password\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/type@4.0.7...@inquirer/type@4.1.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/type\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@jridgewell/sourcemap-codec` from 1.5.5 to 1.6.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jridgewell/sourcemaps/blob/main/packages/sourcemap-codec/CHANGELOG.md\"\u003e@​jridgewell/sourcemap-codec's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e[1.6.0] - 2026-08-27\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Range Mapping support: \u003ca href=\"https://github.com/jridgewell/sourcemaps/tree/HEAD/packages/sourcemap-codec/issues/45\"\u003e#45\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003eincludes new \u003ccode\u003edecodeRangeMappings\u003c/code\u003e and \u003ccode\u003eencodeRangeMappings\u003c/code\u003e APIs\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/jridgewell/sourcemaps/compare/sourcemap-codec/1.5.5...sourcemap-codec/1.6.0\"\u003ehttps://github.com/jridgewell/sourcemaps/compare/sourcemap-codec/1.5.5...sourcemap-codec/1.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jridgewell/sourcemaps/commit/b7600158f4de012d246b7834a73c7c2190e75136\"\u003e\u003ccode\u003eb760015\u003c/code\u003e\u003c/a\u003e sourcemap-codec/1.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jridgewell/sourcemaps/commit/8aec72939113eff31a4fed37b7f78a19c81ddcd3\"\u003e\u003ccode\u003e8aec729\u003c/code\u003e\u003c/a\u003e Ignore map files during ripgrepping\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jridgewell/sourcemaps/commit/6566f0c3c8c0dcdbd93655e5b82e990d48c77606\"\u003e\u003ccode\u003e6566f0c\u003c/code\u003e\u003c/a\u003e Range mappings: update encoding to latest\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jridgewell/sourcemaps/commit/e5d58e6611a03a84ca64e2dd0de5667d7716b877\"\u003e\u003ccode\u003ee5d58e6\u003c/code\u003e\u003c/a\u003e Improve mocha setup\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jridgewell/sourcemaps/commit/f34bc275de9b6947c1d7e90e0f106d2440675104\"\u003e\u003ccode\u003ef34bc27\u003c/code\u003e\u003c/a\u003e Changelogs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jridgewell/sourcemaps/commit/01a4f69b2582826f9476d7045272a5eab67133e6\"\u003e\u003ccode\u003e01a4f69\u003c/code\u003e\u003c/a\u003e Small clenaup\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jridgewell/sourcemaps/commit/6cbfce2cc8318fdc2f917d7e64833d0d7154deec\"\u003e\u003ccode\u003e6cbfce2\u003c/code\u003e\u003c/a\u003e Add test:watch commands\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jridgewell/sourcemaps/commit/f3cb43e91f830c8f46d2223dff494dcd075ec087\"\u003e\u003ccode\u003ef3cb43e\u003c/code\u003e\u003c/a\u003e Separate signing from encoding/decoding integers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jridgewell/sourcemaps/commit/b319fc0af756b0079e7a6735afd586f0d52c7736\"\u003e\u003ccode\u003eb319fc0\u003c/code\u003e\u003c/a\u003e Range mappings: add initial decoding/encoding support\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jridgewell/sourcemaps/commit/59f4045d1319138c521604f30b9f1e38947eb776\"\u003e\u003ccode\u003e59f4045\u003c/code\u003e\u003c/a\u003e Add unsigned VLQ encode/decode options\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/jridgewell/sourcemaps/commits/sourcemap-codec/1.6.0/packages/sourcemap-codec\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@nap...\n\n_Description has been truncated_","html_url":"https://github.com/alderichoarau/alderichoarau.github.io/pull/259","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/alderichoarau%2Falderichoarau.github.io/issues/259","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/259/packages"},{"uuid":"5422008605","node_id":"PR_kwDOUSOj0s8AAAABDHQosA","number":9,"state":"open","title":"Bump undici from 8.10.1 to 8.10.2","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T08:14:58.000Z","updated_at":"2026-09-11T08:15:04.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"undici","old_version":"8.10.1","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 8.10.1 to 8.10.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm\"\u003eGHSA-vp8m-p9jh-q5pm\u003c/a\u003e: cache and deduplication interceptors could use caller-controlled request metadata instead of the authoritative dispatcher origin, enabling cross-origin cache poisoning and data disclosure. Undici now derives interceptor identities from the dispatcher origin and bypasses origin-dependent interceptors when no authoritative origin exists. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/caf6194d3dae989b731ed87ab85f182befe5eb80\"\u003ecaf6194d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e8f5868fb\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e66e12816\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6\"\u003e4411a238\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/662d0ea671fe64139e79533c913fce412765e1d7\"\u003e662d0ea6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003ecb75bbb3\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e7aac7f12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003ee905b5b8\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e2be07bf9\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e6d583124\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e0160a719\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps-dev): bump undici from 6.27.0 to 6.28.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5653\"\u003enodejs/undici#5653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump jest from 30.4.2 to 30.5.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5750\"\u003enodejs/undici#5750\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/analyze from 4.37.3 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5752\"\u003enodejs/undici#5752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5754\"\u003enodejs/undici#5754\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(h2): cover stream reset with NGHTTP2_INTERNAL_ERROR by \u003ca href=\"https://github.com/zeexzeex\"\u003e\u003ccode\u003e@​zeexzeex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5725\"\u003enodejs/undici#5725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): reject invalid resumed responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5724\"\u003enodejs/undici#5724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: make stale-while-revalidate cache update test deterministic by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5722\"\u003enodejs/undici#5722\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid unbounded recursion in Set-Cookie attribute parser by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5757\"\u003enodejs/undici#5757\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: honor SOCKS5 connection timeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5733\"\u003enodejs/undici#5733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(eventsource): validate Last-Event-ID on reconnect by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5746\"\u003enodejs/undici#5746\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid duplicate release attempts by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5745\"\u003enodejs/undici#5745\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(cache): refetch when 304 adds vary fields by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5732\"\u003enodejs/undici#5732\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etypes: expose PendingInterceptor and PendingInterceptorsFormatter on the MockAgent namespace by \u003ca href=\"https://github.com/RaphaelFakhri\"\u003e\u003ccode\u003e@​RaphaelFakhri\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5721\"\u003enodejs/undici#5721\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(codeql): align CodeQL action versions to v4.37.9 by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5759\"\u003enodejs/undici#5759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5760\"\u003enodejs/undici#5760\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(proxy-agent): guard Proxy-Authorization in iterable header containers by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5758\"\u003enodejs/undici#5758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: name the parameters these two blocks describe by \u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): fail the connection on a non-200 h2 extended CONNECT response by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(node-fetch): re-enable the set-cookie header combining test by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5730\"\u003enodejs/undici#5730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward rawHeaders writes through RetryController by \u003ca href=\"https://github.com/official-burak\"\u003e\u003ccode\u003e@​official-burak\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5727\"\u003enodejs/undici#5727\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5738\"\u003enodejs/undici#5738\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/5e541e0b9df7563e5766bbd469fbfe383d9ae6ca\"\u003e\u003ccode\u003e5e541e0\u003c/code\u003e\u003c/a\u003e Bumped v8.10.2 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5771\"\u003e#5771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/eb04cc39954e63e9b46bdf824e6efad9fff2e7b5\"\u003e\u003ccode\u003eeb04cc3\u003c/code\u003e\u003c/a\u003e fix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5738\"\u003e#5738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003e\u003ccode\u003ee905b5b\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e\u003ccode\u003e0160a71\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e\u003ccode\u003e66e1281\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e\u003ccode\u003e7aac7f1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003e\u003ccode\u003ecb75bbb\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e\u003ccode\u003e6d58312\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e\u003ccode\u003e8f5868f\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e\u003ccode\u003e2be07bf\u003c/code\u003e\u003c/a\u003e fix(cache): reject unsafe method response caching\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v8.10.1...v8.10.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=8.10.1\u0026new-version=8.10.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/xcawh/rsshub/pull/9","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/xcawh%2Frsshub/issues/9","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/9/packages"},{"uuid":"5421718027","node_id":"PR_kwDOJUlaKM8AAAABDHB9pw","number":473,"state":"open","title":"chore(deps): bump the production-minor-patch group across 1 directory with 20 updates","user":"dependabot[bot]","labels":["dependencies","javascript","ai-fix-requested"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T07:40:51.000Z","updated_at":"2026-09-11T07:43:15.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"production-minor-patch","update_count":20,"packages":[{"name":"@fortedigital/nextjs-cache-handler","old_version":"3.2.0","new_version":"3.3.0","repository_url":"https://github.com/fortedigital/nextjs-cache-handler"},{"name":"@headlessui/react","old_version":"2.2.9","new_version":"2.2.10","repository_url":"https://github.com/tailwindlabs/headlessui"},{"name":"@sentry/nextjs","old_version":"10.32.0","new_version":"10.73.0","repository_url":"https://github.com/getsentry/sentry-javascript"},{"name":"@tailwindcss/forms","old_version":"0.5.10","new_version":"0.5.11","repository_url":"https://github.com/tailwindlabs/tailwindcss-forms"},{"name":"@tailwindcss/typography","old_version":"0.5.16","new_version":"0.5.20","repository_url":"https://github.com/tailwindlabs/tailwindcss-typography"},{"name":"autoprefixer","old_version":"10.4.21","new_version":"10.5.5","repository_url":"https://github.com/postcss/autoprefixer"},{"name":"date-fns","old_version":"4.1.0","new_version":"4.4.0","repository_url":"https://github.com/date-fns/date-fns"},{"name":"fast-xml-parser","old_version":"5.8.0","new_version":"5.11.1","repository_url":"https://github.com/NaturalIntelligence/fast-xml-parser"},{"name":"next","old_version":"16.2.6","new_version":"16.3.4","repository_url":"https://github.com/vercel/next.js"},{"name":"next-intl","old_version":"4.12.0","new_version":"4.14.2","repository_url":"https://github.com/amannn/next-intl"},{"name":"postcss","old_version":"8.5.16","new_version":"8.5.28","repository_url":"https://github.com/postcss/postcss"},{"name":"react","old_version":"19.2.4","new_version":"19.2.8","repository_url":"https://github.com/react/react"},{"name":"react-dom","old_version":"19.2.4","new_version":"19.2.8","repository_url":"https://github.com/react/react"},{"name":"react-select","old_version":"5.10.1","new_version":"5.10.2","repository_url":"https://github.com/JedWatson/react-select"},{"name":"react-share","old_version":"5.2.2","new_version":"5.3.0","repository_url":"https://github.com/nygardk/react-share"},{"name":"redis","old_version":"6.0.0","new_version":"6.2.1","repository_url":"https://github.com/redis/node-redis"},{"name":"sharp","old_version":"0.34.5","new_version":"0.35.4","repository_url":"https://github.com/lovell/sharp"},{"name":"swr","old_version":"2.3.4","new_version":"2.5.1","repository_url":"https://github.com/vercel/swr"},{"name":"undici","old_version":"8.6.0","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"},{"name":"zod","old_version":"3.24.3","new_version":"3.25.76","repository_url":"https://github.com/colinhacks/zod"}],"path":null,"ecosystem":"npm"},"body":"Bumps the production-minor-patch group with 20 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@fortedigital/nextjs-cache-handler](https://github.com/fortedigital/nextjs-cache-handler) | `3.2.0` | `3.3.0` |\n| [@headlessui/react](https://github.com/tailwindlabs/headlessui/tree/HEAD/packages/@headlessui-react) | `2.2.9` | `2.2.10` |\n| [@sentry/nextjs](https://github.com/getsentry/sentry-javascript) | `10.32.0` | `10.73.0` |\n| [@tailwindcss/forms](https://github.com/tailwindlabs/tailwindcss-forms) | `0.5.10` | `0.5.11` |\n| [@tailwindcss/typography](https://github.com/tailwindlabs/tailwindcss-typography) | `0.5.16` | `0.5.20` |\n| [autoprefixer](https://github.com/postcss/autoprefixer) | `10.4.21` | `10.5.5` |\n| [date-fns](https://github.com/date-fns/date-fns) | `4.1.0` | `4.4.0` |\n| [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) | `5.8.0` | `5.11.1` |\n| [next](https://github.com/vercel/next.js) | `16.2.6` | `16.3.4` |\n| [next-intl](https://github.com/amannn/next-intl) | `4.12.0` | `4.14.2` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.16` | `8.5.28` |\n| [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.4` | `19.2.8` |\n| [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) | `19.2.4` | `19.2.8` |\n| [react-select](https://github.com/JedWatson/react-select) | `5.10.1` | `5.10.2` |\n| [react-share](https://github.com/nygardk/react-share) | `5.2.2` | `5.3.0` |\n| [redis](https://github.com/redis/node-redis) | `6.0.0` | `6.2.1` |\n| [sharp](https://github.com/lovell/sharp) | `0.34.5` | `0.35.4` |\n| [swr](https://github.com/vercel/swr) | `2.3.4` | `2.5.1` |\n| [undici](https://github.com/nodejs/undici) | `8.6.0` | `8.10.2` |\n| [zod](https://github.com/colinhacks/zod) | `3.24.3` | `3.25.76` |\n\n\nUpdates `@fortedigital/nextjs-cache-handler` from 3.2.0 to 3.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/releases\"\u003e@​fortedigital/nextjs-cache-handler's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(redis-strings): preserve native Redis abort handling by \u003ca href=\"https://github.com/Dwlad90\"\u003e\u003ccode\u003e@​Dwlad90\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/pull/236\"\u003efortedigital/nextjs-cache-handler#236\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the npm_and_yarn group across 1 directory with 2 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/pull/239\"\u003efortedigital/nextjs-cache-handler#239\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(instrumentation): load segmentData from disk in registerInitialCache by \u003ca href=\"https://github.com/gergokee\"\u003e\u003ccode\u003e@​gergokee\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/pull/237\"\u003efortedigital/nextjs-cache-handler#237\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!WARNING]\n\u003cstrong\u003eNext.js 16.3.0 breaking change:\u003c/strong\u003e Starting with Next.js 16.3.0, prefetch requests for the app router's route tree (\u003ccode\u003e/_tree\u003c/code\u003e) require per-segment RSC payloads (\u003ccode\u003esegmentData\u003c/code\u003e) to be present in the cache entry. Versions of this package prior to \u003cstrong\u003e3.3.0\u003c/strong\u003e did not populate \u003ccode\u003esegmentData\u003c/code\u003e when restoring the initial cache from disk (via \u003ccode\u003eregisterInitialCache\u003c/code\u003e), which caused the Next.js 16.3.0+ client to receive an unparseable response for \u003ccode\u003e/_tree\u003c/code\u003e prefetch requests and retry indefinitely.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/compare/3.2.2...3.3.0\"\u003ehttps://github.com/fortedigital/nextjs-cache-handler/compare/3.2.2...3.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.2.2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: use route cache revalidation by \u003ca href=\"https://github.com/tomatotomata\"\u003e\u003ccode\u003e@​tomatotomata\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/pull/232\"\u003efortedigital/nextjs-cache-handler#232\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tomatotomata\"\u003e\u003ccode\u003e@​tomatotomata\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/pull/232\"\u003efortedigital/nextjs-cache-handler#232\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/compare/3.2.1...3.2.2\"\u003ehttps://github.com/fortedigital/nextjs-cache-handler/compare/3.2.1...3.2.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.2.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(cache-handler): persist implicit path tags for PAGES entries  by \u003ca href=\"https://github.com/KajSzy\"\u003e\u003ccode\u003e@​KajSzy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/pull/227\"\u003efortedigital/nextjs-cache-handler#227\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: packages upgraded\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/compare/3.2.0...3.2.1\"\u003ehttps://github.com/fortedigital/nextjs-cache-handler/compare/3.2.0...3.2.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/commit/702913d1cdc4f9966706df89513017c39ff4182a\"\u003e\u003ccode\u003e702913d\u003c/code\u003e\u003c/a\u003e 3.3.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/commit/48c1faf04af989651dde36b6dfc9776a73c98410\"\u003e\u003ccode\u003e48c1faf\u003c/code\u003e\u003c/a\u003e Added concurrency limit\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/commit/78b8cbd34551b471657646afc8246b5214a271d5\"\u003e\u003ccode\u003e78b8cbd\u003c/code\u003e\u003c/a\u003e Package bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/commit/8861a1256be64c962f12b680523bafd07bcc0cb5\"\u003e\u003ccode\u003e8861a12\u003c/code\u003e\u003c/a\u003e fix(instrumentation): load segmentData from disk in registerInitialCache (\u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/issues/237\"\u003e#237\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/commit/4ba9330b1b3bffa98419c7acba1004ba569d4c30\"\u003e\u003ccode\u003e4ba9330\u003c/code\u003e\u003c/a\u003e Bump the npm_and_yarn group across 1 directory with 2 updates (\u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/issues/239\"\u003e#239\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/commit/199179aed632a6e0993809727f9c5190cdc2aa03\"\u003e\u003ccode\u003e199179a\u003c/code\u003e\u003c/a\u003e fix(redis-strings): preserve native Redis abort handling (\u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/issues/236\"\u003e#236\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/commit/e742eaa227526ebeaefdff4f8fc4c0af017096fc\"\u003e\u003ccode\u003ee742eaa\u003c/code\u003e\u003c/a\u003e 3.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/commit/a015559345648010cb138826f868eed99d59ae7a\"\u003e\u003ccode\u003ea015559\u003c/code\u003e\u003c/a\u003e fix: use route cache revalidation (\u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/issues/232\"\u003e#232\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/commit/e6dbc68447a8d15a24c30c1ed646a200e29ac9f3\"\u003e\u003ccode\u003ee6dbc68\u003c/code\u003e\u003c/a\u003e Version bumped to 3.2.1 and packages upgraded\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/commit/74149e3db10dda71a8c29c0b99bb105069701423\"\u003e\u003ccode\u003e74149e3\u003c/code\u003e\u003c/a\u003e fix(cache-handler): persist implicit path tags for PAGES entries  (\u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/issues/227\"\u003e#227\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/compare/3.2.0...3.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@headlessui/react` from 2.2.9 to 2.2.10\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/headlessui/releases\"\u003e@​headlessui/react's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​headlessui/react\u003c/code\u003e\u003ca href=\"https://github.com/v2\"\u003e\u003ccode\u003e@​v2\u003c/code\u003e\u003c/a\u003e.2.10\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDon’t render \u003ccode\u003e\u0026lt;Portal\u0026gt;\u003c/code\u003e while hydrating (\u003ca href=\"https://redirect.github.com/tailwindlabs/headlessui/pull/3825\"\u003e#3825\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix passing props on \u003ccode\u003eFragment\u003c/code\u003e error due to \u003ccode\u003eSymbol(react.lazy)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/headlessui/pull/3873\"\u003e#3873\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/headlessui/blob/main/packages/@headlessui-react/CHANGELOG.md\"\u003e@​headlessui/react's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[2.2.10] - 2026-04-07\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDon’t render \u003ccode\u003e\u0026lt;Portal\u0026gt;\u003c/code\u003e while hydrating (\u003ca href=\"https://redirect.github.com/tailwindlabs/headlessui/pull/3825\"\u003e#3825\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix passing props on \u003ccode\u003eFragment\u003c/code\u003e error due to \u003ccode\u003eSymbol(react.lazy)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/headlessui/pull/3873\"\u003e#3873\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/headlessui/commit/d13526d02a2de92c4ad7b62c15cd980636543fe2\"\u003e\u003ccode\u003ed13526d\u003c/code\u003e\u003c/a\u003e 2.2.10 - \u003ccode\u003e@​headlessui/react\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/headlessui/commit/b0dcd8fc6ce78bc80221e602c0b1aa94e304ef81\"\u003e\u003ccode\u003eb0dcd8f\u003c/code\u003e\u003c/a\u003e Handle props on Fragment error due to \u003ccode\u003eSymbol(react.lazy)\u003c/code\u003e (\u003ca href=\"https://github.com/tailwindlabs/headlessui/tree/HEAD/packages/@headlessui-react/issues/3873\"\u003e#3873\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/headlessui/commit/7baca70434e11432b4210e87558cd452801bb2f9\"\u003e\u003ccode\u003e7baca70\u003c/code\u003e\u003c/a\u003e Don’t render \u003ccode\u003e\\\u0026lt;Portal\u0026gt;\u003c/code\u003es while hydrating (\u003ca href=\"https://github.com/tailwindlabs/headlessui/tree/HEAD/packages/@headlessui-react/issues/3825\"\u003e#3825\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/headlessui/commit/5ef7395d86dc322ea056c4839bfd0910299b3808\"\u003e\u003ccode\u003e5ef7395\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003eRefProp\u003c/code\u003e to \u003ccode\u003eprops\u003c/code\u003e (\u003ca href=\"https://github.com/tailwindlabs/headlessui/tree/HEAD/packages/@headlessui-react/issues/3823\"\u003e#3823\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/tailwindlabs/headlessui/commits/@headlessui/react@v2.2.10/packages/@headlessui-react\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@sentry/nextjs` from 10.32.0 to 10.73.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/getsentry/sentry-javascript/releases\"\u003e@​sentry/nextjs's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e10.73.0\u003c/h2\u003e\n\u003ch3\u003eImportant Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003efeat(v10/nextjs): Add \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e entry point (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23766\"\u003e#23766\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003ewithSentryConfig\u003c/code\u003e is now available from \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e, the path it moves to in v11. Importing it from \u003ccode\u003e@sentry/nextjs\u003c/code\u003e still works on v10 but logs a warning once, so you can change your \u003ccode\u003enext.config\u003c/code\u003e file today and upgrade to v11 without touching it again.\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// next.config.mjs\n- import { withSentryConfig } from '@sentry/nextjs';\n+ import { withSentryConfig } from '@sentry/nextjs/config';\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(v10/node): Deprecate \u003ccode\u003eshouldHandleError\u003c/code\u003e on \u003ccode\u003esetupExpressErrorHandler\u003c/code\u003e and \u003ccode\u003esetupFasitfyErrorHandler\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23734\"\u003e#23734\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/cloudflare): Instrument Durable Object handlers installed as read-only properties (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23769\"\u003e#23769\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003etest(v10/nextjs): Drop nextjs-16-cf-workers canary variant (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23775\"\u003e#23775\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eBundle size 📦\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003ePath\u003c/th\u003e\n\u003cth\u003eSize\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e27.1 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e - with treeshaking flags\u003c/td\u003e\n\u003ctd\u003e25.58 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing)\u003c/td\u003e\n\u003ctd\u003e45.54 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing + Span Streaming)\u003c/td\u003e\n\u003ctd\u003e47.28 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Profiling)\u003c/td\u003e\n\u003ctd\u003e50.17 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay)\u003c/td\u003e\n\u003ctd\u003e83.87 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay) - with treeshaking flags\u003c/td\u003e\n\u003ctd\u003e73.74 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay with Canvas)\u003c/td\u003e\n\u003ctd\u003e88.49 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay, Feedback)\u003c/td\u003e\n\u003ctd\u003e100.83 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Feedback)\u003c/td\u003e\n\u003ctd\u003e43.87 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. sendFeedback)\u003c/td\u003e\n\u003ctd\u003e31.78 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. FeedbackAsync)\u003c/td\u003e\n\u003ctd\u003e36.79 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Metrics)\u003c/td\u003e\n\u003ctd\u003e28.16 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Logs)\u003c/td\u003e\n\u003ctd\u003e28.38 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Metrics \u0026amp; Logs)\u003c/td\u003e\n\u003ctd\u003e29.06 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/react\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e28.86 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/react\u003c/code\u003e (incl. Tracing)\u003c/td\u003e\n\u003ctd\u003e47.74 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/vue\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e32.4 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/vue\u003c/code\u003e (incl. Tracing)\u003c/td\u003e\n\u003ctd\u003e47.46 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/svelte\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e27.12 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eCDN Bundle\u003c/td\u003e\n\u003ctd\u003e29.43 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/getsentry/sentry-javascript/blob/10.73.0/CHANGELOG.md\"\u003e@​sentry/nextjs's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e10.73.0\u003c/h2\u003e\n\u003ch3\u003eImportant Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003efeat(v10/nextjs): Add \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e entry point (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23766\"\u003e#23766\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003ewithSentryConfig\u003c/code\u003e is now available from \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e, the path it moves to in v11. Importing it from \u003ccode\u003e@sentry/nextjs\u003c/code\u003e still works on v10 but logs a warning once, so you can change your \u003ccode\u003enext.config\u003c/code\u003e file today and upgrade to v11 without touching it again.\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// next.config.mjs\n- import { withSentryConfig } from '@sentry/nextjs';\n+ import { withSentryConfig } from '@sentry/nextjs/config';\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(v10/node): Deprecate \u003ccode\u003eshouldHandleError\u003c/code\u003e on \u003ccode\u003esetupExpressErrorHandler\u003c/code\u003e and \u003ccode\u003esetupFasitfyErrorHandler\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23734\"\u003e#23734\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/cloudflare): Instrument Durable Object handlers installed as read-only properties (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23769\"\u003e#23769\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003etest(v10/nextjs): Drop nextjs-16-cf-workers canary variant (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23775\"\u003e#23775\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e10.72.0\u003c/h2\u003e\n\u003ch3\u003eImportant Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eAI integrations no longer report errors that propagate to the caller (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23638\"\u003e#23638\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23639\"\u003e#23639\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23640\"\u003e#23640\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eAcross all AI integrations (OpenAI, Anthropic, Google GenAI, LangChain, and LangGraph), the SDK no longer sends an event to Sentry for errors that the AI framework propagates to your code. Previously the instrumentation reported these as unhandled (\u003ccode\u003ehandled: false\u003c/code\u003e) before your own error handling ran, so an error your code caught still showed up in Sentry as an unhandled crash. The span is still marked as errored and the error still propagates, so reporting is left to your application: if your code does not handle the error, it reaches Sentry's global error handlers and is captured as unhandled, just like any other uncaught error. Errors that a provider surfaces as data on an otherwise successful response (such as Anthropic error-shaped responses or Google GenAI blocked content) are still captured, since your code never sees them propagate.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003efeat(v10/cloudflare): Add \u003ccode\u003erpcTracePropagationBindings\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23737\"\u003e#23737\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23738\"\u003e#23738\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe new \u003ccode\u003erpcTracePropagationBindings\u003c/code\u003e option names the \u003ccode\u003eenv\u003c/code\u003e bindings that outgoing RPC calls propagate trace context to. Strings match a binding name exactly, regular expressions match by pattern, and the default empty array propagates to nothing. RPC has no headers to carry trace context, so the SDK appends it as a trailing argument that only a Sentry-instrumented receiver removes again. List only the bindings whose receiver you know runs Sentry. Setting the option takes precedence over \u003ccode\u003eenableRpcTracePropagation\u003c/code\u003e, which is now deprecated. When you build with the Sentry Cloudflare Vite plugin, the bindings that resolve to this worker (its own Durable Objects and self service bindings) are derived from your wrangler config and added for you.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(v10/astro): support astro v7 route patterns properly (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23657\"\u003e#23657\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/bundler-plugins): Preserve full file path in component annotation source maps (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23595\"\u003e#23595\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/core): Store child span timeout handle in \u003ccode\u003e_childSpanTimeoutID\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23673\"\u003e#23673\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/node): Only end the process session when it is still ok (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23731\"\u003e#23731\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/react-router): Use react-router's own instrumentation types instead of a mirrored copy (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23589\"\u003e#23589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/replay): Suppress Worker destroyed error on session expiry (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23654\"\u003e#23654\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/server-utils): Keep orchestrion registration out of tree-shaking (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23591\"\u003e#23591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/server-utils): Stop shipping orchestrion bundler plugins as production dependencies (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23667\"\u003e#23667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/server-utils): Support openai v7 in auto-instrumentation (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23713\"\u003e#23713\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/sveltekit): Detect native tracing in flattened SvelteKit 3 config (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23656\"\u003e#23656\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/f109d922f5971e2ade549b6c755524168b101818\"\u003e\u003ccode\u003ef109d92\u003c/code\u003e\u003c/a\u003e release: 10.73.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/1a3e04edc4d1c97a702861a9bddd3ed577a71de4\"\u003e\u003ccode\u003e1a3e04e\u003c/code\u003e\u003c/a\u003e meta(changelog): Update changelog for 10.73.0 (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23778\"\u003e#23778\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/da8d7696b08432cd94e78552d9f4c9322c1dc746\"\u003e\u003ccode\u003eda8d769\u003c/code\u003e\u003c/a\u003e test(v10/nextjs): Drop nextjs-16-cf-workers canary variant (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23775\"\u003e#23775\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/bea4d38bf5422ae917275d0b68ad575a2b2b475b\"\u003e\u003ccode\u003ebea4d38\u003c/code\u003e\u003c/a\u003e feat(v10/node): Deprecate \u003ccode\u003eshouldHandleError\u003c/code\u003e on \u003ccode\u003esetupExpressErrorHandler\u003c/code\u003e a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/605caaf2aa85f78ed9a180b273a335fe798bf30c\"\u003e\u003ccode\u003e605caaf\u003c/code\u003e\u003c/a\u003e feat(v10/nextjs): Add \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e entry point (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23766\"\u003e#23766\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/da17307e9e1898a48a3d4037aff96d5849f123fb\"\u003e\u003ccode\u003eda17307\u003c/code\u003e\u003c/a\u003e fix(v10/cloudflare): Instrument Durable Object handlers installed as read-onl...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/2c4ca38e52cb0e4c4ee69cbdc218c9cabd52eccf\"\u003e\u003ccode\u003e2c4ca38\u003c/code\u003e\u003c/a\u003e Merge branch 'release/10.72.0' into v10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/0d236289ba889ac8f007882726aaa62d9a83cc15\"\u003e\u003ccode\u003e0d23628\u003c/code\u003e\u003c/a\u003e release: 10.72.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/ac2094d469ace03e883abb5fc98b5dc678ccfe49\"\u003e\u003ccode\u003eac2094d\u003c/code\u003e\u003c/a\u003e meta(changelog): Update changelog for 10.72.0 (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23743\"\u003e#23743\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/f3254344c4b63382c12cec95b64e7c54f9e45ff9\"\u003e\u003ccode\u003ef325434\u003c/code\u003e\u003c/a\u003e feat(v10/cloudflare): Derive rpcTracePropagationBindings from the wrangler co...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/getsentry/sentry-javascript/compare/10.32.0...10.73.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@tailwindcss/forms` from 0.5.10 to 0.5.11\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/tailwindcss-forms/releases\"\u003e@​tailwindcss/forms's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.5.11\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eLimit attribute rules to input and select elements (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-forms/pull/159\"\u003e#159\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/tailwindcss-forms/blob/main/CHANGELOG.md\"\u003e@​tailwindcss/forms's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[0.5.11] - 2025-12-17\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eLimit attribute rules to input and select elements (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-forms/pull/159\"\u003e#159\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-forms/commit/e1b609d57954eb0036c4c2e7ae9c9c2ba558146b\"\u003e\u003ccode\u003ee1b609d\u003c/code\u003e\u003c/a\u003e 0.5.11\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-forms/commit/67ff8ea3dc0093d5c9f4c45cc8413e8c5bc082d6\"\u003e\u003ccode\u003e67ff8ea\u003c/code\u003e\u003c/a\u003e Limit attribute rules to input and select elements (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-forms/issues/159\"\u003e#159\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-forms/commit/fc3f7e6bce06a1985d445c53e90c3c7fac0e1d18\"\u003e\u003ccode\u003efc3f7e6\u003c/code\u003e\u003c/a\u003e docs: update installation guide to add tailwind css v4 instructions while kee...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/tailwindlabs/tailwindcss-forms/compare/v0.5.10...v0.5.11\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@tailwindcss/typography` from 0.5.16 to 0.5.20\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/releases\"\u003e@​tailwindcss/typography's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.5.20\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport installing with stable versions of Tailwind CSS v4 (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/424\"\u003e#424\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.5.19\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed broken color styles (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/405\"\u003e#405\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.5.18\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed undefined variable error (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/403\"\u003e#403\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.5.17\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd modifiers for description list elements (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/357\"\u003e#357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eprose-picture\u003c/code\u003e modifier (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/367\"\u003e#367\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eInclude unit in \u003ccode\u003ehr\u003c/code\u003e border-width value (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/379\"\u003e#379\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003e\u0026lt;kbd\u0026gt;\u003c/code\u003e styles work with Tailwind CSS v4 (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/387\"\u003e#387\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove lodash dependencies (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/402\"\u003e#402\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/blob/main/CHANGELOG.md\"\u003e@​tailwindcss/typography's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[0.5.20] - 2026-06-08\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport installing with stable versions of Tailwind CSS v4 (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/424\"\u003e#424\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[0.5.19] - 2025-09-24\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed broken color styles (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/405\"\u003e#405\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[0.5.18] - 2025-09-19\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed undefined variable error (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/403\"\u003e#403\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[0.5.17] - 2025-09-19\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd modifiers for description list elements (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/357\"\u003e#357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eprose-picture\u003c/code\u003e modifier (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/367\"\u003e#367\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eInclude unit in \u003ccode\u003ehr\u003c/code\u003e border-width value (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/379\"\u003e#379\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003e\u0026lt;kbd\u0026gt;\u003c/code\u003e styles work with Tailwind CSS v4 (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/387\"\u003e#387\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove lodash dependencies (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/402\"\u003e#402\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/commit/e3714a3fe55551ce9d51eec4721183ed6b1d5cd1\"\u003e\u003ccode\u003ee3714a3\u003c/code\u003e\u003c/a\u003e 0.5.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/commit/f34283d2961e18dd0dc2a849702e0dfd45fc80cb\"\u003e\u003ccode\u003ef34283d\u003c/code\u003e\u003c/a\u003e Update tailwindcss peer dependency version (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/issues/424\"\u003e#424\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/commit/543de4274390e90c4aab5d216729b46a3ba5541b\"\u003e\u003ccode\u003e543de42\u003c/code\u003e\u003c/a\u003e bump Node.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/commit/881b0488df9fd05e5361276b66a9ee8e7f39a3a7\"\u003e\u003ccode\u003e881b048\u003c/code\u003e\u003c/a\u003e Setup OIDC (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/issues/423\"\u003e#423\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/commit/74a3da779bb43e4e68f446395224c768704c1fb6\"\u003e\u003ccode\u003e74a3da7\u003c/code\u003e\u003c/a\u003e Fix typo in README.md (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/issues/413\"\u003e#413\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/commit/3963dfede4845f46451db1863fd5321f4cdea03b\"\u003e\u003ccode\u003e3963dfe\u003c/code\u003e\u003c/a\u003e Bump js-yaml from 3.14.1 to 3.14.2 (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/issues/410\"\u003e#410\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/commit/abf85cc6e1b4f9b914b0f66453e5a97a9899a15c\"\u003e\u003ccode\u003eabf85cc\u003c/code\u003e\u003c/a\u003e className instead of classname (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/issues/406\"\u003e#406\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/commit/e002ab89ad8f4202638249c1c300c0cf0b3739c5\"\u003e\u003ccode\u003ee002ab8\u003c/code\u003e\u003c/a\u003e 0.5.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/commit/bbb1c21099e34ff4d1d7f82f7528b85e71ed3c5a\"\u003e\u003ccode\u003ebbb1c21\u003c/code\u003e\u003c/a\u003e Fix bad RGB syntax (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/issues/405\"\u003e#405\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/commit/b316f958af5bc12a981526c3091d8319626e274e\"\u003e\u003ccode\u003eb316f95\u003c/code\u003e\u003c/a\u003e 0.5.18\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/compare/v0.5.16...v0.5.20\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​tailwindcss/typography\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `autoprefixer` from 10.4.21 to 10.5.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/autoprefixer/releases\"\u003eautoprefixer's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e10.5.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed resolution media query parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.5.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed prefixed rule duplication (by \u003ca href=\"https://github.com/xianjianlf2\"\u003e\u003ccode\u003e@​xianjianlf2\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.5.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed brackets and gradient parser (\u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003e-webkit-fill-available\u003c/code\u003e before \u003ccode\u003e-moz-available\u003c/code\u003e, so Firefox\nwill use \u003ccode\u003e-webkit-\u003c/code\u003e version which is closer to \u003ccode\u003estretch\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.5.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003egrid-area\u003c/code\u003e span reset for overriding areas (by \u003ca href=\"https://github.com/puneetdixit200\"\u003e\u003ccode\u003e@​puneetdixit200\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.5.0 “Each Endeavouring, All Achieving”\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003emask-position-x\u003c/code\u003e and \u003ccode\u003emask-position-y\u003c/code\u003e support (by \u003ca href=\"https://github.com/toporek\"\u003e\u003ccode\u003e@​toporek\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved development key from \u003ccode\u003epackage.json\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed broken gradients on CSS Custom Properties (by \u003ca href=\"https://github.com/serger777\"\u003e\u003ccode\u003e@​serger777\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMade Autoprefixer a little faster (by \u003ca href=\"https://github.com/Cherry\"\u003e\u003ccode\u003e@​Cherry\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced dependencies (by \u003ca href=\"https://github.com/hyperz111\"\u003e\u003ccode\u003e@​hyperz111\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003estretch\u003c/code\u003e prefixes on new Can I Use database.\u003c/li\u003e\n\u003cli\u003eUpdated \u003ccode\u003efraction.js\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md\"\u003eautoprefixer's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e10.5.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed resolution media query parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.5.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed prefixed rule duplication (by \u003ca href=\"https://github.com/xianjianlf2\"\u003e\u003ccode\u003e@​xianjianlf2\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.5.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed brackets and gradient parser (\u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003e-webkit-fill-available\u003c/code\u003e before \u003ccode\u003e-moz-available\u003c/code\u003e, so Firefox\nwill use \u003ccode\u003e-webkit-\u003c/code\u003e version which is closer to \u003ccode\u003estretch\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.5.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003egrid-area\u003c/code\u003e span reset for overriding areas (by \u003ca href=\"https://github.com/puneetdixit200\"\u003e\u003ccode\u003e@​puneetdixit200\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.5.0 “Each Endeavouring, All Achieving”\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003emask-position-x\u003c/code\u003e and \u003ccode\u003emask-position-y\u003c/code\u003e support (by \u003ca href=\"https://github.com/toporek\"\u003e\u003ccode\u003e@​toporek\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved development key from \u003ccode\u003epackage.json\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed broken gradients on CSS Custom Properties (by \u003ca href=\"https://github.com/serger777\"\u003e\u003ccode\u003e@​serger777\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMade Autoprefixer a little faster (by \u003ca href=\"https://github.com/Cherry\"\u003e\u003ccode\u003e@​Cherry\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced dependencies (by \u003ca href=\"https://github.com/hyperz111\"\u003e\u003ccode\u003e@​hyperz111\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003estretch\u003c/code\u003e prefixes on new Can I Use database.\u003c/li\u003e\n\u003cli\u003eUpdated \u003ccode\u003efraction.js\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/autoprefixer/commit/7e81ffff9d824968394bab6f81da2e2c2511cc49\"\u003e\u003ccode\u003e7e81fff\u003c/code\u003e\u003c/a\u003e Release 10.5.5 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/autoprefixer/commit/d9e3531b4109d9e68bae23ed451c48197e67cb29\"\u003e\u003ccode\u003ed9e3531\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/autoprefixer/commit/34b3a3e275ae223642aaec7686eece008bb88803\"\u003e\u003ccode\u003e34b3a3e\u003c/code\u003e\u003c/a\u003e Fix media query parse performance\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/autoprefixer/commit/265521ee8ee3098dcb114e8259259ca614146e00\"\u003e\u003ccode\u003e265521e\u003c/code\u003e\u003c/a\u003e Remove Cult\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/autoprefixer/commit/dd80d38938055a66d2ab1694234f5ad472fb1bb5\"\u003e\u003ccode\u003edd80d38\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/autoprefixer/commit/4cad00f0e839f3d7bbcdcc00b7df6fc448fb28f3\"\u003e\u003ccode\u003e4cad00f\u003c/code\u003e\u003c/a\u003e Release 10.5.4 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/autoprefixer/commit/e62a4b1782f4ece51070feba79b0ff19f4305c68\"\u003e\u003ccode\u003ee62a4b1\u003c/code\u003e\u003c/a\u003e Update CI config\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/autoprefixer/commit/c8f0d0ae00f5bb28bbcc3413f70b088020007469\"\u003e\u003ccode\u003ec8f0d0a\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/autoprefixer/commit/cae35771dc4a4dfeda637a31dc1795ace6d9d28b\"\u003e\u003ccode\u003ecae3577\u003c/code\u003e\u003c/a\u003e Move back to latest pnpm 11\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/autoprefixer/commit/fd31eb33b56ab9663d298b5bf08ae4ff47f76878\"\u003e\u003ccode\u003efd31eb3\u003c/code\u003e\u003c/a\u003e Fix duplicated prefixed selectors on reformatted CSS (\u003ca href=\"https://redirect.github.com/postcss/autoprefixer/issues/1552\"\u003e#1552\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/autoprefixer/compare/10.4.21...10.5.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for autoprefixer since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `date-fns` from 4.1.0 to 4.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/date-fns/date-fns/releases\"\u003edate-fns's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cp\u003eThis release revisits the approach to CDN usage and introduces a new package, \u003ccode\u003e@date-fns/cdn\u003c/code\u003e and deprecates the \u003ccode\u003edate-fns\u003c/code\u003e CDN scripts. It allowed reducing the zipped package size from \u003ccode\u003e5.83 MB\u003c/code\u003e down to \u003ccode\u003e3.96 MB\u003c/code\u003e without introducing any breaking changes.\u003c/p\u003e\n\u003cp\u003eIn \u003ccode\u003ev5.0.0-alpha.0\u003c/code\u003e where CDN scripts are completely removed from \u003ccode\u003edate-fns\u003c/code\u003e the change is more significant and brings the zipped package size down to \u003ccode\u003e2.89 MB\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eIt is just the first step in optimizing the package size. Expect further size reduction in the future v4 and v5 versions.\u003c/p\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDEPRECATED\u003c/strong\u003e: The \u003ccode\u003edate-fns\u003c/code\u003e CDN scripts are now deprecated and will be removed in the next major release. Please switch to the new \u003ccode\u003e@date-fns/cdn\u003c/code\u003e package for CDN usage.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRemoved CDN source maps to reduce the package size. If you rely on them, please switch to the new \u003ccode\u003e@date-fns/cdn\u003c/code\u003e package that still includes them.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cp\u003eKudos to \u003ca href=\"https://github.com/ImRodry\"\u003e\u003ccode\u003e@​ImRodry\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/puneetdixit200\"\u003e\u003ccode\u003e@​puneetdixit200\u003c/code\u003e\u003c/a\u003e for their contributions.\u003c/p\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFixed missing modularized optimization fallback (\u003ca href=\"https://x.com/kossnocorp/status/1731181274579325260\"\u003efor Next.js and others\u003c/a\u003e). See \u003ca href=\"https://x.com/kossnocorp/status/1731181274579325260\"\u003e#4193\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003ept\u003c/code\u003e locale first day of week to be Sunday. See \u003ca href=\"https://redirect.github.com/date-fns/date-fns/pull/4195\"\u003e#4195\u003c/a\u003e by \u003ca href=\"https://github.com/ImRodry\"\u003e\u003ccode\u003e@​ImRodry\u003c/code\u003e\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003ezh-CN\u003c/code\u003e, \u003ccode\u003ezh-HK\u003c/code\u003e, and \u003ccode\u003ezh-TW\u003c/code\u003e locale month parsing for October, November, and December. See \u003ca href=\"https://redirect.github.com/date-fns/date-fns/pull/4194\"\u003e#4194\u003c/a\u003e by \u003ca href=\"https://github.com/puneetdixit200\"\u003e\u003ccode\u003e@​puneetdixit200\u003c/code\u003e\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.2.1\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed type definitions missing in v4.2.0 due to TypeScript misconfiguration.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.2.0\u003c/h2\u003e\n\u003cp\u003eThis is a minor release in all senses, it only includes documentation updates (first of many) that points to the new \u003ca href=\"https://date-fns.org/you-dont-need-date-fns\"\u003eYou Don't Need date-fns*\u003c/a\u003e page.\u003c/p\u003e\n\u003cp\u003e* Not really\u003c/p\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded Temporal API references to the JSDoc annotations of \u003ccode\u003eadd\u003c/code\u003e, \u003ccode\u003eaddBusinessDays\u003c/code\u003e, and \u003ccode\u003eaddDays\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/date-fns/date-fns/commit/cd53d2538cfa318404eff7ade6449b49bf34562e\"\u003e\u003ccode\u003ecd53d25\u003c/code\u003e\u003c/a\u003e Promote to v4.4.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/date-fns/date-fns/commit/d948ec151d395096de8a45fbcd9b1e79c26fda25\"\u003e\u003ccode\u003ed948ec1\u003c/code\u003e\u003c/a\u003e Preserve but deprecate CDN versions for v4, set up v5 with polyfills\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/date-fns/date-fns/commit/ee65753cfc5d73cc9acd43aaa8012b3b233ddf32\"\u003e\u003ccode\u003eee65753\u003c/code\u003e\u003c/a\u003e Add root \u003ccode\u003emise :format\u003c/code\u003e task\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/date-fns/date-fns/commit/9f5bdf5d5a944772aa9668c4fa6567d89ca01fa9\"\u003e\u003ccode\u003e9f5bdf5\u003c/code\u003e\u003c/a\u003e Add positional argument to \u003ccode\u003etest/smoke.sh\u003c/code\u003e script\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/date-fns/date-fns/commit/651ead6faf331515814803faf457f5b9db7c9729\"\u003e\u003ccode\u003e651ead6\u003c/code\u003e\u003c/a\u003e Split CDN bundles into separate \u003ccode\u003e@​date-fns/cdn\u003c/code\u003e package\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/date-fns/date-fns/commit/224c1a209967dad359a2c2adc9a5b0ef72e4fe7b\"\u003e\u003ccode\u003e224c1a2\u003c/code\u003e\u003c/a\u003e Deprecate type tests as attw hangs on date-fns package\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/date-fns/date-fns/commit/7bb2842dac3d579f84b2de62f015335fb3ac734a\"\u003e\u003ccode\u003e7bb2842\u003c/code\u003e\u003c/a\u003e Switch \u003ccode\u003ePACKAGE_OUTPUT_PATH\u003c/code\u003e to \u003ccode\u003e--dist\u003c/code\u003e flag in the package build script\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/date-fns/date-fns/commit/b6ad5acc5ab0b40777a2695ec074c2ffcd982763\"\u003e\u003ccode\u003eb6ad5ac\u003c/code\u003e\u003c/a\u003e Add flags to control package build script\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/date-fns/date-fns/commit/424a783de1fd974bcdbe907c9c5eb5154e9db29f\"\u003e\u003ccode\u003e424a783\u003c/code\u003e\u003c/a\u003e Fix docs release after moving to monorepo setup\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/date-fns/date-fns/commit/f95bcf18b53e6832b2c575c24c98654a24f52699\"\u003e\u003ccode\u003ef95bcf1\u003c/code\u003e\u003c/a\u003e (docs): Add missing \u003ccode\u003etsx\u003c/code\u003e dependency\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/date-fns/date-fns/compare/v4.1.0...v4.4.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-xml-parser` from 5.8.0 to 5.11.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/releases\"\u003efast-xml-parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.11.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump actions/checkout from 7.0.0 to 7.0.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/858\"\u003eNaturalIntelligence/fast-xml-parser#858\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump zizmorcore/zizmor-action from 0.5.7 to 0.6.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/856\"\u003eNaturalIntelligence/fast-xml-parser#856\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/setup-node from 6.4.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/854\"\u003eNaturalIntelligence/fast-xml-parser#854\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: fix two 404 documentation links by \u003ca href=\"https://github.com/rajanpanth\"\u003e\u003ccode\u003e@​rajanpanth\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/862\"\u003eNaturalIntelligence/fast-xml-parser#862\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rajanpanth\"\u003e\u003ccode\u003e@​rajanpanth\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/862\"\u003eNaturalIntelligence/fast-xml-parser#862\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.11.0...v5.11.1\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.11.0...v5.11.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.11.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eadd support for endIndex in node metadata (5.x edition) by \u003ca href=\"https://github.com/Wain-PC\"\u003e\u003ccode\u003e@​Wain-PC\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/850\"\u003eNaturalIntelligence/fast-xml-parser#850\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: don't crash on a closing tag with no matching opening tag by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/861\"\u003eNaturalIntelligence/fast-xml-parser#861\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Wain-PC\"\u003e\u003ccode\u003e@​Wain-PC\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/850\"\u003eNaturalIntelligence/fast-xml-parser#850\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/861\"\u003eNaturalIntelligence/fast-xml-parser#861\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.10.1...v5.11.0\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.10.1...v5.11.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.10.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.10.0...v5.10.1\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.10.0...v5.10.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.10.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump actions/checkout from 6.0.3 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/849\"\u003eNaturalIntelligence/fast-xml-parser#849\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump zizmorcore/zizmor-action from 0.5.6 to 0.5.7 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/848\"\u003eNaturalIntelligence/fast-xml-parser#848\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.3...v5.10.0\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.3...v5.10.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.9.3\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHarden GitHub Actions workflows by \u003ca href=\"https://github.com/martincostello\"\u003e\u003ccode\u003e@​martincostello\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/841\"\u003eNaturalIntelligence/fast-xml-parser#841\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eGitHub Actions workflow fixes by \u003ca href=\"https://github.com/martincostello\"\u003e\u003ccode\u003e@​martincostello\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/844\"\u003eNaturalIntelligence/fast-xml-parser#844\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/martincostello\"\u003e\u003ccode\u003e@​martincostello\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/841\"\u003eNaturalIntelligence/fast-xml-parser#841\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.2...v5.9.3\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.2...v5.9.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.9.2\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.1...v5.9.2\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.1...v5.9.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.9.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.0...v5.9.1\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.0...v5.9.1\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md\"\u003efast-xml-parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003eNote: If you find missing information about particular minor version, that version must have been changed without any functional change in this library.\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003cp\u003eNote: Due to some last quick changes on v4, detail of v4.5.3 \u0026amp; v4.5.4 are not updated here. v4.5.4x is the last tag of v4 in github repository. I'm extremely sorry for the confusion\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e5.11.1 / 2026-08-27\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efix: validator; Replace regex with a single-pass scanner for attribute tokens, eliminating quadratic behavior on long whitespace runs.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e5.11.0 / 2026-08-16\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efeat: support for endIndex in node metadata (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/850\"\u003e#850\u003c/a\u003e) [By \u003ca href=\"https://github.com/Wain-PC\"\u003ePavel Dranichnikov\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003efix: don't crash on a closing tag with no matching opening tag (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/861\"\u003e#861\u003c/a\u003e) [By \u003ca href=\"https://github.com/hdimer\"\u003eHaïm Dimer\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003efix: DOCTYPE to read SYSTEM/PUBLIC\u003c/li\u003e\n\u003cli\u003edeps: strnum v2.4.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e5.10.1 / 2026-07-17\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efix: multiple DOCTYPE declarations.\u003c/li\u003e\n\u003cli\u003edeps: \u003ccode\u003e@nodable/entities\u003c/code\u003e for treeshaking\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e5.10.0 / 2026-07-11\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eupgrade:\n\u003cul\u003e\n\u003cli\u003exml-naming v0.3.0: cache support\u003c/li\u003e\n\u003cli\u003ePEM v1.6.2: sibling bug fix\u003c/li\u003e\n\u003cli\u003eis-unsafe v2.0.0: tree shaking\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e*\u003cem\u003e5.9.3 / 2026-06-19\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eupdate strnum\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e*\u003cem\u003e5.9.2 / 2026-06-17\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003edummy release to test changes in github action\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e*\u003cem\u003e5.9.1 / 2026-06-17\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003edummy release to test release from github action\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e*\u003cem\u003e5.9.0 / 2026-06-15\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eupdate strnum to 2.3.0\n\u003cul\u003e\n\u003cli\u003eyou can set hex, binary, enotation, infinity, unicode\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003evalidate unsafe HTML or XML data in doctype entities unsing 'is-unsafe' library.\nUser can override rules by overriding EntityDecoder.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e*\u003cem\u003e5.8.0 / 2026-05-12\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eintegrate xml-naming to validate DOCTYPE entity name and notation name (using qname becaue of backward compatibility)\n\u003cul\u003e\n\u003cli\u003eThis will consider xml-version as well. '1.0' is default\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eupdate strnum to 2.3.0\n\u003cul\u003e\n\u003cli\u003eYou can set octal and binary parsing which is bydeault off\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eupdate fast-xml-builder to 1.2.0\n\u003cul\u003e\n\u003cli\u003ecan sanitize tag names if found invalid\u003c/li\u003e\n\u003cli\u003efix format output\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e5.7.3 / 2006-05-05\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efix: alwaysCreateTextNode should create text node when attributes are present for self closing node\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/3617550adfb280989f482d662b7e9ece55a32a34\"\u003e\u003ccode\u003e3617550\u003c/code\u003e\u003c/a\u003e 5.11.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/6021128c3251d4c1456d2c6cd8442a5005a1f39a\"\u003e\u003ccode\u003e6021128\u003c/code\u003e\u003c/a\u003e update for release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/6ddcb65f240005988457af6af6dd68fa0947acf5\"\u003e\u003ccode\u003e6ddcb65\u003c/code\u003e\u003c/a\u003e remove regex from validator\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/7d608151078d47040841e9804d490feb5c07dfe7\"\u003e\u003ccode\u003e7d60815\u003c/code\u003e\u003c/a\u003e docs: fix two 404 documentation links (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/862\"\u003e#862\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/4e3857b3ab78f0b8e37e70e5cd08f2bc1ac726a8\"\u003e\u003ccode\u003e4e3857b\u003c/code\u003e\u003c/a\u003e Bump actions/setup-node from 6.4.0 to 7.0.0 (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/854\"\u003e#854\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/fcc62fb8f6f620c95dd1c9ab7aac3061f0905592\"\u003e\u003ccode\u003efcc62fb\u003c/code\u003e\u003c/a\u003e Bump zizmorcore/zizmor-action from 0.5.7 to 0.6.1 (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/856\"\u003e#856\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/23a9019d1e481ad3d1b9aef5266194f4e366f14e\"\u003e\u003ccode\u003e23a9019\u003c/code\u003e\u003c/a\u003e Bump actions/checkout from 7.0.0 to 7.0.1 (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/858\"\u003e#858\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/f3c69ae2a9a1a1df4e4be9ca954ddcdf6563d16a\"\u003e\u003ccode\u003ef3c69ae\u003c/code\u003e\u003c/a\u003e 5.11.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/fdbd072e23fcc6ea1a4779aecdd7196620f432d7\"\u003e\u003ccode\u003efdbd072\u003c/code\u003e\u003c/a\u003e update for release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/c5fcb5b1f9178ed07a078b08f53382ee49268ba3\"\u003e\u003ccode\u003ec5fcb5b\u003c/code\u003e\u003c/a\u003e update lock files\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.8.0...v5.11.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for fast-xml-parser since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `next` from 16.2.6 to 16.3.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003enext's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.4\u003c/h2\u003e\n\u003cp\u003eFollow-up release to \u003ca href=\"https://github.com/vercel/next.js/releases/tag/v16.3.3\"\u003ev16.3.3\u003c/a\u003e re-enabling AVIF Image Optimization (\u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97949\"\u003e#97949\u003c/a\u003e).\u003c/p\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003etestmode: Fix infinite recursion in testmode passthrough fetch (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97691\"\u003e#97691\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix build error when aliasing typescript to \u003ccode\u003e@​typescript/typescript6\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97997\"\u003e#97997\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix unset crossOrigin in Turbopack manifests (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97930\"\u003e#97930\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.3\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eCritical:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36\"\u003eUnauthenticated Remote Code Execution on windows-hosted servers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4\"\u003eUnauthenticated Remote Code Execution in Image Optimization API when AVIF files are used\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.2\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Scope app-entry export validation to files inside the app directory (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97357\"\u003e#97357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[backport] Fix catch-all index page being served for every other slug (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97416\"\u003e#97416\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: don't trace embedded WASM loader helpers (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97353\"\u003e#97353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97463\"\u003e#97463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: retain conditions when replacing resolve request keys (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97453\"\u003e#97453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Fix Turbopack worker chunk loading with asset prefix (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97419\"\u003e#97419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97603\"\u003e#97603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/lubieowoce\"\u003e\u003ccode\u003e@​lubieowoce\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[16.x] Turbopack: don't strip async-module runtime from shared runtime chunks by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96653\"\u003evercel/next.js#96653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] [turbopack] Add \u003ccode\u003eturbopack_ecmascript\u003c/code\u003e and \u003ccode\u003eturbopack_wasm\u003c/code\u003e's embeded FS to \u003ccode\u003einternal_assets_conditions\u003c/code\u003e by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96655\"\u003evercel/next.js#96655\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] [turbopack] Collapse nested promises in the analyzer by \u003ca href=\"https://github.com/sampoder\"\u003e\u003ccode\u003e@​sampoder\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96675\"\u003evercel/next.js#96675\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] fix(next/image): preserve image response after optimization by \u003ca href=\"https://github.com/styfle\"\u003e\u003ccode\u003e@​styfle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96733\"\u003evercel/next.js#96733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.3.x] Default deploy e2e tests to the repo next version by \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96900\"\u003evercel/next.js#96900\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Bump \u003ccode\u003e@​swc/helpers\u003c/code\u003e by \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96885\"\u003evercel/next.js#96885\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [turbopack] Raise registration calls in hoisted modules to the top by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97308\"\u003evercel/next.js#97308\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Fix missing styled-jsx styles in Pages Router SSR on adapter builds by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97302\"\u003evercel/next.js#97302\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [turbopack] Fix HMR for dynamic imports evaluated from layouts by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97317\"\u003evercel/next.js#97317\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Restore the live \u003ccode\u003eheaders()\u003c/code\u003e view of the incoming request by \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97311\"\u003evercel/next.js#97311\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/299180d3315c7ebd7b199d2b1a265b5986c5fc7d\"\u003e\u003ccode\u003e299180d\u003c/code\u003e\u003c/a\u003e v16.3.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/12e173dd73ed6c39622281c7282c8364234ad94f\"\u003e\u003ccode\u003e12e173d\u003c/code\u003e\u003c/a\u003e [16.3.x] Re-enable AVIF image optimization and require sharp 0.35.4 (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97949\"\u003e#97949\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/5d9022edd29e32d7061bc56cf713ffe8769cd900\"\u003e\u003ccode\u003e5d9022e\u003c/code\u003e\u003c/a\u003e [backport] Fix unset crossOrigin in Turbopack manifests (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97930\"\u003e#97930\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/d8f45609fa74e56f24958d45d93d3426511f957f\"\u003e\u003ccode\u003ed8f4560\u003c/code\u003e\u003c/a\u003e [16.3.x] Fix build error when aliasing typescript to \u003ccode\u003e@​typescript/typescript6\u003c/code\u003e ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/656aebfb58ce194fb603f18942dad6e94d15b21c\"\u003e\u003ccode\u003e656aebf\u003c/code\u003e\u003c/a\u003e [16.3] testmode: Fix infinite recursion in testmode passthrough fetch (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97691\"\u003e#97691\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/f37c1d656553b8950330b6683ab242a5c610135c\"\u003e\u003ccode\u003ef37c1d6\u003c/code\u003e\u003c/a\u003e [16.3.x] ci: remove pull_request_stats workflow (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97975\"\u003e#97975\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/a9a1cb7859f178f830ad3773b303130c21b19586\"\u003e\u003ccode\u003ea9a1cb7\u003c/code\u003e\u003c/a\u003e v16.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/968b9fcb26bdeb8e0a861a9df05361474666d51b\"\u003e\u003ccode\u003e968b9fc\u003c/code\u003e\u003c/a\u003e [16.3.x] Fix ISR misses with backslashes in segments when deployed on Windows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/3a15b4ac6ac8e70b1a9b18ecc18e8434462899b3\"\u003e\u003ccode\u003e3a15b4a\u003c/code\u003e\u003c/a\u003e [16.3.x] [next/image]: disable avif image optimization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/7378b51ea05a6745d3676bee00cb4c63aac3dd16\"\u003e\u003ccode\u003e7378b51\u003c/code\u003e\u003c/a\u003e Backport/docs fixes 16.3 (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97649\"\u003e#97649\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/compare/v16.2.6...v16.3.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `next-intl` from 4.12.0 to 4.14.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/amannn/next-intl/releases\"\u003enext-intl's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.14.2\u003c/h2\u003e\n\u003ch2\u003e4.14.2 (2026-09-01)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAllow \u003ccode\u003e@eloqnt/*\u003c/code\u003e patches to resolve by moving to \u003ccode\u003e^0.1.0\u003c/code\u003e ranges (\u003ca href=\"https://redirect.github.com/amannn/next-intl/issues/2398\"\u003e#2398\u003c/a\u003e) (\u003ca href=\"https://github.com/amannn/next-intl/commit/4d18120bf3c14ad2beda836659c6854a03c4f368\"\u003e4d18120\u003c/a\u003e) – by \u003ca href=\"https://github.com/amannn\"\u003e\u003ccode\u003e@​amannn\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.14.1\u003c/h2\u003e\n\u003ch2\u003e4.14.1 (2026-08-28)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUnbreak \u003ccode\u003eexperimental.messages\u003c/code\u003e without a \u003ccode\u003emessages.sourceLocale\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/amannn/next-intl/issues/2395\"\u003e#2395\u003c/a\u003e) (\u003ca href=\"https://github.com/amannn/next-intl/commit/67fca941e943e8fa273fbc8a7f362354f6804d35\"\u003e67fca94\u003c/a\u003e) – by \u003ca href=\"https://github.com/amannn\"\u003e\u003ccode\u003e@​amannn\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.14.0\u003c/h2\u003e\n\u003ch2\u003e4.14.0 (2026-08-27)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003euseExtracted\u003c/code\u003e improvements (\u003ca href=\"https://redirect.github.com/amannn/next-intl/issues/2346\"\u003e#2346\u003c/a\u003e) (\u003ca href=\"https://github.com/amannn/next-intl/commit/4ccf3b80a143c192ccfbe576817e2e7fe98aec24\"\u003e4ccf3b8\u003c/a\u003e) – by \u003ca href=\"https://github.com/amannn\"\u003e\u003ccode\u003e@​amannn\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e⚠️ If you're using \u003ccode\u003euseExtracted\u003c/code\u003e and the \u003ccode\u003epo\u003c/code\u003e format, this requires an update to your messages.\u003c/p\u003e\n\u003cp\u003ePlease see \u003ca href=\"https://redirect.github.com/amannn/next-intl/pull/2393\"\u003eamannn/next-intl#2393\u003c/a\u003e for details and an upgrade prompt.\u003c/p\u003e\n\u003ch2\u003ev4.13.7\u003c/h2\u003e\n\u003ch2\u003e4.13.7 (2026-08-17)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePin \u003ccode\u003e@swc/core\u003c/code\u003e to a range that is compatible with the extractor plugin (\u003ca href=\"https://redirect.github.com/amannn/next-intl/issues/2389\"\u003e#2389\u003c/a\u003e) (\u003ca href=\"https://github.com/amannn/next-intl/commit/a37d8aaec094620cc1f8c345023db833eeebbbed\"\u003ea37d8aa\u003c/a\u003e) – by \u003ca href=\"https://github.com/amannn\"\u003e\u003ccode\u003e@​amannn\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.13.6\u003c/h2\u003e\n\u003ch2\u003e4.13.6 (2026-08-10)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDeprecate \u003ccode\u003erequestLocale\u003c/code\u003e param of \u003ccode\u003egetRequestConfig\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/amannn/next-intl/issues/2380\"\u003e#2380\u003c/a\u003e) (\u003ca href=\"https://github.com/amannn/next-intl/commit/ae770af84983fdd2ed8f9a3d9acca5a7275b2b0f\"\u003eae770af\u003c/a\u003e) – by \u003ca href=\"https://github.com/amannn\"\u003e\u003ccode\u003e@​amannn\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSee the \u003ca href=\"https://next-intl.dev/blog/nextjs-root-params\"\u003eblog post on \u003ccode\u003enext/root-params\u003c/code\u003e\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003ev4.13.5\u003c/h2\u003e\n\u003ch2\u003e4.13.5 (2026-08-04)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDeprecate \u003ccode\u003esetRequestLocale\u003c/code\u003e and add \u003ca href=\"https://next-intl.dev/blog/nextjs-root-params\"\u003eblog post on \u003ccode\u003enext/root-params\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/amannn/next-intl/issues/1632\"\u003e#1632\u003c/a\u003e) – by \u003ca href=\"https://github.com/amannn\"\u003e\u003ccode\u003e@​amannn\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.13.4\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/amannn/next-intl/blob/main/CHANGELOG.md\"\u003enext-intl's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.14.2 (2026-09-01)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAllow \u003ccode\u003e@eloqnt/*\u003c/code\u003e patches to resolve by moving to \u003ccode\u003e^0.1.0\u003c/code\u003e ranges (\u003ca href=\"https://redirect.github.com/amannn/next-intl/issues/2398\"\u003e#2398\u003c/a\u003e) (\u003ca href=\"https://github.com/amannn/next-intl/commit/4d18120bf3c14ad2beda836659c6854a03c4f368\"\u003e4d18120\u003c/a\u003e) – by \u003ca href=\"https://github.com/amannn\"\u003e\u003ccode\u003e@​amannn\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.14.1 (2026-08-28)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUnbreak \u003ccode\u003eexperimental.messages\u003c/code\u003e without a \u003ccode\u003emessages.sourceLocale\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/amannn/next-intl/issues/2395\"\u003e#2395\u003c/a\u003e) (\u003ca href=\"https://github.com/amannn/next-intl/commit/67fca941e943e8fa273fbc8a7f362354f6804d35\"\u003e67fca94\u003c/a\u003e) – by \u003ca href=\"https://github.com/amannn\"\u003e\u003ccode\u003e@​amannn\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.14.0 (2026-08-27)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003euseExtracted\u003c/code\u003e improvements (\u003ca href=\"https://redirect.github.com/amannn/next-intl/issues/2346\"\u003e#2346\u003c/a\u003e) (\u003ca href=\"https://github.com/amannn/next-intl/commit/4ccf3b80a143c192ccfbe576817e2e7fe98aec24\"\u003e4ccf3b8\u003c/a\u003e) – by \u003ca href=\"https://github.com/amannn\"\u003e\u003ccode\u003e@​amannn\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.13.7 (2026-08-17)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePin \u003ccode\u003e@swc/core\u003c/code\u003e to a range that is compatible with the extractor plugin (\u003ca href=\"ht...\n\n_Description has been truncated_\n\n\u003c!-- This is an auto-generated description by cubic. --\u003e\n---\n## Summary by cubic\nBumps 20 production dependencies, most notably `next` with critical security fixes, plus `react`, `@sentry/nextjs`, and `zod`.\n\n**Key Notes**\n- `next` 16.3.4 includes critical unauthenticated RCE security fixes for Windows-hosted servers and the Image Optimization API.\n- `@fortedigital/nextjs-cache-handler` 3.3.0 is required for `next` 16.3.0+ to fix the `/ _tree` prefetch regression when restoring cache from disk.\n- `@sentry/nextjs` 10.73.0 deprecates importing `withSentryConfig` from `@sentry/nextjs`; migrate the import to `@sentry/nextjs/config`.\n- `zod` jumps from 3.24.3 to 3.25.76; verify schema validation still works as expected.\n\n\u003csup\u003eWritten for commit d7c6abc6e7bd9b17c2ab21fa745b0d06c6810eb1. Summary will update on new commits.\u003c/sup\u003e\n\n\u003ca href=\"https://cubic.dev/pr/Esdeveniments/esdeveniments-frontend/pull/473?utm_source=github\" target=\"_blank\" rel=\"noopener noreferrer\" data-no-image-dialog=\"true\"\u003e\u003cpicture\u003e\u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-light.svg\"\u003e\u003cimg alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003c/picture\u003e\u003c/a\u003e\n\n\u003c!-- End of auto-generated description by cubic. --\u003e\n\n","html_url":"https://github.com/Esdeveniments/esdeveniments-frontend/pull/473","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Esdeveniments%2Fesdeveniments-frontend/issues/473","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/473/packages"}],"issue_packages":[{"old_version":"6.24.1","new_version":"6.28.1","update_type":"minor","path":null,"pr_created_at":"2026-09-12T06:48:50.000Z","version_change":"6.24.1 → 6.28.1","issue":{"uuid":"5431803498","node_id":"PR_kwDOSZtW-88AAAABDPDJLg","number":4,"state":"closed","title":"Bump the npm_and_yarn group across 3 directories with 25 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-12T06:49:28.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-12T06:48:50.000Z","updated_at":"2026-09-12T06:49:30.000Z","time_to_close":38,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"npm_and_yarn","update_count":25,"packages":[{"name":"qs","old_version":"6.14.2","new_version":"6.16.0","repository_url":"https://github.com/ljharb/qs"},{"name":"axios","old_version":"1.15.0","new_version":"1.20.0","repository_url":"https://github.com/axios/axios"},{"name":"maplibre-gl","old_version":"4.7.1","new_version":"6.9.0","repository_url":"https://github.com/maplibre/maplibre-gl-js"},{"name":"mysql2","old_version":"3.16.2","new_version":"3.23.1","repository_url":"https://github.com/sidorares/node-mysql2"},{"name":"postcss","old_version":"8.5.15","new_version":"8.5.28","repository_url":"https://github.com/postcss/postcss"},{"name":"sharp","old_version":"0.34.5","new_version":"0.35.4","repository_url":"https://github.com/lovell/sharp"},{"name":"systeminformation","old_version":"5.31.6","new_version":"5.31.7","repository_url":"https://github.com/sebhildebrandt/systeminformation"},{"name":"tar","old_version":"7.5.11","new_version":"7.5.22","repository_url":"https://github.com/isaacs/node-tar"},{"name":"vite","old_version":"6.4.2","new_version":"6.4.3","repository_url":"https://github.com/vitejs/vite"},{"name":"@adonisjs/bodyparser","old_version":"10.1.3","new_version":"10.1.5","repository_url":"https://github.com/adonisjs/bodyparser"},{"name":"@babel/core","old_version":"7.29.0","new_version":"7.29.7","repository_url":"https://github.com/babel/babel"},{"name":"brace-expansion","old_version":"1.1.12","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"@faker-js/faker","old_version":"9.9.0","new_version":"10.6.0","repository_url":"https://github.com/faker-js/faker"},{"name":"@grpc/grpc-js","old_version":"1.14.3","new_version":"1.14.4","repository_url":"https://github.com/grpc/grpc-node"},{"name":"@humanfs/node","old_version":"0.16.7","new_version":"0.16.8","repository_url":"https://github.com/humanwhocodes/humanfs"},{"name":"baseline-browser-mapping","old_version":"2.9.19","new_version":"2.11.22","repository_url":"https://github.com/web-platform-dx/baseline-browser-mapping"},{"name":"browserslist","old_version":"4.28.1","new_version":"4.28.9","repository_url":"https://github.com/browserslist/browserslist"},{"name":"undici","old_version":"6.24.1","new_version":"6.28.1","repository_url":"https://github.com/nodejs/undici"},{"name":"undici","old_version":"7.24.3","new_version":"7.29.1","repository_url":"https://github.com/nodejs/undici"},{"name":"fflate","old_version":"0.8.2","new_version":"0.8.3","repository_url":"https://github.com/101arrowz/fflate"},{"name":"ip-address","old_version":"10.1.0","new_version":"10.7.0","repository_url":"https://github.com/beaugunderson/ip-address"},{"name":"js-yaml","old_version":"4.1.1","new_version":"4.3.2","repository_url":"https://github.com/nodeca/js-yaml"},{"name":"protobufjs","old_version":"7.5.5","new_version":"7.6.6","repository_url":"https://github.com/protobufjs/protobuf.js"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 1 update in the /evez-ecosystem/evezart-repos/spectrumscan-api directory: [body-parser](https://github.com/expressjs/body-parser).\nBumps the npm_and_yarn group with 1 update in the /evez-ecosystem/evezart-repos/quantumseal-api directory: [body-parser](https://github.com/expressjs/body-parser).\nBumps the npm_and_yarn group with 22 updates in the /evez-ecosystem/evezart-repos/project-nomad-evez/admin directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [qs](https://github.com/ljharb/qs) | `6.14.2` | `6.16.0` |\n| [axios](https://github.com/axios/axios) | `1.15.0` | `1.20.0` |\n| [maplibre-gl](https://github.com/maplibre/maplibre-gl-js) | `4.7.1` | `6.9.0` |\n| [mysql2](https://github.com/sidorares/node-mysql2) | `3.16.2` | `3.23.1` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.15` | `8.5.28` |\n| [sharp](https://github.com/lovell/sharp) | `0.34.5` | `0.35.4` |\n| [systeminformation](https://github.com/sebhildebrandt/systeminformation) | `5.31.6` | `5.31.7` |\n| [tar](https://github.com/isaacs/node-tar) | `7.5.11` | `7.5.22` |\n| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `6.4.2` | `6.4.3` |\n| [@adonisjs/bodyparser](https://github.com/adonisjs/bodyparser) | `10.1.3` | `10.1.5` |\n| [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) | `7.29.0` | `7.29.7` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.12` | `1.1.18` |\n| [@faker-js/faker](https://github.com/faker-js/faker) | `9.9.0` | `10.6.0` |\n| [@grpc/grpc-js](https://github.com/grpc/grpc-node) | `1.14.3` | `1.14.4` |\n| [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node) | `0.16.7` | `0.16.8` |\n| [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) | `2.9.19` | `2.11.22` |\n| [browserslist](https://github.com/browserslist/browserslist) | `4.28.1` | `4.28.9` |\n| [undici](https://github.com/nodejs/undici) | `6.24.1` | `6.28.1` |\n| [undici](https://github.com/nodejs/undici) | `7.24.3` | `7.29.1` |\n| [fflate](https://github.com/101arrowz/fflate) | `0.8.2` | `0.8.3` |\n| [ip-address](https://github.com/beaugunderson/ip-address) | `10.1.0` | `10.7.0` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.1` | `4.3.2` |\n| [protobufjs](https://github.com/protobufjs/protobuf.js) | `7.5.5` | `7.6.6` |\n\n\nUpdates `body-parser` from 1.20.5 to 1.20.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/body-parser/releases\"\u003ebody-parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.20.8\u003c/h2\u003e\n\u003ch2\u003eImportant\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eSame code base as \u003ca href=\"https://github.com/expressjs/body-parser/releases/tag/1.20.7\"\u003e1.20.7\u003c/a\u003e. This was created to test the new release process.\u003c/strong\u003e\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eci: backport npm-publish workflow from master by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/769\"\u003eexpressjs/body-parser#769\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e1.20.8 by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/770\"\u003eexpressjs/body-parser#770\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.7...1.20.8\"\u003ehttps://github.com/expressjs/body-parser/compare/1.20.7...1.20.8\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.20.7\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocs: include security fix in 1.20.6 changes by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/747\"\u003eexpressjs/body-parser#747\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edeps: qs@~6.16.0 by \u003ca href=\"https://github.com/krzysdz\"\u003e\u003ccode\u003e@​krzysdz\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/761\"\u003eexpressjs/body-parser#761\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e1.20.7 by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/767\"\u003eexpressjs/body-parser#767\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.6...1.20.7\"\u003ehttps://github.com/expressjs/body-parser/compare/1.20.6...1.20.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.20.6\u003c/h2\u003e\n\u003ch2\u003eImportant: Security\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity fix for \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2025-13466\"\u003eCVE-2026-12590\u003c/a\u003e (\u003ca href=\"https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6\"\u003eGHSA-v422-hmwv-36x6\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: improve limit option validation by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/741\"\u003eexpressjs/body-parser#741\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.5...1.20.6\"\u003ehttps://github.com/expressjs/body-parser/compare/1.20.5...1.20.6\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/body-parser/blob/1.20.8/HISTORY.md\"\u003ebody-parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e1.20.8\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eSame code base as 1.20.7. This was created to test the new release process.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.20.7\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003edeps: qs@~6.16.0\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.20.6\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity fix for \u003ca href=\"https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6\"\u003eGHSA-v422-hmwv-36x6\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: improve \u003ccode\u003elimit\u003c/code\u003e option validation (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/698\"\u003e#698\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003eInvalid \u003ccode\u003elimit\u003c/code\u003e values (e.g. unparseable strings or \u003ccode\u003eNaN\u003c/code\u003e) now throw instead of being silently ignored, which previously disabled size limit enforcement\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003enull\u003c/code\u003e and \u003ccode\u003eundefined\u003c/code\u003e fall back to the default 100kb limit\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/5c08c2008eac79abddb8abfa5095491d02958d56\"\u003e\u003ccode\u003e5c08c20\u003c/code\u003e\u003c/a\u003e 1.20.8 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/770\"\u003e#770\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/0cea4f42a40996eafac441d0e71084afbe1407d4\"\u003e\u003ccode\u003e0cea4f4\u003c/code\u003e\u003c/a\u003e ci: backport npm-publish workflow from master (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/769\"\u003e#769\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/0f0f0d7f96fc7444407aef85a6d1fa363279e654\"\u003e\u003ccode\u003e0f0f0d7\u003c/code\u003e\u003c/a\u003e 1.20.7 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/767\"\u003e#767\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/355eb04ade7c27f57f93a0e90e26ed6f121becc5\"\u003e\u003ccode\u003e355eb04\u003c/code\u003e\u003c/a\u003e deps: qs@~6.16.0 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/761\"\u003e#761\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/8be369a5f8b0f4070ebb7a0ae9aca12db9d8f947\"\u003e\u003ccode\u003e8be369a\u003c/code\u003e\u003c/a\u003e docs: include security fix in 1.20.6 changes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/5cc4fb8867c93a3aa4455927e38858c9ab89ff43\"\u003e\u003ccode\u003e5cc4fb8\u003c/code\u003e\u003c/a\u003e 1.20.6 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/746\"\u003e#746\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/3492672eee593d5c158f239b6e9115498a5dbeac\"\u003e\u003ccode\u003e3492672\u003c/code\u003e\u003c/a\u003e fix: improve limit option validation (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/741\"\u003e#741\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.5...1.20.8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for body-parser since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `body-parser` from 1.20.5 to 1.20.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/body-parser/releases\"\u003ebody-parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.20.8\u003c/h2\u003e\n\u003ch2\u003eImportant\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eSame code base as \u003ca href=\"https://github.com/expressjs/body-parser/releases/tag/1.20.7\"\u003e1.20.7\u003c/a\u003e. This was created to test the new release process.\u003c/strong\u003e\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eci: backport npm-publish workflow from master by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/769\"\u003eexpressjs/body-parser#769\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e1.20.8 by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/770\"\u003eexpressjs/body-parser#770\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.7...1.20.8\"\u003ehttps://github.com/expressjs/body-parser/compare/1.20.7...1.20.8\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.20.7\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocs: include security fix in 1.20.6 changes by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/747\"\u003eexpressjs/body-parser#747\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edeps: qs@~6.16.0 by \u003ca href=\"https://github.com/krzysdz\"\u003e\u003ccode\u003e@​krzysdz\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/761\"\u003eexpressjs/body-parser#761\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e1.20.7 by \u003ca href=\"https://github.com/UlisesGascon\"\u003e\u003ccode\u003e@​UlisesGascon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/767\"\u003eexpressjs/body-parser#767\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.6...1.20.7\"\u003ehttps://github.com/expressjs/body-parser/compare/1.20.6...1.20.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.20.6\u003c/h2\u003e\n\u003ch2\u003eImportant: Security\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity fix for \u003ca href=\"https://www.cve.org/CVERecord?id=CVE-2025-13466\"\u003eCVE-2026-12590\u003c/a\u003e (\u003ca href=\"https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6\"\u003eGHSA-v422-hmwv-36x6\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: improve limit option validation by \u003ca href=\"https://github.com/Phillip9587\"\u003e\u003ccode\u003e@​Phillip9587\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/expressjs/body-parser/pull/741\"\u003eexpressjs/body-parser#741\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.5...1.20.6\"\u003ehttps://github.com/expressjs/body-parser/compare/1.20.5...1.20.6\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/expressjs/body-parser/blob/1.20.8/HISTORY.md\"\u003ebody-parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e1.20.8\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eSame code base as 1.20.7. This was created to test the new release process.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.20.7\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003edeps: qs@~6.16.0\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.20.6\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity fix for \u003ca href=\"https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6\"\u003eGHSA-v422-hmwv-36x6\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: improve \u003ccode\u003elimit\u003c/code\u003e option validation (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/698\"\u003e#698\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003eInvalid \u003ccode\u003elimit\u003c/code\u003e values (e.g. unparseable strings or \u003ccode\u003eNaN\u003c/code\u003e) now throw instead of being silently ignored, which previously disabled size limit enforcement\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003enull\u003c/code\u003e and \u003ccode\u003eundefined\u003c/code\u003e fall back to the default 100kb limit\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/5c08c2008eac79abddb8abfa5095491d02958d56\"\u003e\u003ccode\u003e5c08c20\u003c/code\u003e\u003c/a\u003e 1.20.8 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/770\"\u003e#770\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/0cea4f42a40996eafac441d0e71084afbe1407d4\"\u003e\u003ccode\u003e0cea4f4\u003c/code\u003e\u003c/a\u003e ci: backport npm-publish workflow from master (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/769\"\u003e#769\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/0f0f0d7f96fc7444407aef85a6d1fa363279e654\"\u003e\u003ccode\u003e0f0f0d7\u003c/code\u003e\u003c/a\u003e 1.20.7 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/767\"\u003e#767\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/355eb04ade7c27f57f93a0e90e26ed6f121becc5\"\u003e\u003ccode\u003e355eb04\u003c/code\u003e\u003c/a\u003e deps: qs@~6.16.0 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/761\"\u003e#761\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/8be369a5f8b0f4070ebb7a0ae9aca12db9d8f947\"\u003e\u003ccode\u003e8be369a\u003c/code\u003e\u003c/a\u003e docs: include security fix in 1.20.6 changes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/5cc4fb8867c93a3aa4455927e38858c9ab89ff43\"\u003e\u003ccode\u003e5cc4fb8\u003c/code\u003e\u003c/a\u003e 1.20.6 (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/746\"\u003e#746\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/expressjs/body-parser/commit/3492672eee593d5c158f239b6e9115498a5dbeac\"\u003e\u003ccode\u003e3492672\u003c/code\u003e\u003c/a\u003e fix: improve limit option validation (\u003ca href=\"https://redirect.github.com/expressjs/body-parser/issues/741\"\u003e#741\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/expressjs/body-parser/compare/1.20.5...1.20.8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for body-parser since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `qs` from 6.14.2 to 6.16.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ljharb/qs/blob/main/CHANGELOG.md\"\u003eqs's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003cstrong\u003e6.16.0\u003c/strong\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[New] \u003ccode\u003estringify\u003c/code\u003e: add a \u003ccode\u003edepth\u003c/code\u003e option to bound recursion depth (default \u003ccode\u003eInfinity\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003e[Fix] stringify: serialize Date values when a filter is provided\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: enforce \u003ccode\u003earrayLimit\u003c/code\u003e on comma groups under \u003ccode\u003e[]=\u003c/code\u003e when \u003ccode\u003ethrowOnLimitExceeded\u003c/code\u003e is set\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: flatten a collection appended to an overflowed array (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/571\"\u003e#571\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eutils\u003c/code\u003e: \u003ccode\u003eisBuffer\u003c/code\u003e: do not invoke a non-callable \u003ccode\u003econstructor.isBuffer\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003estringify\u003c/code\u003e: do not let \u003ccode\u003eallowEmptyArrays\u003c/code\u003e skip cycle detection (or drop own keys) on an empty array with own properties\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003estringify\u003c/code\u003e: encode dots in a top-level key with a primitive value when encodeDotInKeys is set (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/562\"\u003e#562\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Docs] threat model: clarify \u003ccode\u003estringify\u003c/code\u003e deep-nesting DoS is caller-bounded\u003c/li\u003e\n\u003cli\u003e[Docs] clarify \u003ccode\u003earrayLimit\u003c/code\u003e is a representation threshold, not an element-count cap\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003eparse\u003c/code\u003e: remove a test that pinned \u003ccode\u003e[]=\u003c/code\u003e comma groups escaping \u003ccode\u003earrayLimit\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003estringify\u003c/code\u003e: pin current \u003ccode\u003eencodeDotInKeys\u003c/code\u003e separator-dot behavior\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003eevalmd\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003cstrong\u003e6.15.3\u003c/strong\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: enforce \u003ccode\u003ethrowOnLimitExceeded\u003c/code\u003e for cumulative array growth via \u003ccode\u003ecombine\u003c/code\u003e/\u003ccode\u003emerge\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eutils\u003c/code\u003e: respect encoding of surrogate pairs across chunks (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/559\"\u003e#559\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Robustness] \u003ccode\u003eparse\u003c/code\u003e: throw the \u003ccode\u003earrayLimit\u003c/code\u003e error before splitting oversized comma values\u003c/li\u003e\n\u003cli\u003e[Robustness] \u003ccode\u003eutils.merge\u003c/code\u003e / \u003ccode\u003eutils.assign\u003c/code\u003e: avoid invoking \u003ccode\u003e__proto__\u003c/code\u003e setter when copying own properties\u003c/li\u003e\n\u003cli\u003e[Robustness] \u003ccode\u003eutils\u003c/code\u003e: enforce \u003ccode\u003earrayLimit\u003c/code\u003e consistently across \u003ccode\u003emerge\u003c/code\u003e's array paths\u003c/li\u003e\n\u003cli\u003e[Perf] \u003ccode\u003eutils\u003c/code\u003e: make \u003ccode\u003ecompact\u003c/code\u003e O(n) via a side-channel visited-set instead of \u003ccode\u003eArray.indexOf\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Deps] update \u003ccode\u003eside-channel\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003emock-property\u003c/code\u003e, \u003ccode\u003etape\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] \u003ccode\u003eparse\u003c/code\u003e: characterize current lenient handling of unbalanced bracket keys (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/558\"\u003e#558\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003cstrong\u003e6.15.2\u003c/strong\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] \u003ccode\u003estringify\u003c/code\u003e: skip null/undefined entries in \u003ccode\u003earrayFormat: 'comma'\u003c/code\u003e + \u003ccode\u003eencodeValuesOnly\u003c/code\u003e instead of crashing in \u003ccode\u003eencoder\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003estringify\u003c/code\u003e: use configured \u003ccode\u003edelimiter\u003c/code\u003e after \u003ccode\u003echarsetSentinel\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/555\"\u003e#555\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003estringify\u003c/code\u003e: apply \u003ccode\u003eformatter\u003c/code\u003e to encoded key under \u003ccode\u003estrictNullHandling\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/554\"\u003e#554\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003estringify\u003c/code\u003e: skip null/undefined filter-array entries instead of crashing in \u003ccode\u003eencoder\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/551\"\u003e#551\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: handle nested bracket groups and add regression tests (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/530\"\u003e#530\u003c/a\u003e); changes output for some unbalanced bracket keys (see \u003ca href=\"https://redirect.github.com/ljharb/qs/issues/558\"\u003e#558\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[readme] fix grammar (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/550\"\u003e#550\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] add regression tests for keys containing percent-encoded bracket text\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003cstrong\u003e6.15.1\u003c/strong\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eparse\u003c/code\u003e: \u003ccode\u003eparameterLimit: Infinity\u003c/code\u003e with \u003ccode\u003ethrowOnLimitExceeded: true\u003c/code\u003e silently drops all parameters\u003c/li\u003e\n\u003cli\u003e[Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eiconv-lite\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e[Tests] increase coverage\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003cstrong\u003e6.15.0\u003c/strong\u003e\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[New] \u003ccode\u003eparse\u003c/code\u003e: add \u003ccode\u003estrictMerge\u003c/code\u003e option to wrap object/primitive conflicts in an array (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/425\"\u003e#425\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/ljharb/qs/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Fix] \u003ccode\u003eduplicates\u003c/code\u003e option should not apply to bracket notation keys (\u003ca href=\"https://redirect.github.com/ljharb/qs/issues/514\"\u003e#514\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/qs/commit/bb9379e01fad04c601478acd6152143cb20c984b\"\u003e\u003ccode\u003ebb9379e\u003c/code\u003e\u003c/a\u003e v6.16.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/qs/commit/62fd25480b0b0d9c0a667ee67e13608a363f5d0e\"\u003e\u003ccode\u003e62fd254\u003c/code\u003e\u003c/a\u003e [Fix] stringify: serialize Date values when a filter is provided\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/qs/commit/8859c37470e11b42b547b275e4e9bd0bc8cc5464\"\u003e\u003ccode\u003e8859c37\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003eparse\u003c/code\u003e: enforce \u003ccode\u003earrayLimit\u003c/code\u003e on comma groups under \u003ccode\u003e[]=\u003c/code\u003e when `throwOn...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/qs/commit/8079adc7e7cf84b8289898d1b18877160de67d40\"\u003e\u003ccode\u003e8079adc\u003c/code\u003e\u003c/a\u003e [Tests] \u003ccode\u003eparse\u003c/code\u003e: remove a test that pinned \u003ccode\u003e[]=\u003c/code\u003e comma groups escaping `array...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/qs/commit/d56f48ca137b1bf6385da749b1044246ae142f19\"\u003e\u003ccode\u003ed56f48c\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003eparse\u003c/code\u003e: flatten a collection appended to an overflowed array\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/qs/commit/e83d321ffafb38cf210683ac31714fce6ce1c6c6\"\u003e\u003ccode\u003ee83d321\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003eutils\u003c/code\u003e: \u003ccode\u003eisBuffer\u003c/code\u003e: do not invoke a non-callable \u003ccode\u003econstructor.isBuffer\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/qs/commit/7e87a07c2c62301dd8fc2e099ac38227bc96c74c\"\u003e\u003ccode\u003e7e87a07\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eeslint\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/qs/commit/9a76af21604a4ece315e58ba251b93cf0fd944f2\"\u003e\u003ccode\u003e9a76af2\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003eevalmd\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/qs/commit/3a890d4ecd3deb72a45d90be36f4f8c5970467c7\"\u003e\u003ccode\u003e3a890d4\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003eeslint\u003c/code\u003e, \u003ccode\u003eevalmd\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ljharb/qs/commit/b433a9b1633e1c3348aa53c513589a5bfe47f113\"\u003e\u003ccode\u003eb433a9b\u003c/code\u003e\u003c/a\u003e [Fix] \u003ccode\u003estringify\u003c/code\u003e: do not let \u003ccode\u003eallowEmptyArrays\u003c/code\u003e skip cycle detection (or dro...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ljharb/qs/compare/v6.14.2...v6.16.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `axios` from 1.15.0 to 1.20.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/axios/axios/releases\"\u003eaxios's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.20.0 — August 19, 2026\u003c/h2\u003e\n\u003cp\u003eThis release hardens runtime option handling, adds RFC 9110 status-code aliases, fixes Node.js and XHR reliability issues, and refreshes project tooling and documentation.\u003c/p\u003e\n\u003ch2\u003e⚠️ Breaking Changes \u0026amp; Deprecations\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHTTP Status Naming: Added ContentTooLarge (413) and UnprocessableContent (422), while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11082\"\u003e#11082\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRuntime Option Handling: Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects. This also clarifies Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection; see the PR for documented compatibility effects. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11141\"\u003e#11141\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eInterceptor Lifecycle: Prevented unbounded handler-array growth by trimming trailing ejected interceptors without changing iteration semantics, and kept interceptor operations safe when the public handlers field is nullish. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11087\"\u003e#11087\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11118\"\u003e#11118\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequest Error Preservation: Prevented custom Error.prepareStackTrace implementations that return non-string values from replacing the original request failure with an unrelated TypeError. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11109\"\u003e#11109\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eXHR Reliability: Navigation-canceled requests now reject with ECONNABORTED instead of resolving with status 0, while successful downloads flush their final progress callback during the live loadend dispatch. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11094\"\u003e#11094\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11121\"\u003e#11121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNode.js Socket Memory: Removed request-context retention from per-socket error listeners, preventing completed response data from being pinned for the lifetime of pooled keep-alive sockets. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11091\"\u003e#11091\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCore Methods and HTTP Errors: Prevented structural method-header buckets from leaking into outgoing headers, standardized invalid DNS lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE, and corrected the timeoutErrorMessage merge strategy. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11096\"\u003e#11096\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔧 Maintenance \u0026amp; Chores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDependencies: Updated fast-uri, postcss, js-yaml, mocha, development-tooling groups, and GitHub Actions dependencies. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11092\"\u003e#11092\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11098\"\u003e#11098\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11099\"\u003e#11099\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11106\"\u003e#11106\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11107\"\u003e#11107\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11122\"\u003e#11122\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11123\"\u003e#11123\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11126\"\u003e#11126\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11127\"\u003e#11127\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11133\"\u003e#11133\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11140\"\u003e#11140\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11143\"\u003e#11143\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11144\"\u003e#11144\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDocumentation: Applied the v1.19.0 documentation updates, added the missing fs import to the README stream example, introduced localized global search, and repaired the interceptor test link. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11101\"\u003e#11101\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11113\"\u003e#11113\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11097\"\u003e#11097\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11119\"\u003e#11119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSponsorship: Updated sponsorship links and data and added ScrapingBee as a sponsor. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11124\"\u003e#11124\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11136\"\u003e#11136\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11137\"\u003e#11137\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCI and Release: Switched ESM smoke tests to locked dependencies and synchronized package and runtime version metadata for v1.20.0. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11128\"\u003e#11128\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11152\"\u003e#11152\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🌟 New Contributors\u003c/h2\u003e\n\u003cp\u003eWe are thrilled to welcome our new contributors. Thank you for helping improve axios:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yens1\"\u003e\u003ccode\u003e@​yens1\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11109\"\u003e#11109\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Sasireddy001\"\u003e\u003ccode\u003e@​Sasireddy001\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11113\"\u003e#11113\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ari-token-security\"\u003e\u003ccode\u003e@​ari-token-security\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11094\"\u003e#11094\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timothyokooboh\"\u003e\u003ccode\u003e@​timothyokooboh\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11097\"\u003e#11097\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gi9439041-png\"\u003e\u003ccode\u003e@​gi9439041-png\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11119\"\u003e#11119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Hashim1999164\"\u003e\u003ccode\u003e@​Hashim1999164\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11082\"\u003e#11082\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/v-dev-cl\"\u003e\u003ccode\u003e@​v-dev-cl\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11091\"\u003e#11091\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0h1tb\"\u003e\u003ccode\u003e@​r0h1tb\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11118\"\u003e#11118\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ostapondo\"\u003e\u003ccode\u003e@​ostapondo\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11121\"\u003e#11121\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFull Changelog (\u003ca href=\"https://github.com/axios/axios/compare/v1.19.0...v1.20.0\"\u003ehttps://github.com/axios/axios/compare/v1.19.0...v1.20.0\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003ev1.19.0 - July 22, 2026\u003c/h2\u003e\n\u003cp\u003eThis release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMultipart Form Data: Raised the form-data dependency floor to ^4.0.6, preventing fresh installations from resolving versions affected by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (\u003ca href=\"https://github.com/advisories/GHSA-hmw2-7cc7-3qxx\"\u003ehttps://github.com/advisories/GHSA-hmw2-7cc7-3qxx\u003c/a\u003e). (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11028\"\u003e#11028\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/axios/axios/blob/v1.x/CHANGELOG.md\"\u003eaxios's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog\u003c/h1\u003e\n\u003ch2\u003ev1.19.0 — July 22, 2026\u003c/h2\u003e\n\u003cp\u003eThis release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.\u003c/p\u003e\n\u003ch2\u003e🔒 Security Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMultipart Form Data: Raised the form-data dependency floor to ^4.0.6, preventing fresh installations from resolving versions affected by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (\u003ca href=\"https://github.com/advisories/GHSA-hmw2-7cc7-3qxx\"\u003ehttps://github.com/advisories/GHSA-hmw2-7cc7-3qxx\u003c/a\u003e). (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11028\"\u003e#11028\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚀 New Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eConfiguration Extensibility: Preserved own-enumerable symbol-keyed fields through mergeConfig and added a generic params type across public TypeScript declarations, responses, errors,\nadapters, and serializers. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11043\"\u003e#11043\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11081\"\u003e#11081\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHeader Parameter Parsing: Added the opt-in AxiosHeaders.parseParameters() parser for quote-aware, RFC-style HTTP parameter parsing while preserving legacy parsing behavior. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11051\"\u003e#11051\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHTTP Status Codes: Added the missing Cloudflare 520 WebServerReturnsAnUnknownError status and matching ESM/CJS declarations. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11067\"\u003e#11067\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eForm Data Conversion: Limited formDataToJSON path splitting to dot and bracket notation, preserving literal punctuation in keys, and removed browser-facing Buffer.from usage from toFormData to avoid unnecessary polyfills. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11006\"\u003e#11006\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11018\"\u003e#11018\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eProxy Bypass: Canonicalized IPv4 shorthand, octal, and hexadecimal forms during NO_PROXY matching and honored * entries within comma- or space-separated bypass lists. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11029\"\u003e#11029\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11053\"\u003e#11053\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eCancellation: Propagated already-aborted input signals immediately when composing abort signals. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11035\"\u003e#11035\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eHeader Handling: Preserved empty first values for duplicate singleton headers and made AxiosHeaders#getSetCookie() consistently return arrays for present values. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11036\"\u003e#11036\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11037\"\u003e#11037\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eURL Handling: Included normalized, safely redacted offending URLs in malformed-protocol errors and removed repeated trailing slashes when combining base URLs. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11008\"\u003e#11008\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11038\"\u003e#11038\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eProgress Events: Clamped malformed negative progress values to zero and ensured final Node.js download progress events are delivered before streamed responses close. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11039\"\u003e#11039\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11040\"\u003e#11040\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eError and JSON Serialization: Serialized Set values as arrays in JSON-compatible snapshots and synthesized useful AxiosError messages from otherwise-empty AggregateError instances. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11044\"\u003e#11044\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11059\"\u003e#11059\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eContent-Length Enforcement: Corrected base64 data: URL size estimation so maxContentLength is enforced consistently by the HTTP and Fetch adapters. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11061\"\u003e#11061\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSynchronous Interceptors: Prevented requests from being dispatched after synchronous request interceptors fail unless their paired rejection handler resolves successfully. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11071\"\u003e#11071\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔧 Maintenance \u0026amp; Chores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDependencies: Updated development and test tooling, the docs fixture's Axios version, and GitHub Actions integrations including Checkout, Setup Node, Setup Deno, and Zizmor. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11031\"\u003e#11031\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11055\"\u003e#11055\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11056\"\u003e#11056\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11058\"\u003e#11058\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11079\"\u003e#11079\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11080\"\u003e#11080\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11088\"\u003e#11088\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11089\"\u003e#11089\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11090\"\u003e#11090\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBuild Outputs: Limited sourcemap generation to published minified bundles, removing broken map references from non-minified builds. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11054\"\u003e#11054\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eForm Data Internals: Centralized FormData header handling and made the Node.js adapter tolerate getHeaders() returning undefined under the content-only policy. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11062\"\u003e#11062\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeveloper Experience: Ignored common local AI-tooling directories and fixed a constant-reassignment crash when the development sandbox serves its root path. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11032\"\u003e#11032\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11073\"\u003e#11073\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDocumentation: Updated sponsor information, clarified that baseURL is not a path-security boundary, scoped provenance claims to attested releases, and corrected the configuration-defaults documentation. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11041\"\u003e#11041\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11068\"\u003e#11068\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11076\"\u003e#11076\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11078\"\u003e#11078\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePublishing: Simplified v1 publishing to use the npm version bundled with Node.js 26 and updated package metadata for the 1.19.0 release. (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11083\"\u003e#11083\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/axios/axios/issues/11095\"\u003e#11095\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🌟 New Contributors\u003c/h2\u003e\n\u003cp\u003eWe are thrilled to welcome our new contributors. Thank you for helping improve Axios:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/afonsojramos\"\u003e\u003ccode\u003e@​afonsojramos\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11028\"\u003e#11028\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11006\"\u003e#11006\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yassertawfik4\"\u003e\u003ccode\u003e@​yassertawfik4\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11024\"\u003e#11024\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AnandSundar\"\u003e\u003ccode\u003e@​AnandSundar\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11029\"\u003e#11029\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lin-hongkuan\"\u003e\u003ccode\u003e@​lin-hongkuan\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11035\"\u003e#11035\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Wali007-lab\"\u003e\u003ccode\u003e@​Wali007-lab\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11054\"\u003e#11054\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/magicdawn\"\u003e\u003ccode\u003e@​magicdawn\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11043\"\u003e#11043\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/84a9f3b9a4f3244b8c8e818f557d64c7b964fb25\"\u003e\u003ccode\u003e84a9f3b\u003c/code\u003e\u003c/a\u003e chore(release): prepare release 1.20.0 (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11152\"\u003e#11152\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/e6824eec5fcf9da467a9792724396badc490c469\"\u003e\u003ccode\u003ee6824ee\u003c/code\u003e\u003c/a\u003e fix: core methodList, HTTP adapter errors, and add tests (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11096\"\u003e#11096\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/d8a919fd81403d59058c0e9dbefc540407dee83f\"\u003e\u003ccode\u003ed8a919f\u003c/code\u003e\u003c/a\u003e fix(xhr): flush final progress during the live loadend dispatch (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11121\"\u003e#11121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/2d2a21af8a433089474a2149781799c93acbcf3c\"\u003e\u003ccode\u003e2d2a21a\u003c/code\u003e\u003c/a\u003e fix(interceptors): tolerate nullish handlers in syncHandlerEntries (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11118\"\u003e#11118\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a\"\u003e\u003ccode\u003ed19040b\u003c/code\u003e\u003c/a\u003e fix: harden runtime option handling (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11141\"\u003e#11141\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/e0a02dd16671deabe2b809334d4c2ebede29a233\"\u003e\u003ccode\u003ee0a02dd\u003c/code\u003e\u003c/a\u003e chore(deps): bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 in the github-...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/d10cb3aa3cda1d78721ddf96be590478df26cd81\"\u003e\u003ccode\u003ed10cb3a\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump the development_dependencies group with 4 updates (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11143\"\u003e#11143\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/2c94646eb7cb7ab9dcb2aefdb04ab1b040c28e16\"\u003e\u003ccode\u003e2c94646\u003c/code\u003e\u003c/a\u003e chore(deps): bump js-yaml and mocha in /tests/smoke/cjs (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11133\"\u003e#11133\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/76c12bce5a4fe9a45bef9a5bf2baaf599d7d382e\"\u003e\u003ccode\u003e76c12bc\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump js-yaml from 4.3.0 to 4.3.1 (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11140\"\u003e#11140\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/axios/axios/commit/ba98559a7f5a18e531b5762387e5957bd281af3d\"\u003e\u003ccode\u003eba98559\u003c/code\u003e\u003c/a\u003e docs: add ScrapingBee sponsor (\u003ca href=\"https://redirect.github.com/axios/axios/issues/11137\"\u003e#11137\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/axios/axios/compare/v1.15.0...v1.20.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `maplibre-gl` from 4.7.1 to 6.9.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/maplibre/maplibre-gl-js/releases\"\u003emaplibre-gl's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.9.0\u003c/h2\u003e\n\u003ch3\u003e✨ Features and improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImproved support for drawing the letters of Devanagari, Khmer, Burmese and the other complex scripts and also draws Arabic and Hebrew labels correctly without loading a right-to-left text plugin, which deprecates \u003ccode\u003esetRTLTextPlugin\u003c/code\u003e and \u003ccode\u003egetRTLTextPluginStatus\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8343\"\u003e#8343\u003c/a\u003e) (by \u003ca href=\"https://github.com/HarelM\"\u003e\u003ccode\u003e@​HarelM\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRead sprite and image pixels back through an \u003ccode\u003eOffscreenCanvas\u003c/code\u003e where available, removing a main-thread stall of tens of milliseconds on GPU-accelerated browsers when a sprite loads (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8339\"\u003e#8339\u003c/a\u003e) (by \u003ca href=\"https://github.com/cherenkov\"\u003e\u003ccode\u003e@​cherenkov\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSkip clipping masks for layers hidden at the current zoom and stop re-binding dynamic buffers on cached vertex array binds, removing redundant WebGL calls every frame (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8369\"\u003e#8369\u003c/a\u003e) (by \u003ca href=\"https://github.com/johncarmack1984\"\u003e\u003ccode\u003e@​johncarmack1984\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRe-render at most one stale terrain drape per frame and keep drapes that differ only by zoom while the map moves, so a finger lift over terrain no longer re-renders every tile at once (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8368\"\u003e#8368\u003c/a\u003e) (by \u003ca href=\"https://github.com/johncarmack1984\"\u003e\u003ccode\u003e@​johncarmack1984\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🐞 Bug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003esetStyle()\u003c/code\u003e throwing while terrain is still loading because an intermediate render tried to compile a terrain shader before the replacement style initialized its projection (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/6824\"\u003e#6824\u003c/a\u003e) (by \u003ca href=\"https://github.com/miakh\"\u003e\u003ccode\u003e@​miakh\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix queued GeoJSON \u003ccode\u003eupdateData\u003c/code\u003e property removals throwing after geometry-only updates or retaining previously updated values (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8372\"\u003e#8372\u003c/a\u003e) (by \u003ca href=\"https://github.com/jokrasno\"\u003e\u003ccode\u003e@​jokrasno\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eTreat camera options passed as \u003ccode\u003eundefined\u003c/code\u003e as not given in \u003ccode\u003ejumpTo\u003c/code\u003e, \u003ccode\u003eeaseTo\u003c/code\u003e and \u003ccode\u003eflyTo\u003c/code\u003e; they were coerced to NaN (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8373\"\u003e#8373\u003c/a\u003e) (by \u003ca href=\"https://github.com/vlumi\"\u003e\u003ccode\u003e@​vlumi\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix a \u003ccode\u003eNot implemented.\u003c/code\u003e error that broke panning and zooming when the projection was changed while the camera was moving, on maps with terrain enabled or a \u003ccode\u003etransformCameraUpdate\u003c/code\u003e callback (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8351\"\u003e#8351\u003c/a\u003e) (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix a map created inside a hidden container staying at the \u003ccode\u003e400x300\u003c/code\u003e fallback size when the container is shown before the resize observer's first notification is delivered (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8277\"\u003e#8277\u003c/a\u003e) (by \u003ca href=\"https://github.com/spliffone\"\u003e\u003ccode\u003e@​spliffone\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eMercatorTransform\u003c/code\u003e throwing when it is resized to a zero width, and skip the matrix calculation of every projection while the transform has a zero width or height (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8374\"\u003e#8374\u003c/a\u003e) (by \u003ca href=\"https://github.com/avosa\"\u003e\u003ccode\u003e@​avosa\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix every style update opening a redundant sky and light transition, which kept \u003ccode\u003eidle\u003c/code\u003e from firing for the transition duration after the map was otherwise done, and could ease the sky and the light on a different curve from the layers (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8348\"\u003e#8348\u003c/a\u003e) (by \u003ca href=\"https://github.com/cherenkov\"\u003e\u003ccode\u003e@​cherenkov\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix DOM sanitization for iframe and srcdoc (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8396\"\u003e#8396\u003c/a\u003e) (by \u003ca href=\"https://github.com/HarelM\"\u003e\u003ccode\u003e@​HarelM\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.8.0\u003c/h2\u003e\n\u003ch3\u003e✨ Features and improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003emap.getStyleUrl()\u003c/code\u003e, which returns the URL the style was loaded from, or \u003ccode\u003enull\u003c/code\u003e when the style was given as an object (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/7109\"\u003e#7109\u003c/a\u003e) (by \u003ca href=\"https://github.com/bradymadden97\"\u003e\u003ccode\u003e@​bradymadden97\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/giswqs\"\u003e\u003ccode\u003e@​giswqs\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSample terrain render-to-texture output through mipmaps with trilinear filtering, so draped layers stop shimmering and aliasing at high pitch (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8328\"\u003e#8328\u003c/a\u003e, continues \u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/7673\"\u003e#7673\u003c/a\u003e) (by \u003ca href=\"https://github.com/AveryanAlex\"\u003e\u003ccode\u003e@​AveryanAlex\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBuild the \u003ccode\u003eIntl.Segmenter\u003c/code\u003e instances used for text shaping on first use instead of at import, shaving several milliseconds off loading MapLibre on the main thread (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8337\"\u003e#8337\u003c/a\u003e) (by \u003ca href=\"https://github.com/cherenkov\"\u003e\u003ccode\u003e@​cherenkov\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eLink shader programs before reading their compile status, so the driver can overlap the compiles and the main thread waits less on shader compilation (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8338\"\u003e#8338\u003c/a\u003e) (by \u003ca href=\"https://github.com/cherenkov\"\u003e\u003ccode\u003e@​cherenkov\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBuild the default \u003ccode\u003eMarker\u003c/code\u003e pin once and clone it per marker, so creating many default markers takes roughly half the constructor time (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8340\"\u003e#8340\u003c/a\u003e) (by \u003ca href=\"https://github.com/cherenkov\"\u003e\u003ccode\u003e@​cherenkov\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd SDF rendering support for fill patterns, using \u003ccode\u003efill-color\u003c/code\u003e as the foreground color (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/7747\"\u003e#7747\u003c/a\u003e) (by \u003ca href=\"https://github.com/bradymadden97\"\u003e\u003ccode\u003e@​bradymadden97\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/deniial00\"\u003e\u003ccode\u003e@​deniial00\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eWarn once when the canvas is clamped to \u003ccode\u003emaxCanvasSize\u003c/code\u003e, which previously lowered the rendered resolution silently (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8200\"\u003e#8200\u003c/a\u003e) (by \u003ca href=\"https://github.com/str0kes\"\u003e\u003ccode\u003e@​str0kes\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🐞 Bug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix a marker's popup jumping to another world copy when the marker is moved across the antimeridian on a zoomed-out map (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/5655\"\u003e#5655\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8326\"\u003e#8326\u003c/a\u003e, continues \u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/5956\"\u003e#5956\u003c/a\u003e) (by \u003ca href=\"https://github.com/yuiseki\"\u003e\u003ccode\u003e@​yuiseki\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix terrain drape textures not being refreshed after zoom changes, causing stale rendering at the new zoom level (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8251\"\u003e#8251\u003c/a\u003e) (by \u003ca href=\"https://github.com/patte\"\u003e\u003ccode\u003e@​patte\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix a gap between the sky and the ground at high pitch while globe transitions to mercator (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/7382\"\u003e#7382\u003c/a\u003e) (by \u003ca href=\"https://github.com/birkskyum\"\u003e\u003ccode\u003e@​birkskyum\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eTreat an empty tile response (e.g. HTTP 204) as no data: raster-DEM tiles now load without elevation instead of failing with a \u003ccode\u003edem dimension mismatch\u003c/code\u003e error, and empty raster tiles render as transparent (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/1551\"\u003e#1551\u003c/a\u003e) (by \u003ca href=\"https://github.com/clement-igonet\"\u003e\u003ccode\u003e@​clement-igonet\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eValidate the \u003ccode\u003ebefore\u003c/code\u003e layer in \u003ccode\u003emap.moveLayer\u003c/code\u003e before reordering, so passing the id of a layer that does not exist leaves the layer order untouched instead of dropping the moved layer out of it (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8301\"\u003e#8301\u003c/a\u003e) (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix visible seams between hillshade tiles when using linear interpolation. (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8302\"\u003e#8302\u003c/a\u003e) (by \u003ca href=\"https://github.com/Turbo87\"\u003e\u003ccode\u003e@​Turbo87\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix the map freezing when a render task throws an error (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/6093\"\u003e#6093\u003c/a\u003e) (by \u003ca href=\"https://github.com/UberMouse\"\u003e\u003ccode\u003e@​UberMouse\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003egetCameraAltitude()\u003c/code\u003e returning \u003ccode\u003eNaN\u003c/code\u003e under \u003ccode\u003eglobe\u003c/code\u003e and \u003ccode\u003evertical-perspective\u003c/code\u003e, which disabled marker terrain occlusion and the camera terrain check; the altitude now follows the sphere (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/6584\"\u003e#6584\u003c/a\u003e) (by \u003ca href=\"https://github.com/bigmistqke\"\u003e\u003ccode\u003e@​bigmistqke\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/patte\"\u003e\u003ccode\u003e@​patte\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDraw an elevated symbol on globe when the symbol itself is in view but the ground under it is behind the horizon; occlusion now follows the line of sight to the elevated point (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8253\"\u003e#8253\u003c/a\u003e) (by \u003ca href=\"https://github.com/clement-igonet\"\u003e\u003ccode\u003e@​clement-igonet\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003esetTiles\u003c/code\u003e producing stale tile URLs when \u003ccode\u003eloadTile\u003c/code\u003e runs in the same frame (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8323\"\u003e#8323\u003c/a\u003e) (by \u003ca href=\"https://github.com/johncarmack1984\"\u003e\u003ccode\u003e@​johncarmack1984\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/nostrorom\"\u003e\u003ccode\u003e@​nostrorom\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eKeep the tile under an elevated symbol from being culled near the horizon, so a symbol with a large \u003ccode\u003esymbol-height-offset\u003c/code\u003e stays visible until it is behind the planet (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8316\"\u003e#8316\u003c/a\u003e) (by \u003ca href=\"https://github.com/clement-igonet\"\u003e\u003ccode\u003e@​clement-igonet\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.7.0\u003c/h2\u003e\n\u003ch3\u003e✨ Features and improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport the style specification's \u003ccode\u003efont-faces\u003c/code\u003e property, with \u003ccode\u003emap.setFontFaces\u003c/code\u003e and \u003ccode\u003emap.getFontFaces\u003c/code\u003e and improve complex script languages such as Devanagari, Khmer, Burmese and Hebrew (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8237\"\u003e#8237\u003c/a\u003e)  (by \u003ca href=\"https://github.com/HarelM\"\u003e\u003ccode\u003e@​HarelM\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/maplibre/maplibre-gl-js/blob/main/CHANGELOG.md\"\u003emaplibre-gl's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e6.9.0\u003c/h2\u003e\n\u003ch3\u003e✨ Features and improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImproved support for drawing the letters of Devanagari, Khmer, Burmese and the other complex scripts and also draws Arabic and Hebrew labels correctly without loading a right-to-left text plugin, which deprecates \u003ccode\u003esetRTLTextPlugin\u003c/code\u003e and \u003ccode\u003egetRTLTextPluginStatus\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8343\"\u003e#8343\u003c/a\u003e) (by \u003ca href=\"https://github.com/HarelM\"\u003e\u003ccode\u003e@​HarelM\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRead sprite and image pixels back through an \u003ccode\u003eOffscreenCanvas\u003c/code\u003e where available, removing a main-thread stall of tens of milliseconds on GPU-accelerated browsers when a sprite loads (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8339\"\u003e#8339\u003c/a\u003e) (by \u003ca href=\"https://github.com/cherenkov\"\u003e\u003ccode\u003e@​cherenkov\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSkip clipping masks for layers hidden at the current zoom and stop re-binding dynamic buffers on cached vertex array binds, removing redundant WebGL calls every frame (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8369\"\u003e#8369\u003c/a\u003e) (by \u003ca href=\"https://github.com/johncarmack1984\"\u003e\u003ccode\u003e@​johncarmack1984\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRe-render at most one stale terrain drape per frame and keep drapes that differ only by zoom while the map moves, so a finger lift over terrain no longer re-renders every tile at once (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8368\"\u003e#8368\u003c/a\u003e) (by \u003ca href=\"https://github.com/johncarmack1984\"\u003e\u003ccode\u003e@​johncarmack1984\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🐞 Bug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003esetStyle()\u003c/code\u003e throwing while terrain is still loading because an intermediate render tried to compile a terrain shader before the replacement style initialized its projection (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/6824\"\u003e#6824\u003c/a\u003e) (by \u003ca href=\"https://github.com/miakh\"\u003e\u003ccode\u003e@​miakh\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix queued GeoJSON \u003ccode\u003eupdateData\u003c/code\u003e property removals throwing after geometry-only updates or retaining previously updated values (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8372\"\u003e#8372\u003c/a\u003e) (by \u003ca href=\"https://github.com/jokrasno\"\u003e\u003ccode\u003e@​jokrasno\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eTreat camera options passed as \u003ccode\u003eundefined\u003c/code\u003e as not given in \u003ccode\u003ejumpTo\u003c/code\u003e, \u003ccode\u003eeaseTo\u003c/code\u003e and \u003ccode\u003eflyTo\u003c/code\u003e; they were coerced to NaN (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8373\"\u003e#8373\u003c/a\u003e) (by \u003ca href=\"https://github.com/vlumi\"\u003e\u003ccode\u003e@​vlumi\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix a \u003ccode\u003eNot implemented.\u003c/code\u003e error that broke panning and zooming when the projection was changed while the camera was moving, on maps with terrain enabled or a \u003ccode\u003etransformCameraUpdate\u003c/code\u003e callback (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8351\"\u003e#8351\u003c/a\u003e) (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix a map created inside a hidden container staying at the \u003ccode\u003e400x300\u003c/code\u003e fallback size when the container is shown before the resize observer's first notification is delivered (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8277\"\u003e#8277\u003c/a\u003e) (by \u003ca href=\"https://github.com/spliffone\"\u003e\u003ccode\u003e@​spliffone\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eMercatorTransform\u003c/code\u003e throwing when it is resized to a zero width, and skip the matrix calculation of every projection while the transform has a zero width or height (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8374\"\u003e#8374\u003c/a\u003e) (by \u003ca href=\"https://github.com/avosa\"\u003e\u003ccode\u003e@​avosa\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix every style update opening a redundant sky and light transition, which kept \u003ccode\u003eidle\u003c/code\u003e from firing for the transition duration after the map was otherwise done, and could ease the sky and the light on a different curve from the layers (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8348\"\u003e#8348\u003c/a\u003e) (by \u003ca href=\"https://github.com/cherenkov\"\u003e\u003ccode\u003e@​cherenkov\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix DOM sanitization for iframe and srcdoc (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8396\"\u003e#8396\u003c/a\u003e) (by \u003ca href=\"https://github.com/HarelM\"\u003e\u003ccode\u003e@​HarelM\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e6.8.0\u003c/h2\u003e\n\u003ch3\u003e✨ Features and improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003emap.getStyleUrl()\u003c/code\u003e, which returns the URL the style was loaded from, or \u003ccode\u003enull\u003c/code\u003e when the style was given as an object (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/7109\"\u003e#7109\u003c/a\u003e) (by \u003ca href=\"https://github.com/bradymadden97\"\u003e\u003ccode\u003e@​bradymadden97\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/giswqs\"\u003e\u003ccode\u003e@​giswqs\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSample terrain render-to-texture output through mipmaps with trilinear filtering, so draped layers stop shimmering and aliasing at high pitch (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8328\"\u003e#8328\u003c/a\u003e, continues \u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/7673\"\u003e#7673\u003c/a\u003e) (by \u003ca href=\"https://github.com/AveryanAlex\"\u003e\u003ccode\u003e@​AveryanAlex\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBuild the \u003ccode\u003eIntl.Segmenter\u003c/code\u003e instances used for text shaping on first use instead of at import, shaving several milliseconds off loading MapLibre on the main thread (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8337\"\u003e#8337\u003c/a\u003e) (by \u003ca href=\"https://github.com/cherenkov\"\u003e\u003ccode\u003e@​cherenkov\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eLink shader programs before reading their compile status, so the driver can overlap the compiles and the main thread waits less on shader compilation (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8338\"\u003e#8338\u003c/a\u003e) (by \u003ca href=\"https://github.com/cherenkov\"\u003e\u003ccode\u003e@​cherenkov\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBuild the default \u003ccode\u003eMarker\u003c/code\u003e pin once and clone it per marker, so creating many default markers takes roughly half the constructor time (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8340\"\u003e#8340\u003c/a\u003e) (by \u003ca href=\"https://github.com/cherenkov\"\u003e\u003ccode\u003e@​cherenkov\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd SDF rendering support for fill patterns, using \u003ccode\u003efill-color\u003c/code\u003e as the foreground color (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/7747\"\u003e#7747\u003c/a\u003e) (by \u003ca href=\"https://github.com/bradymadden97\"\u003e\u003ccode\u003e@​bradymadden97\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/deniial00\"\u003e\u003ccode\u003e@​deniial00\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eWarn once when the canvas is clamped to \u003ccode\u003emaxCanvasSize\u003c/code\u003e, which previously lowered the rendered resolution silently (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8200\"\u003e#8200\u003c/a\u003e) (by \u003ca href=\"https://github.com/str0kes\"\u003e\u003ccode\u003e@​str0kes\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🐞 Bug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix a marker's popup jumping to another world copy when the marker is moved across the antimeridian on a zoomed-out map (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/5655\"\u003e#5655\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8326\"\u003e#8326\u003c/a\u003e, continues \u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/5956\"\u003e#5956\u003c/a\u003e) (by \u003ca href=\"https://github.com/yuiseki\"\u003e\u003ccode\u003e@​yuiseki\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix terrain drape textures not being refreshed after zoom changes, causing stale rendering at the new zoom level (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8251\"\u003e#8251\u003c/a\u003e) (by \u003ca href=\"https://github.com/patte\"\u003e\u003ccode\u003e@​patte\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix a gap between the sky and the ground at high pitch while globe transitions to mercator (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/7382\"\u003e#7382\u003c/a\u003e) (by \u003ca href=\"https://github.com/birkskyum\"\u003e\u003ccode\u003e@​birkskyum\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eTreat an empty tile response (e.g. HTTP 204) as no data: raster-DEM tiles now load without elevation instead of failing with a \u003ccode\u003edem dimension mismatch\u003c/code\u003e error, and empty raster tiles render as transparent (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/1551\"\u003e#1551\u003c/a\u003e) (by \u003ca href=\"https://github.com/clement-igonet\"\u003e\u003ccode\u003e@​clement-igonet\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRead the map container's dimensions before mutating it in \u003ccode\u003eMap#_setupContainer\u003c/code\u003e, avoiding a forced synchronous layout reflow on every map initialization (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8307\"\u003e#8307\u003c/a\u003e) (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eValidate the \u003ccode\u003ebefore\u003c/code\u003e layer in \u003ccode\u003emap.moveLayer\u003c/code\u003e before reordering, so passing the id of a layer that does not exist leaves the layer order untouched instead of dropping the moved layer out of it (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8301\"\u003e#8301\u003c/a\u003e) (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix visible seams between hillshade tiles when using linear interpolation. (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8302\"\u003e#8302\u003c/a\u003e) (by \u003ca href=\"https://github.com/Turbo87\"\u003e\u003ccode\u003e@​Turbo87\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix the map freezing when a render task throws an error (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/6093\"\u003e#6093\u003c/a\u003e) (by \u003ca href=\"https://github.com/UberMouse\"\u003e\u003ccode\u003e@​UberMouse\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003egetCameraAltitude()\u003c/code\u003e returning \u003ccode\u003eNaN\u003c/code\u003e under \u003ccode\u003eglobe\u003c/code\u003e and \u003ccode\u003evertical-perspective\u003c/code\u003e, which disabled marker terrain occlusion and the camera terrain check; the altitude now follows the sphere (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/6584\"\u003e#6584\u003c/a\u003e) (by \u003ca href=\"https://github.com/bigmistqke\"\u003e\u003ccode\u003e@​bigmistqke\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/patte\"\u003e\u003ccode\u003e@​patte\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDraw an elevated symbol on globe when the symbol itself is in view but the ground under it is behind the horizon; occlusion now follows the line of sight to the elevated point (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8253\"\u003e#8253\u003c/a\u003e) (by \u003ca href=\"https://github.com/clement-igonet\"\u003e\u003ccode\u003e@​clement-igonet\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003esetTiles\u003c/code\u003e producing stale tile URLs when \u003ccode\u003eloadTile\u003c/code\u003e runs in the same frame (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/pull/8323\"\u003e#8323\u003c/a\u003e) (by \u003ca href=\"https://github.com/johncarmack1984\"\u003e\u003ccode\u003e@​johncarmack1984\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/nostrorom\"\u003e\u003ccode\u003e@​nostrorom\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eKeep the tile under an elevated symbol from being culled near the horizon, so a symbol with a large \u003ccode\u003esymbol-height-offset\u003c/code\u003e stays visible until it is behind the planet (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8316\"\u003e#8316\u003c/a\u003e) (by \u003ca href=\"https://github.com/clement-igonet\"\u003e\u003ccode\u003e@​clement-igonet\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e6.7.0\u003c/h2\u003e\n\u003ch3\u003e✨ Features and improvements\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maplibre/maplibre-gl-js/commit/f985318d1fa7e01d8b7e32a719aaf91efcb348d4\"\u003e\u003ccode\u003ef985318\u003c/code\u003e\u003c/a\u003e Bump js version to 6.9.0 (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8398\"\u003e#8398\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maplibre/maplibre-gl-js/commit/b51d10a7b0bff4ffe4480b9e26b4ebe57461b928\"\u003e\u003ccode\u003eb51d10a\u003c/code\u003e\u003c/a\u003e improve sanitization (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8396\"\u003e#8396\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maplibre/maplibre-gl-js/commit/36034010e11c5cf9a9d1f10bcb4b5306dab14ba1\"\u003e\u003ccode\u003e3603401\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump cssnano from 9.0.2 to 9.0.3 (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8390\"\u003e#8390\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maplibre/maplibre-gl-js/commit/3e3c447168f00dd82485fa5b27b6e7d90d6f705e\"\u003e\u003ccode\u003e3e3c447\u003c/code\u003e\u003c/a\u003e chore(deps): bump \u003ccode\u003e@​maplibre/maplibre-gl-style-spec\u003c/code\u003e from 26.4.1 to 26.4.2 (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8391\"\u003e#8391\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maplibre/maplibre-gl-js/commit/ea9f7df5e374a65401ddf388a54158d0b59b2e97\"\u003e\u003ccode\u003eea9f7df\u003c/code\u003e\u003c/a\u003e chore(deps): bump zensical/zensical from 0.0.59 to 0.0.60 (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8392\"\u003e#8392\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maplibre/maplibre-gl-js/commit/ce10d220875eac604ee5c646e9b17680d7e182ed\"\u003e\u003ccode\u003ece10d22\u003c/code\u003e\u003c/a\u003e feat: add bidi support and deprecate RTL plugin (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8343\"\u003e#8343\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maplibre/maplibre-gl-js/commit/86901c5b7f638c201928e3e7ccea08200718ff3e\"\u003e\u003ccode\u003e86901c5\u003c/code\u003e\u003c/a\u003e fix: stop re-opening sky and light transitions on every style update (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8350\"\u003e#8350\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maplibre/maplibre-gl-js/commit/54dfab1e186e72fc43bc319cab97c5427f80a0f3\"\u003e\u003ccode\u003e54dfab1\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump \u003ccode\u003e@​types/node\u003c/code\u003e from 26.4.0 to 26.4.1 (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8352\"\u003e#8352\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maplibre/maplibre-gl-js/commit/209e34203b2ac001d022334471182a1d06c5b2b0\"\u003e\u003ccode\u003e209e342\u003c/code\u003e\u003c/a\u003e perf: skip hidden layers before their clipping masks and drop the dynamic buf...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maplibre/maplibre-gl-js/commit/71a12d8c37a052eec276f3ad93ae8cc5b8a92f15\"\u003e\u003ccode\u003e71a12d8\u003c/code\u003e\u003c/a\u003e fix: skip terrain drawing until replacement projection is ready (\u003ca href=\"https://redirect.github.com/maplibre/maplibre-gl-js/issues/8258\"\u003e#8258\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/maplibre/maplibre-gl-js/compare/v4.7.1...v6.9.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for maplibre-gl since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `mysql2` from 3.16.2 to 3.23.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/sidorares/node-mysql2/releases\"\u003emysql2's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.23.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/sidorares/node-mysql2/compare/v3.23.0...v3.23.1\"\u003e3.23.1\u003c/a\u003e (2026-07-19)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003esecurity:\u003c/strong\u003e fix unb...\n\n_Description has been truncated_\n\n\u003c!-- This is an auto-generated description by cubic. --\u003e\n---\n## Summary by cubic\nUpdates 25 npm dependencies across three projects: `project-nomad-evez/admin`, `quantumseal-api`, and `spectrumscan-api`. Includes security fixes and major version bumps that may require code changes.\n\n**Breaking changes**\n- `maplibre-gl` jumps from 4.7.1 to 6.9.0; review API changes and the deprecation of `setRTLTextPlugin`.\n- `@adonisjs/auth`, `@adonisjs/lucid`, and `@adonisjs/session` move to new major versions; check for breaking changes.\n- `axios` deprecates `PayloadTooLarge` and `UnprocessableEntity` aliases in favor of new status-code names.\n\n**Security fixes**\n- `body-parser` updated to 1.20.8 to address CVE-2026-12590.\n\n\u003csup\u003eWritten for commit d674c7e55e26876327e54b4df0520c06125529db. Summary will update on new commits.\u003c/sup\u003e\n\n\u003ca href=\"https://cubic.dev/pr/EvezArt/evez-ai/pull/4?utm_source=github\" target=\"_blank\" rel=\"noopener noreferrer\" data-no-image-dialog=\"true\"\u003e\u003cpicture\u003e\u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-light.svg\"\u003e\u003cimg alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003c/picture\u003e\u003c/a\u003e\n\n\u003c!-- End of auto-generated description by cubic. --\u003e\n\n","html_url":"https://github.com/EvezArt/evez-ai/pull/4","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/EvezArt%2Fevez-ai/issues/4","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/4/packages"}},{"old_version":"8.10.0","new_version":"8.10.2","update_type":"patch","path":"the evals group across 1 directory","pr_created_at":"2026-09-12T04:58:10.000Z","version_change":"8.10.0 → 8.10.2","issue":{"uuid":"5431254857","node_id":"PR_kwDOOgwg5c8AAAABDOnHxQ","number":1170,"state":"open","title":"build(deps-dev): Bump undici from 8.10.0 to 8.10.2 in the evals group across 1 directory","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-12T04:58:10.000Z","updated_at":"2026-09-12T05:06:06.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps-dev): Bump","packages":[{"name":"undici","old_version":"8.10.0","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"}],"path":"the evals group across 1 directory","ecosystem":"npm"},"body":"Bumps the evals group with 1 update in the / directory: [undici](https://github.com/nodejs/undici).\n\nUpdates `undici` from 8.10.0 to 8.10.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm\"\u003eGHSA-vp8m-p9jh-q5pm\u003c/a\u003e: cache and deduplication interceptors could use caller-controlled request metadata instead of the authoritative dispatcher origin, enabling cross-origin cache poisoning and data disclosure. Undici now derives interceptor identities from the dispatcher origin and bypasses origin-dependent interceptors when no authoritative origin exists. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/caf6194d3dae989b731ed87ab85f182befe5eb80\"\u003ecaf6194d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e8f5868fb\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e66e12816\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6\"\u003e4411a238\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/662d0ea671fe64139e79533c913fce412765e1d7\"\u003e662d0ea6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003ecb75bbb3\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e7aac7f12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003ee905b5b8\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e2be07bf9\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e6d583124\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e0160a719\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps-dev): bump undici from 6.27.0 to 6.28.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5653\"\u003enodejs/undici#5653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump jest from 30.4.2 to 30.5.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5750\"\u003enodejs/undici#5750\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/analyze from 4.37.3 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5752\"\u003enodejs/undici#5752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5754\"\u003enodejs/undici#5754\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(h2): cover stream reset with NGHTTP2_INTERNAL_ERROR by \u003ca href=\"https://github.com/zeexzeex\"\u003e\u003ccode\u003e@​zeexzeex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5725\"\u003enodejs/undici#5725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): reject invalid resumed responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5724\"\u003enodejs/undici#5724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: make stale-while-revalidate cache update test deterministic by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5722\"\u003enodejs/undici#5722\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid unbounded recursion in Set-Cookie attribute parser by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5757\"\u003enodejs/undici#5757\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: honor SOCKS5 connection timeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5733\"\u003enodejs/undici#5733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(eventsource): validate Last-Event-ID on reconnect by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5746\"\u003enodejs/undici#5746\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid duplicate release attempts by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5745\"\u003enodejs/undici#5745\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(cache): refetch when 304 adds vary fields by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5732\"\u003enodejs/undici#5732\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etypes: expose PendingInterceptor and PendingInterceptorsFormatter on the MockAgent namespace by \u003ca href=\"https://github.com/RaphaelFakhri\"\u003e\u003ccode\u003e@​RaphaelFakhri\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5721\"\u003enodejs/undici#5721\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(codeql): align CodeQL action versions to v4.37.9 by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5759\"\u003enodejs/undici#5759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5760\"\u003enodejs/undici#5760\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(proxy-agent): guard Proxy-Authorization in iterable header containers by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5758\"\u003enodejs/undici#5758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: name the parameters these two blocks describe by \u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): fail the connection on a non-200 h2 extended CONNECT response by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(node-fetch): re-enable the set-cookie header combining test by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5730\"\u003enodejs/undici#5730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward rawHeaders writes through RetryController by \u003ca href=\"https://github.com/official-burak\"\u003e\u003ccode\u003e@​official-burak\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5727\"\u003enodejs/undici#5727\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5738\"\u003enodejs/undici#5738\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/5e541e0b9df7563e5766bbd469fbfe383d9ae6ca\"\u003e\u003ccode\u003e5e541e0\u003c/code\u003e\u003c/a\u003e Bumped v8.10.2 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5771\"\u003e#5771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/eb04cc39954e63e9b46bdf824e6efad9fff2e7b5\"\u003e\u003ccode\u003eeb04cc3\u003c/code\u003e\u003c/a\u003e fix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5738\"\u003e#5738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003e\u003ccode\u003ee905b5b\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e\u003ccode\u003e0160a71\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e\u003ccode\u003e66e1281\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e\u003ccode\u003e7aac7f1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003e\u003ccode\u003ecb75bbb\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e\u003ccode\u003e6d58312\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e\u003ccode\u003e8f5868f\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e\u003ccode\u003e2be07bf\u003c/code\u003e\u003c/a\u003e fix(cache): reject unsafe method response caching\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v8.10.0...v8.10.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n","html_url":"https://github.com/adamjmurray/producer-pal/pull/1170","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/adamjmurray%2Fproducer-pal/issues/1170","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1170/packages"}},{"old_version":"8.10.0","new_version":"8.10.2","update_type":"patch","path":null,"pr_created_at":"2026-09-12T02:35:48.000Z","version_change":"8.10.0 → 8.10.2","issue":{"uuid":"5430679006","node_id":"PR_kwDORo9bUM8AAAABDOKuSw","number":136,"state":"open","title":"chore(deps): bump the web group across 1 directory with 14 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-12T02:35:48.000Z","updated_at":"2026-09-12T02:35:57.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"web","update_count":14,"packages":[{"name":"@aws-sdk/client-s3","old_version":"3.1108.0","new_version":"3.1128.0","repository_url":"https://github.com/aws/aws-sdk-js-v3"},{"name":"@google/genai","old_version":"2.16.0","new_version":"2.21.0","repository_url":"https://github.com/googleapis/js-genai"},{"name":"@next/third-parties","old_version":"16.3.0","new_version":"16.3.4","repository_url":"https://github.com/vercel/next.js"},{"name":"@supabase/ssr","old_version":"0.12.4","new_version":"0.12.7","repository_url":"https://github.com/supabase/ssr"},{"name":"lucide-react","old_version":"1.31.0","new_version":"1.43.0","repository_url":"https://github.com/lucide-icons/lucide"},{"name":"next","old_version":"16.3.0","new_version":"16.3.4","repository_url":"https://github.com/vercel/next.js"},{"name":"resend","old_version":"6.19.0","new_version":"6.26.0","repository_url":"https://github.com/resend/resend-node"},{"name":"undici","old_version":"8.10.0","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"},{"name":"@types/node","old_version":"26.2.0","new_version":"26.5.0","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"@types/react-dom","old_version":"19.2.4","new_version":"19.2.7","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"postcss","old_version":"8.5.26","new_version":"8.5.28","repository_url":"https://github.com/postcss/postcss"},{"name":"supercluster","old_version":"9.0.0","new_version":"9.1.0","repository_url":"https://github.com/mapbox/supercluster"}],"path":null,"ecosystem":"npm"},"body":"Bumps the web group with 12 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) | `3.1108.0` | `3.1128.0` |\n| [@google/genai](https://github.com/googleapis/js-genai) | `2.16.0` | `2.21.0` |\n| [@next/third-parties](https://github.com/vercel/next.js/tree/HEAD/packages/third-parties) | `16.3.0` | `16.3.4` |\n| [@supabase/ssr](https://github.com/supabase/ssr) | `0.12.4` | `0.12.7` |\n| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.31.0` | `1.43.0` |\n| [next](https://github.com/vercel/next.js) | `16.3.0` | `16.3.4` |\n| [resend](https://github.com/resend/resend-node) | `6.19.0` | `6.26.0` |\n| [undici](https://github.com/nodejs/undici) | `8.10.0` | `8.10.2` |\n| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.2.0` | `26.5.0` |\n| [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom) | `19.2.4` | `19.2.7` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.26` | `8.5.28` |\n| [supercluster](https://github.com/mapbox/supercluster) | `9.0.0` | `9.1.0` |\n\n\nUpdates `@aws-sdk/client-s3` from 3.1108.0 to 3.1128.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/aws/aws-sdk-js-v3/releases\"\u003e@​aws-sdk/client-s3's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.1128.0\u003c/h2\u003e\n\u003ch4\u003e3.1128.0(2026-09-08)\u003c/h4\u003e\n\u003ch5\u003eNew Features\u003c/h5\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eclients:\u003c/strong\u003e  update client endpoints as of 2026-09-08 (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/bdcc40a79ef0a6acbca6db93dd9561731b12a55a\"\u003ebdcc40a7\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-ec2:\u003c/strong\u003e  Adds the InterfaceTypes field to NetworkCardInfo in the DescribeInstanceTypes response. This field identifies the network interface types supported by each network card. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/9336e689cde8ef1f4501c7739a445328ce2ef52d\"\u003e9336e689\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-appflow:\u003c/strong\u003e  Amazon AppFlow now supports key pair (RSA private key) authentication for the Snowflake connector. You can provide a privateKey in SnowflakeConnectorProfileCredentials, and password is no longer required. This is a non-breaking, additive change available via the AWS SDK and CLI. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/ec8753ad6f2305daca3d8679a8438dceaee9b4b9\"\u003eec8753ad\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-sagemaker:\u003c/strong\u003e  Add support for InstancePreferences list for multiple instance type input support on SageMaker Training and Processing (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/45153f6cf19c4a8bc1c567ff1e7323b0c27caba4\"\u003e45153f6c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-cloudtrail:\u003c/strong\u003e  Adds support for the RecursiveLogging trail setting, which suppresses recursive events generated when CloudTrail delivers logs to a trail's destinations. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/62a43c78602be4b20d64a11380ee03163c32ae60\"\u003e62a43c78\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-s3:\u003c/strong\u003e  Adds support for Amazon S3 Object Lock variable retention.  Existing S3 APIs that support S3 Object Lock parameters now support two new parameters EventHold and EventHoldDuration at the object level, and DefaultEventHoldDuration at the bucket level. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/8b5898753d091cf7647df0a65418430e5c0ce55f\"\u003e8b589875\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-s3-control:\u003c/strong\u003e  Adds support for Amazon S3 Object Lock variable retention.  Existing S3 APIs that support S3 Object Lock parameters now support two new parameters EventHold and EventHoldDuration at the object level, and DefaultEventHoldDuration at the bucket level. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/5765b68b0ef990f91ae49d0eae48e1958991498a\"\u003e5765b68b\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-omics:\u003c/strong\u003e  Added support for session policies in AWS HealthOmics Workflows, allowing customers to scope down IAM permissions for individual workflow runs without modifying the service role. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/ad55dcd6e323df20f9add4d38e0f3b70eca8348e\"\u003ead55dcd6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-connect:\u003c/strong\u003e  Releasing workload types feature. A proper launch announcement or details will follow up. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/63ded7ae8188e0b48d0d76258964a9027b57c453\"\u003e63ded7ae\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-pinpoint-sms-voice-v2:\u003c/strong\u003e  This feature will allow customers to specify an area-code when requesting a 10DLC number. Why it matters- Customers can now select a number that matches where their business is located. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/7aac3447f181a72b79ab473d97e0797962fed13d\"\u003e7aac3447\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-mgn:\u003c/strong\u003e  This release adds support for configuring the EBS volume initialization rate and delete on termination behavior in launch configuration template (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/bb780670c3305dc44168aa18cfea57262c24287c\"\u003ebb780670\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch5\u003eBug Fixes\u003c/h5\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003elib-storage:\u003c/strong\u003e  fix symlink stream sizing and abort on part-count mismatch (\u003ca href=\"https://redirect.github.com/aws/aws-sdk-js-v3/pull/8300\"\u003e#8300\u003c/a\u003e) (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/aa58831cf57d789884e4163dcba19fb22a71851f\"\u003eaa58831c\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003eFor list of updated packages, view \u003cstrong\u003eupdated-packages.md\u003c/strong\u003e in \u003cstrong\u003eassets-3.1128.0.zip\u003c/strong\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1127.0\u003c/h2\u003e\n\u003ch4\u003e3.1127.0(2026-09-04)\u003c/h4\u003e\n\u003ch5\u003eNew Features\u003c/h5\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eclient-mediatailor:\u003c/strong\u003e  Elemental MediaTailor now supports two new Monetization Functions lifecycle hooks, Post Ads Response and Pre Manifest Insertion, and a VAST Request function type that calls a VAST or VMAP ad server. This release also adds Yield Optimization with demand from Amazon Publisher Services. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/c238a693cf4e9e9fa4bd5ad76f83caa35279ad46\"\u003ec238a693\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-service-quotas:\u003c/strong\u003e  Service Quotas adds the AdjustableAtLevel property to QuotaContext, indicating whether a quota is adjustable at the account or resource level. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/f56bdf2c0e9581a97b246204dd95b7be1028a6f9\"\u003ef56bdf2c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-bedrock:\u003c/strong\u003e  New AWS REVIEW mode as supported data retention mode for Bedrock models (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/cbd9ea9a4262cb007ed74da234d52e8feef0402f\"\u003ecbd9ea9a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-ec2:\u003c/strong\u003e  Adds support for ValidateSecurityGroupQuotasForInterface, an API that specifically authorized AWS services use to validate security group rule quotas before creating an elastic network interface. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/f51c3b3e30327dd6fa45a9b8398422c7078d905d\"\u003ef51c3b3e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003eFor list of updated packages, view \u003cstrong\u003eupdated-packages.md\u003c/strong\u003e in \u003cstrong\u003eassets-3.1127.0.zip\u003c/strong\u003e\u003c/p\u003e\n\u003ch2\u003ev3.1126.0\u003c/h2\u003e\n\u003ch4\u003e3.1126.0(2026-09-03)\u003c/h4\u003e\n\u003ch5\u003eDocumentation Changes\u003c/h5\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eclient-sfn:\u003c/strong\u003e  Updates Step Functions API documentation around CloudTrail, Execution name reuse and sort order of ListExecutions API (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/8dda8b4b9e90ec0cca551759885ca524b8d65a91\"\u003e8dda8b4b\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eclient-elastic-load-balancing-v2:\u003c/strong\u003e  This release adds support for sending TCP resets for Gateway Load Balancer when a flow's idle timeout expires, or when a target becomes unhealthy or is deregistered. This adds updates the CLI documentation. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/a16f16596740e5b7ee6032c4fc95fdd3a08a46e2\"\u003ea16f1659\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch5\u003eNew Features\u003c/h5\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md\"\u003e@​aws-sdk/client-s3's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/compare/v3.1127.0...v3.1128.0\"\u003e3.1128.0\u003c/a\u003e (2026-09-08)\u003c/h1\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eclient-s3:\u003c/strong\u003e Adds support for Amazon S3 Object Lock variable retention.  Existing S3 APIs that support S3 Object Lock parameters now support two new parameters EventHold and EventHoldDuration at the object level, and DefaultEventHoldDuration at the bucket level. (\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/8b5898753d091cf7647df0a65418430e5c0ce55f\"\u003e8b58987\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/compare/v3.1126.0...v3.1127.0\"\u003e3.1127.0\u003c/a\u003e (2026-09-04)\u003c/h1\u003e\n\u003cp\u003e\u003cstrong\u003eNote:\u003c/strong\u003e Version bump only for package \u003ccode\u003e@​aws-sdk/client-s3\u003c/code\u003e\u003c/p\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/compare/v3.1125.0...v3.1126.0\"\u003e3.1126.0\u003c/a\u003e (2026-09-03)\u003c/h1\u003e\n\u003cp\u003e\u003cstrong\u003eNote:\u003c/strong\u003e Version bump only for package \u003ccode\u003e@​aws-sdk/client-s3\u003c/code\u003e\u003c/p\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/compare/v3.1124.0...v3.1125.0\"\u003e3.1125.0\u003c/a\u003e (2026-09-02)\u003c/h1\u003e\n\u003cp\u003e\u003cstrong\u003eNote:\u003c/strong\u003e Version bump only for package \u003ccode\u003e@​aws-sdk/client-s3\u003c/code\u003e\u003c/p\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/compare/v3.1123.0...v3.1124.0\"\u003e3.1124.0\u003c/a\u003e (2026-09-01)\u003c/h1\u003e\n\u003cp\u003e\u003cstrong\u003eNote:\u003c/strong\u003e Version bump only for package \u003ccode\u003e@​aws-sdk/client-s3\u003c/code\u003e\u003c/p\u003e\n\u003ch1\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/compare/v3.1122.0...v3.1123.0\"\u003e3.1123.0\u003c/a\u003e (2026-08-31)\u003c/h1\u003e\n\u003cp\u003e\u003cstrong\u003eNote:\u003c/strong\u003e Version bump only for package \u003ccode\u003e@​aws-sdk/client-s3\u003c/code\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/523fff6052428fafb61b8842773c1c142d4c5f74\"\u003e\u003ccode\u003e523fff6\u003c/code\u003e\u003c/a\u003e Publish v3.1128.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/8b5898753d091cf7647df0a65418430e5c0ce55f\"\u003e\u003ccode\u003e8b58987\u003c/code\u003e\u003c/a\u003e feat(client-s3): Adds support for Amazon S3 Object Lock variable retention.  ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/8893344796b14a92844d9a08973bcdc2da89a3eb\"\u003e\u003ccode\u003e8893344\u003c/code\u003e\u003c/a\u003e Publish v3.1127.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/7131e7467d87d0a255fa1c42f6bb0dd12a84835e\"\u003e\u003ccode\u003e7131e74\u003c/code\u003e\u003c/a\u003e Publish v3.1126.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/678282b614156c0085a279c49226c2725a88bf3e\"\u003e\u003ccode\u003e678282b\u003c/code\u003e\u003c/a\u003e Publish v3.1125.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/e80cab3d6831ad16c976bd65ba28a3467e1163e6\"\u003e\u003ccode\u003ee80cab3\u003c/code\u003e\u003c/a\u003e Publish v3.1124.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/49a1557a8f25447d8dbe714d2ac2cfbb482d2c1d\"\u003e\u003ccode\u003e49a1557\u003c/code\u003e\u003c/a\u003e Publish v3.1123.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/e1cf460a1e4707e137931804e3e7b71a8392f227\"\u003e\u003ccode\u003ee1cf460\u003c/code\u003e\u003c/a\u003e Publish v3.1122.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/e53a25aafbdd772c90d26471dc271e383f1daf71\"\u003e\u003ccode\u003ee53a25a\u003c/code\u003e\u003c/a\u003e Publish v3.1121.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commit/d6be6f8dd3ee8d43fd70dfb5b52a977ce251c720\"\u003e\u003ccode\u003ed6be6f8\u003c/code\u003e\u003c/a\u003e Publish v3.1120.0\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/aws/aws-sdk-js-v3/commits/v3.1128.0/clients/client-s3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@google/genai` from 2.16.0 to 2.21.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/googleapis/js-genai/releases\"\u003e@​google/genai's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.21.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/googleapis/js-genai/compare/v2.20.0...v2.21.0\"\u003e2.21.0\u003c/a\u003e (2026-09-02)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Gemini 3.8 Flash model to SDKs and update Flash model descriptions (\u003ca href=\"https://github.com/googleapis/js-genai/commit/4a969feeb938d05faa8389a476a268c1649a7695\"\u003e4a969fe\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.20.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/googleapis/js-genai/compare/v2.19.0...v2.20.0\"\u003e2.20.0\u003c/a\u003e (2026-08-31)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for the audio/webm MIME type. (\u003ca href=\"https://github.com/googleapis/js-genai/commit/b0e3c5f54bbddd875eaa88c699f1b85d5a55918f\"\u003eb0e3c5f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd translation_config SDK support for GEAP. (\u003ca href=\"https://github.com/googleapis/js-genai/commit/3e1d923ef914812c1d209aa2e5461a717d03a081\"\u003e3e1d923\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd Video Understanding support to the Interactions API (\u003ca href=\"https://github.com/googleapis/js-genai/commit/6ddbeba6c3836378f58351e6885f5141aab0c1e7\"\u003e6ddbeba\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDon't set redundant Content-Length on file upload requests (\u003ca href=\"https://github.com/googleapis/js-genai/commit/2f5cc7a00852608a46ffa3bd8cab5d02783810d6\"\u003e2f5cc7a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDon't set redundant Content-Length on file upload requests (\u003ca href=\"https://github.com/googleapis/js-genai/commit/2f5cc7a00852608a46ffa3bd8cab5d02783810d6\"\u003e2f5cc7a\u003c/a\u003e), refs \u003ca href=\"https://redirect.github.com/googleapis/js-genai/issues/1718\"\u003e#1718\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eexpose ProcessingCallStep and ProcessingResultStep in Interactions SDK (\u003ca href=\"https://github.com/googleapis/js-genai/commit/b6f8db553449199ebba1678dbb0936300e982990\"\u003eb6f8db5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eQuote setupComplete key in LiveClientMessage (\u003ca href=\"https://github.com/googleapis/js-genai/commit/4467fafb08948863889f7e87917d311ed39c0884\"\u003e4467faf\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.19.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/googleapis/js-genai/compare/v2.18.0...v2.19.0\"\u003e2.19.0\u003c/a\u003e (2026-08-25)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd AudioTranscriptionConfigMode (\u003ca href=\"https://github.com/googleapis/js-genai/commit/c0a37de9102c1054c2bf9fa2cd3d8b6a4c41fd42\"\u003ec0a37de\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd environment files support and scotty file download helper (\u003ca href=\"https://github.com/googleapis/js-genai/commit/0d6ee9d8e2690e541d12b72205272bba0c33b209\"\u003e0d6ee9d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd TYPE_JPEG2000 to VideoContent.MimeType enum (\u003ca href=\"https://github.com/googleapis/js-genai/commit/41da2043cce07211f793647d57d119e04ff2ef48\"\u003e41da204\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance Improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eKeep the Buffer in the Node tokenizer platform, ~2x faster model parse (\u003ca href=\"https://github.com/googleapis/js-genai/commit/11d804a88fc0ce260d6e4ab80ced4e54d34201ed\"\u003e11d804a\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.18.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/googleapis/js-genai/compare/v2.17.1...v2.18.0\"\u003e2.18.0\u003c/a\u003e (2026-08-19)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003emode\u003c/code\u003e enum (\u003ccode\u003eVERBATIM\u003c/code\u003e, \u003ccode\u003eSMART\u003c/code\u003e) to \u003ccode\u003eAudioTranscriptionConfig\u003c/code\u003e and \u003ccode\u003eTranscriptionConfig\u003c/code\u003e. (\u003ca href=\"https://github.com/googleapis/js-genai/commit/4c5208baa923cecea897b7b4fdc9de5e49555709\"\u003e4c5208b\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd enable_data_retention to ToolParallelAiSearch, Add step_count to ReinforcementTuningHyperParameters, Add BidiGenerateContentSetup (\u003ca href=\"https://github.com/googleapis/js-genai/commit/f52c20858c1bf6c7892192bc41cfc027d30b57ab\"\u003ef52c208\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd IDLE state to live connection status enum and mark REQUIRES_ACTION as deprecated. (\u003ca href=\"https://github.com/googleapis/js-genai/commit/2f110f23372cf2ea52452fe57ddf3a4e30833857\"\u003e2f110f2\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/googleapis/js-genai/blob/main/CHANGELOG.md\"\u003e@​google/genai's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/googleapis/js-genai/compare/v2.20.0...v2.21.0\"\u003e2.21.0\u003c/a\u003e (2026-09-02)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Gemini 3.8 Flash model to SDKs and update Flash model descriptions (\u003ca href=\"https://github.com/googleapis/js-genai/commit/4a969feeb938d05faa8389a476a268c1649a7695\"\u003e4a969fe\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/googleapis/js-genai/compare/v2.19.0...v2.20.0\"\u003e2.20.0\u003c/a\u003e (2026-08-31)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for the audio/webm MIME type. (\u003ca href=\"https://github.com/googleapis/js-genai/commit/b0e3c5f54bbddd875eaa88c699f1b85d5a55918f\"\u003eb0e3c5f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd translation_config SDK support for GEAP. (\u003ca href=\"https://github.com/googleapis/js-genai/commit/3e1d923ef914812c1d209aa2e5461a717d03a081\"\u003e3e1d923\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd Video Understanding support to the Interactions API (\u003ca href=\"https://github.com/googleapis/js-genai/commit/6ddbeba6c3836378f58351e6885f5141aab0c1e7\"\u003e6ddbeba\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDon't set redundant Content-Length on file upload requests (\u003ca href=\"https://github.com/googleapis/js-genai/commit/2f5cc7a00852608a46ffa3bd8cab5d02783810d6\"\u003e2f5cc7a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDon't set redundant Content-Length on file upload requests (\u003ca href=\"https://github.com/googleapis/js-genai/commit/2f5cc7a00852608a46ffa3bd8cab5d02783810d6\"\u003e2f5cc7a\u003c/a\u003e), refs \u003ca href=\"https://redirect.github.com/googleapis/js-genai/issues/1718\"\u003e#1718\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eexpose ProcessingCallStep and ProcessingResultStep in Interactions SDK (\u003ca href=\"https://github.com/googleapis/js-genai/commit/b6f8db553449199ebba1678dbb0936300e982990\"\u003eb6f8db5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eQuote setupComplete key in LiveClientMessage (\u003ca href=\"https://github.com/googleapis/js-genai/commit/4467fafb08948863889f7e87917d311ed39c0884\"\u003e4467faf\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/googleapis/js-genai/compare/v2.18.0...v2.19.0\"\u003e2.19.0\u003c/a\u003e (2026-08-25)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd AudioTranscriptionConfigMode (\u003ca href=\"https://github.com/googleapis/js-genai/commit/c0a37de9102c1054c2bf9fa2cd3d8b6a4c41fd42\"\u003ec0a37de\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd environment files support and scotty file download helper (\u003ca href=\"https://github.com/googleapis/js-genai/commit/0d6ee9d8e2690e541d12b72205272bba0c33b209\"\u003e0d6ee9d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd TYPE_JPEG2000 to VideoContent.MimeType enum (\u003ca href=\"https://github.com/googleapis/js-genai/commit/41da2043cce07211f793647d57d119e04ff2ef48\"\u003e41da204\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance Improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eKeep the Buffer in the Node tokenizer platform, ~2x faster model parse (\u003ca href=\"https://github.com/googleapis/js-genai/commit/11d804a88fc0ce260d6e4ab80ced4e54d34201ed\"\u003e11d804a\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/googleapis/js-genai/compare/v2.17.1...v2.18.0\"\u003e2.18.0\u003c/a\u003e (2026-08-19)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003emode\u003c/code\u003e enum (\u003ccode\u003eVERBATIM\u003c/code\u003e, \u003ccode\u003eSMART\u003c/code\u003e) to \u003ccode\u003eAudioTranscriptionConfig\u003c/code\u003e and \u003ccode\u003eTranscriptionConfig\u003c/code\u003e. (\u003ca href=\"https://github.com/googleapis/js-genai/commit/4c5208baa923cecea897b7b4fdc9de5e49555709\"\u003e4c5208b\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd enable_data_retention to ToolParallelAiSearch, Add step_count to ReinforcementTuningHyperParameters, Add BidiGenerateContentSetup (\u003ca href=\"https://github.com/googleapis/js-genai/commit/f52c20858c1bf6c7892192bc41cfc027d30b57ab\"\u003ef52c208\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd IDLE state to live connection status enum and mark REQUIRES_ACTION as deprecated. (\u003ca href=\"https://github.com/googleapis/js-genai/commit/2f110f23372cf2ea52452fe57ddf3a4e30833857\"\u003e2f110f2\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd video resolution and extension task parameters (\u003ca href=\"https://github.com/googleapis/js-genai/commit/39b2a2dea4c5ff75c1754581b213b9d480504e7d\"\u003e39b2a2d\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/googleapis/js-genai/commit/27af8977598edb68ffccadcd34fae967205a8740\"\u003e\u003ccode\u003e27af897\u003c/code\u003e\u003c/a\u003e chore(main): release 2.21.0 (\u003ca href=\"https://redirect.github.com/googleapis/js-genai/issues/1915\"\u003e#1915\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/googleapis/js-genai/commit/4a969feeb938d05faa8389a476a268c1649a7695\"\u003e\u003ccode\u003e4a969fe\u003c/code\u003e\u003c/a\u003e feat: Add Gemini 3.8 Flash model to SDKs and update Flash model descriptions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/googleapis/js-genai/commit/8233d412bd6900f38a83fac42909bfe135db0c2e\"\u003e\u003ccode\u003e8233d41\u003c/code\u003e\u003c/a\u003e chore: docs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/googleapis/js-genai/commit/7fe15a613e675f1f016fc34d5b5d685ef6105c69\"\u003e\u003ccode\u003e7fe15a6\u003c/code\u003e\u003c/a\u003e chore(main): release 2.20.0 (\u003ca href=\"https://redirect.github.com/googleapis/js-genai/issues/1899\"\u003e#1899\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/googleapis/js-genai/commit/b0e3c5f54bbddd875eaa88c699f1b85d5a55918f\"\u003e\u003ccode\u003eb0e3c5f\u003c/code\u003e\u003c/a\u003e feat: Add support for the audio/webm MIME type.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/googleapis/js-genai/commit/3e1d923ef914812c1d209aa2e5461a717d03a081\"\u003e\u003ccode\u003e3e1d923\u003c/code\u003e\u003c/a\u003e feat: Add translation_config SDK support for GEAP.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/googleapis/js-genai/commit/b6f8db553449199ebba1678dbb0936300e982990\"\u003e\u003ccode\u003eb6f8db5\u003c/code\u003e\u003c/a\u003e fix: expose ProcessingCallStep and ProcessingResultStep in Interactions SDK\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/googleapis/js-genai/commit/4467fafb08948863889f7e87917d311ed39c0884\"\u003e\u003ccode\u003e4467faf\u003c/code\u003e\u003c/a\u003e fix: Quote setupComplete key in LiveClientMessage\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/googleapis/js-genai/commit/6ddbeba6c3836378f58351e6885f5141aab0c1e7\"\u003e\u003ccode\u003e6ddbeba\u003c/code\u003e\u003c/a\u003e feat: add Video Understanding support to the Interactions API\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/googleapis/js-genai/commit/6a44ab0b5b98d816d594df6219eaf23fef584d5a\"\u003e\u003ccode\u003e6a44ab0\u003c/code\u003e\u003c/a\u003e chore: keep config as the last method parameter\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/googleapis/js-genai/compare/v2.16.0...v2.21.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@next/third-parties` from 16.3.0 to 16.3.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003e@​next/third-parties's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.4\u003c/h2\u003e\n\u003cp\u003eFollow-up release to \u003ca href=\"https://github.com/vercel/next.js/releases/tag/v16.3.3\"\u003ev16.3.3\u003c/a\u003e re-enabling AVIF Image Optimization (\u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97949\"\u003e#97949\u003c/a\u003e).\u003c/p\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003etestmode: Fix infinite recursion in testmode passthrough fetch (\u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/third-parties/issues/97691\"\u003e#97691\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix build error when aliasing typescript to \u003ccode\u003e@​typescript/typescript6\u003c/code\u003e (\u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/third-parties/issues/97997\"\u003e#97997\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix unset crossOrigin in Turbopack manifests (\u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/third-parties/issues/97930\"\u003e#97930\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.3\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eCritical:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36\"\u003eUnauthenticated Remote Code Execution on windows-hosted servers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4\"\u003eUnauthenticated Remote Code Execution in Image Optimization API when AVIF files are used\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.2\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Scope app-entry export validation to files inside the app directory (\u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/third-parties/issues/97357\"\u003e#97357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[backport] Fix catch-all index page being served for every other slug (\u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/third-parties/issues/97416\"\u003e#97416\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: don't trace embedded WASM loader helpers (\u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/third-parties/issues/97353\"\u003e#97353\u003c/a\u003e) (\u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/third-parties/issues/97463\"\u003e#97463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: retain conditions when replacing resolve request keys (\u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/third-parties/issues/97453\"\u003e#97453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Fix Turbopack worker chunk loading with asset prefix (\u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/third-parties/issues/97419\"\u003e#97419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (\u003ca href=\"https://github.com/vercel/next.js/tree/HEAD/packages/third-parties/issues/97603\"\u003e#97603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/lubieowoce\"\u003e\u003ccode\u003e@​lubieowoce\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[16.x] Turbopack: don't strip async-module runtime from shared runtime chunks by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96653\"\u003evercel/next.js#96653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] [turbopack] Add \u003ccode\u003eturbopack_ecmascript\u003c/code\u003e and \u003ccode\u003eturbopack_wasm\u003c/code\u003e's embeded FS to \u003ccode\u003einternal_assets_conditions\u003c/code\u003e by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96655\"\u003evercel/next.js#96655\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] [turbopack] Collapse nested promises in the analyzer by \u003ca href=\"https://github.com/sampoder\"\u003e\u003ccode\u003e@​sampoder\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96675\"\u003evercel/next.js#96675\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] fix(next/image): preserve image response after optimization by \u003ca href=\"https://github.com/styfle\"\u003e\u003ccode\u003e@​styfle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96733\"\u003evercel/next.js#96733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.3.x] Default deploy e2e tests to the repo next version by \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96900\"\u003evercel/next.js#96900\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Bump \u003ccode\u003e@​swc/helpers\u003c/code\u003e by \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96885\"\u003evercel/next.js#96885\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [turbopack] Raise registration calls in hoisted modules to the top by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97308\"\u003evercel/next.js#97308\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Fix missing styled-jsx styles in Pages Router SSR on adapter builds by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97302\"\u003evercel/next.js#97302\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [turbopack] Fix HMR for dynamic imports evaluated from layouts by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97317\"\u003evercel/next.js#97317\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Restore the live \u003ccode\u003eheaders()\u003c/code\u003e view of the incoming request by \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97311\"\u003evercel/next.js#97311\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/299180d3315c7ebd7b199d2b1a265b5986c5fc7d\"\u003e\u003ccode\u003e299180d\u003c/code\u003e\u003c/a\u003e v16.3.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/a9a1cb7859f178f830ad3773b303130c21b19586\"\u003e\u003ccode\u003ea9a1cb7\u003c/code\u003e\u003c/a\u003e v16.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/d0ac8828c2fe6026dd7d700488bfd8289711fde6\"\u003e\u003ccode\u003ed0ac882\u003c/code\u003e\u003c/a\u003e v16.3.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/3d32eb870fb4c7009d580a31e2de81a626562270\"\u003e\u003ccode\u003e3d32eb8\u003c/code\u003e\u003c/a\u003e v16.3.1\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/vercel/next.js/commits/v16.3.4/packages/third-parties\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@supabase/ssr` from 0.12.4 to 0.12.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/supabase/ssr/releases\"\u003e@​supabase/ssr's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.12.7\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/supabase/ssr/compare/v0.12.6...v0.12.7\"\u003e0.12.7\u003c/a\u003e (2026-09-08)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eapply non-browser defaults when cookies only sets encode (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/294\"\u003e#294\u003c/a\u003e) (\u003ca href=\"https://github.com/supabase/ssr/commit/9d6e2a54f5e7f205388218f7fe732b8622d3ebd8\"\u003e9d6e2a5\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.12.7-rc.162\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore: add workflow for autoclosing stale issues by \u003ca href=\"https://github.com/mandarini\"\u003e\u003ccode\u003e@​mandarini\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/292\"\u003esupabase/ssr#292\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: apply non-browser defaults when cookies only sets encode by \u003ca href=\"https://github.com/PhuocOng\"\u003e\u003ccode\u003e@​PhuocOng\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/294\"\u003esupabase/ssr#294\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/supabase/ssr/compare/v0.12.6...v0.12.7-rc.162\"\u003ehttps://github.com/supabase/ssr/compare/v0.12.6...v0.12.7-rc.162\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev0.12.6\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/supabase/ssr/compare/v0.12.5...v0.12.6\"\u003e0.12.6\u003c/a\u003e (2026-09-04)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eavoid duplicate cache headers per server client (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/283\"\u003e#283\u003c/a\u003e) (\u003ca href=\"https://github.com/supabase/ssr/commit/af750e259b7fab43b9cbc0c19873384a666a7a47\"\u003eaf750e2\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.12.6-rc.158\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore: update \u003ccode\u003e@​supabase/supabase-js\u003c/code\u003e to v2.114.0 by \u003ca href=\"https://github.com/supabase-libs-pr-manager\"\u003e\u003ccode\u003e@​supabase-libs-pr-manager\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/289\"\u003esupabase/ssr#289\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/deploy-pages from 5.0.0 to 5.0.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/290\"\u003esupabase/ssr#290\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid duplicate cache headers per server client by \u003ca href=\"https://github.com/dhruvxvaishnav\"\u003e\u003ccode\u003e@​dhruvxvaishnav\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/283\"\u003esupabase/ssr#283\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: fix typos in tsdoc and design doc by \u003ca href=\"https://github.com/PhuocOng\"\u003e\u003ccode\u003e@​PhuocOng\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/288\"\u003esupabase/ssr#288\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/dhruvxvaishnav\"\u003e\u003ccode\u003e@​dhruvxvaishnav\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/283\"\u003esupabase/ssr#283\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PhuocOng\"\u003e\u003ccode\u003e@​PhuocOng\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/288\"\u003esupabase/ssr#288\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/supabase/ssr/compare/v0.12.5...v0.12.6-rc.158\"\u003ehttps://github.com/supabase/ssr/compare/v0.12.5...v0.12.6-rc.158\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev0.12.5\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/supabase/ssr/compare/v0.12.4...v0.12.5\"\u003e0.12.5\u003c/a\u003e (2026-08-24)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ewarn when auth.storage is ignored by createBrowserClient/createServerClient (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/284\"\u003e#284\u003c/a\u003e) (\u003ca href=\"https://github.com/supabase/ssr/commit/c1700f277f7f03b13e20ff11abeea633816d5238\"\u003ec1700f2\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/supabase/ssr/issues/142\"\u003e#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.12.5-rc.154\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocs: add React Router middleware example by \u003ca href=\"https://github.com/sornapudisuresh\"\u003e\u003ccode\u003e@​sornapudisuresh\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/274\"\u003esupabase/ssr#274\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump pnpm/action-setup from 6.0.9 to 6.0.10 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/280\"\u003esupabase/ssr#280\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump postcss from 8.5.15 to 8.5.25 in the npm_and_yarn group across 1 directory by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/supabase/ssr/pull/281\"\u003esupabase/ssr#281\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/supabase/ssr/blob/main/CHANGELOG.md\"\u003e@​supabase/ssr's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/supabase/ssr/compare/v0.12.6...v0.12.7\"\u003e0.12.7\u003c/a\u003e (2026-09-08)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eapply non-browser defaults when cookies only sets encode (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/294\"\u003e#294\u003c/a\u003e) (\u003ca href=\"https://github.com/supabase/ssr/commit/9d6e2a54f5e7f205388218f7fe732b8622d3ebd8\"\u003e9d6e2a5\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/supabase/ssr/compare/v0.12.5...v0.12.6\"\u003e0.12.6\u003c/a\u003e (2026-09-04)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eavoid duplicate cache headers per server client (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/283\"\u003e#283\u003c/a\u003e) (\u003ca href=\"https://github.com/supabase/ssr/commit/af750e259b7fab43b9cbc0c19873384a666a7a47\"\u003eaf750e2\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/supabase/ssr/compare/v0.12.4...v0.12.5\"\u003e0.12.5\u003c/a\u003e (2026-08-24)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ewarn when auth.storage is ignored by createBrowserClient/createServerClient (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/284\"\u003e#284\u003c/a\u003e) (\u003ca href=\"https://github.com/supabase/ssr/commit/c1700f277f7f03b13e20ff11abeea633816d5238\"\u003ec1700f2\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/supabase/ssr/issues/142\"\u003e#142\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/ssr/commit/9b28f495a358393046851b926551b706d7e4d267\"\u003e\u003ccode\u003e9b28f49\u003c/code\u003e\u003c/a\u003e chore(main): release 0.12.7 (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/295\"\u003e#295\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/ssr/commit/9d6e2a54f5e7f205388218f7fe732b8622d3ebd8\"\u003e\u003ccode\u003e9d6e2a5\u003c/code\u003e\u003c/a\u003e fix: apply non-browser defaults when cookies only sets encode (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/294\"\u003e#294\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/ssr/commit/4ed9f65274760607c5af5126cfa01210e0185ce1\"\u003e\u003ccode\u003e4ed9f65\u003c/code\u003e\u003c/a\u003e chore: add workflow for autoclosing stale issues (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/292\"\u003e#292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/ssr/commit/71c33a7e8c62c7776d30c8f3cd94b8f6771ce0f0\"\u003e\u003ccode\u003e71c33a7\u003c/code\u003e\u003c/a\u003e chore(main): release 0.12.6 (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/291\"\u003e#291\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/ssr/commit/c7c7e68551d286671dc2b85bce6bbe40e24eae12\"\u003e\u003ccode\u003ec7c7e68\u003c/code\u003e\u003c/a\u003e docs: fix typos in tsdoc and design doc (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/288\"\u003e#288\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/ssr/commit/af750e259b7fab43b9cbc0c19873384a666a7a47\"\u003e\u003ccode\u003eaf750e2\u003c/code\u003e\u003c/a\u003e fix: avoid duplicate cache headers per server client (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/283\"\u003e#283\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/ssr/commit/905c7c3672f356d53beafeefd974209d4a5e0a65\"\u003e\u003ccode\u003e905c7c3\u003c/code\u003e\u003c/a\u003e build(deps): bump actions/deploy-pages from 5.0.0 to 5.0.1 (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/290\"\u003e#290\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/ssr/commit/9e2564d780030f1d682e7d28c1eaf88f46c6496a\"\u003e\u003ccode\u003e9e2564d\u003c/code\u003e\u003c/a\u003e chore: update \u003ccode\u003e@​supabase/supabase-js\u003c/code\u003e to v2.114.0 (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/289\"\u003e#289\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/ssr/commit/c5310fdec2786743e56644ed4fc3861991b82124\"\u003e\u003ccode\u003ec5310fd\u003c/code\u003e\u003c/a\u003e chore(main): release 0.12.5 (\u003ca href=\"https://redirect.github.com/supabase/ssr/issues/286\"\u003e#286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/ssr/commit/c1700f277f7f03b13e20ff11abeea633816d5238\"\u003e\u003ccode\u003ec1700f2\u003c/code\u003e\u003c/a\u003e fix: warn when auth.storage is ignored by createBrowserClient/createServerCli...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/supabase/ssr/compare/v0.12.4...v0.12.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@supabase/supabase-js` from 2.112.3 to 2.116.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/supabase/supabase-js/releases\"\u003e@​supabase/supabase-js's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.116.0\u003c/h2\u003e\n\u003ch2\u003e2.116.0 (2026-09-07)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eauth:\u003c/strong\u003e add MFA recovery codes API (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2676\"\u003e#2676\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003estorage:\u003c/strong\u003e add bucket lifecycle configuration (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2659\"\u003e#2659\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003estorage:\u003c/strong\u003e topk 10k support (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2667\"\u003e#2667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003estorage:\u003c/strong\u003e add versionId support to create URL methods (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2678\"\u003e#2678\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eauth:\u003c/strong\u003e silence commit-guard-discarded refresh in initial session (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2668\"\u003e#2668\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003estorage:\u003c/strong\u003e drop legacy prefix from lifecycles (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2674\"\u003e#2674\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003esupabase:\u003c/strong\u003e warn when schema is passed outside db options (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2663\"\u003e#2663\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efadymak\u003c/li\u003e\n\u003cli\u003eFerhat Elmas\u003c/li\u003e\n\u003cli\u003eKaterina Skroumpelou \u003ca href=\"https://github.com/mandarini\"\u003e\u003ccode\u003e@​mandarini\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTyler Hillery\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.116.0-canary.3\u003c/h2\u003e\n\u003ch2\u003e2.116.0-canary.3 (2026-09-07)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eauth:\u003c/strong\u003e add MFA recovery codes API (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2676\"\u003e#2676\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003estorage:\u003c/strong\u003e add versionId support to create URL methods (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2678\"\u003e#2678\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efadymak\u003c/li\u003e\n\u003cli\u003eKaterina Skroumpelou\u003c/li\u003e\n\u003cli\u003eTyler Hillery\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.116.0-canary.2\u003c/h2\u003e\n\u003ch2\u003e2.116.0-canary.2 (2026-09-07)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003estorage:\u003c/strong\u003e topk 10k support (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2667\"\u003e#2667\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003estorage:\u003c/strong\u003e drop legacy prefix from lifecycles (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2674\"\u003e#2674\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/supabase/supabase-js/blob/master/packages/core/supabase-js/CHANGELOG.md\"\u003e@​supabase/supabase-js's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.116.0 (2026-09-07)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eauth:\u003c/strong\u003e add MFA recovery codes API (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2676\"\u003e#2676\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003esupabase:\u003c/strong\u003e warn when schema is passed outside db options (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2663\"\u003e#2663\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efadymak\u003c/li\u003e\n\u003cli\u003eKaterina Skroumpelou \u003ca href=\"https://github.com/mandarini\"\u003e\u003ccode\u003e@​mandarini\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.115.0 (2026-09-03)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003epostgrest:\u003c/strong\u003e add getOpenApiSpec() (\u003ca href=\"https://redirect.github.com/supabase/supabase-js/pull/2651\"\u003e#2651\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eKaterina Skroumpelou \u003ca href=\"https://github.com/mandarini\"\u003e\u003ccode\u003e@​mandarini\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.114.0 (2026-09-02)\u003c/h2\u003e\n\u003cp\u003eThis was a version bump only for \u003ccode\u003e@​supabase/supabase-js\u003c/code\u003e to align it with other projects, there were no code changes.\u003c/p\u003e\n\u003ch2\u003e2.113.0 (2026-09-02)\u003c/h2\u003e\n\u003cp\u003eThis was a version bump only for \u003ccode\u003e@​supabase/supabase-js\u003c/code\u003e to align it with other projects, there were no code changes.\u003c/p\u003e\n\u003ch2\u003e2.112.4 (2026-08-24)\u003c/h2\u003e\n\u003cp\u003eThis was a version bump only for \u003ccode\u003e@​supabase/supabase-js\u003c/code\u003e to align it with other projects, there were no code changes.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/supabase-js/commit/5aedaab92566149dc728ce0480b032841dddd463\"\u003e\u003ccode\u003e5aedaab\u003c/code\u003e\u003c/a\u003e feat(auth): add MFA recovery codes API (\u003ca href=\"https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js/issues/2676\"\u003e#2676\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/supabase-js/commit/e4f675a96addf3e767c38f7e8c8759754f10f490\"\u003e\u003ccode\u003ee4f675a\u003c/code\u003e\u003c/a\u003e fix(supabase): warn when schema is passed outside db options (\u003ca href=\"https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js/issues/2663\"\u003e#2663\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/supabase-js/commit/dbe76791e9eab34d1b91ec0ebdb9f11fc770b4eb\"\u003e\u003ccode\u003edbe7679\u003c/code\u003e\u003c/a\u003e chore(release): version 2.115.0 changelogs (\u003ca href=\"https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js/issues/2664\"\u003e#2664\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/supabase-js/commit/3eb61931b0d81728eece27b43df962e7336b0ed5\"\u003e\u003ccode\u003e3eb6193\u003c/code\u003e\u003c/a\u003e docs(supabase): clarify db.schema needs the second generic (\u003ca href=\"https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js/issues/2662\"\u003e#2662\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/supabase-js/commit/92fb8ba0cbfc50c3f550b0768210e98d26f2b1d5\"\u003e\u003ccode\u003e92fb8ba\u003c/code\u003e\u003c/a\u003e feat(postgrest): add getOpenApiSpec() (\u003ca href=\"https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js/issues/2651\"\u003e#2651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/supabase-js/commit/aef432bc806fbbe90dde71ec9b75e3cc6d702a31\"\u003e\u003ccode\u003eaef432b\u003c/code\u003e\u003c/a\u003e chore(release): version 2.114.0 changelogs (\u003ca href=\"https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js/issues/2653\"\u003e#2653\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/supabase-js/commit/67b07b075220806f8f7355995db646bd6d0a85db\"\u003e\u003ccode\u003e67b07b0\u003c/code\u003e\u003c/a\u003e chore(release): version 2.113.0 changelogs (\u003ca href=\"https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js/issues/2650\"\u003e#2650\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/supabase-js/commit/062ae5e6f5e06c08284d7392316389dc7a935baf\"\u003e\u003ccode\u003e062ae5e\u003c/code\u003e\u003c/a\u003e chore(release): version 2.112.4 changelogs (\u003ca href=\"https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js/issues/2628\"\u003e#2628\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/supabase-js/commit/c7397c19cb6cb8b1562be27cb0a09ed0e240276a\"\u003e\u003ccode\u003ec7397c1\u003c/code\u003e\u003c/a\u003e chore(supabase): bump supabase cli to 2.113.0 (\u003ca href=\"https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js/issues/2606\"\u003e#2606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/supabase/supabase-js/commit/bbc167cbef7fb841d44c53fb3c45e1d19aa3ece3\"\u003e\u003ccode\u003ebbc167c\u003c/code\u003e\u003c/a\u003e chore(release): version 2.112.3 changelogs (\u003ca href=\"https://github.com/supabase/supabase-js/tree/HEAD/packages/core/supabase-js/issues/2608\"\u003e#2608\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/supabase/supabase-js/commits/v2.116.0/packages/core/supabase-js\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `lucide-react` from 1.31.0 to 1.43.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lucide-icons/lucide/releases\"\u003elucide-react's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 1.43.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003etic-tac-toe\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4772\"\u003elucide-icons/lucide#4772\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): changed \u003ccode\u003eid-card\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4820\"\u003elucide-icons/lucide#4820\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): changed \u003ccode\u003eid-card-lanyard\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4819\"\u003elucide-icons/lucide#4819\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): delegate \u003ccode\u003ecarton\u003c/code\u003e/\u003ccode\u003ecarton-off\u003c/code\u003e from lab by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4818\"\u003elucide-icons/lucide#4818\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/lucide-icons/lucide/compare/1.42.0...1.43.0\"\u003ehttps://github.com/lucide-icons/lucide/compare/1.42.0...1.43.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 1.42.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(docs): added better contribution guide by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4746\"\u003elucide-icons/lucide#4746\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(site): fix HomeHeroIconsCard.data.ts by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4805\"\u003elucide-icons/lucide#4805\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): deprecated swiss franc icons by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4799\"\u003elucide-icons/lucide#4799\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): add gap-horizontal and gap-vertical by \u003ca href=\"https://github.com/samuelalake\"\u003e\u003ccode\u003e@​samuelalake\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4544\"\u003elucide-icons/lucide#4544\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003etrash-off\u003c/code\u003e icon by \u003ca href=\"https://github.com/lx3133584\"\u003e\u003ccode\u003e@​lx3133584\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4788\"\u003elucide-icons/lucide#4788\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003ecircle-dashed-check\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4796\"\u003elucide-icons/lucide#4796\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003eequal-approximately-not\u003c/code\u003e icon by \u003ca href=\"https://github.com/ryck\"\u003e\u003ccode\u003e@​ryck\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4802\"\u003elucide-icons/lucide#4802\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added dome icons by \u003ca href=\"https://github.com/swastik7805\"\u003e\u003ccode\u003e@​swastik7805\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4261\"\u003elucide-icons/lucide#4261\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(lucide-react): Add Lucide React integration tests by \u003ca href=\"https://github.com/ericfennis\"\u003e\u003ccode\u003e@​ericfennis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4804\"\u003elucide-icons/lucide#4804\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(packages): extract icon build logic into \u003ccode\u003e@lucide/shared\u003c/code\u003e by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4409\"\u003elucide-icons/lucide#4409\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): changed \u003ccode\u003ecomputer\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4607\"\u003elucide-icons/lucide#4607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(dependencies): Update dependencies by \u003ca href=\"https://github.com/ericfennis\"\u003e\u003ccode\u003e@​ericfennis\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4806\"\u003elucide-icons/lucide#4806\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): changed \u003ccode\u003etable-2\u003c/code\u003e icon by \u003ca href=\"https://github.com/jguddas\"\u003e\u003ccode\u003e@​jguddas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4810\"\u003elucide-icons/lucide#4810\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003euser-group\u003c/code\u003e icons by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4782\"\u003elucide-icons/lucide#4782\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lx3133584\"\u003e\u003ccode\u003e@​lx3133584\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4788\"\u003elucide-icons/lucide#4788\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ryck\"\u003e\u003ccode\u003e@​ryck\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4802\"\u003elucide-icons/lucide#4802\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/lucide-icons/lucide/compare/1.41.0...1.42.0\"\u003ehttps://github.com/lucide-icons/lucide/compare/1.41.0...1.42.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 1.41.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(icons): Add new icons \u003ccode\u003egerm\u003c/code\u003e and \u003ccode\u003egerm-off\u003c/code\u003e by \u003ca href=\"https://github.com/rrod497\"\u003e\u003ccode\u003e@​rrod497\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4056\"\u003elucide-icons/lucide#4056\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003edoor-stairwell\u003c/code\u003e icon \u0026amp; updated \u003ccode\u003edoor-*\u003c/code\u003e icons by \u003ca href=\"https://github.com/jguddas\"\u003e\u003ccode\u003e@​jguddas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/3554\"\u003elucide-icons/lucide#3554\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003ecredit-card-reader\u003c/code\u003e icon by \u003ca href=\"https://github.com/jguddas\"\u003e\u003ccode\u003e@​jguddas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4616\"\u003elucide-icons/lucide#4616\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added 'engine' icon by \u003ca href=\"https://github.com/benhaube\"\u003e\u003ccode\u003e@​benhaube\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4598\"\u003elucide-icons/lucide#4598\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): fixed \u003ccode\u003egerm\u003c/code\u003e \u0026amp; \u003ccode\u003egerm-off\u003c/code\u003e by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4789\"\u003elucide-icons/lucide#4789\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump the vue-deps group with 2 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4771\"\u003elucide-icons/lucide#4771\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003evirus\u003c/code\u003e/\u003ccode\u003evirus-off\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4765\"\u003elucide-icons/lucide#4765\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(copilot-reviews): Improve use-cases description. by \u003ca href=\"https://github.com/ericfennis\"\u003e\u003ccode\u003e@​ericfennis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4558\"\u003elucide-icons/lucide#4558\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): add \u003ccode\u003ecan-soda\u003c/code\u003e icon by \u003ca href=\"https://github.com/jaynewey\"\u003e\u003ccode\u003e@​jaynewey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4718\"\u003elucide-icons/lucide#4718\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003esquare-alert\u003c/code\u003e Icon by \u003ca href=\"https://github.com/viralcodex\"\u003e\u003ccode\u003e@​viralcodex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/3687\"\u003elucide-icons/lucide#3687\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(lab): Add label for lab icons by \u003ca href=\"https://github.com/ericfennis\"\u003e\u003ccode\u003e@​ericfennis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4793\"\u003elucide-icons/lucide#4793\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): changed \u003ccode\u003elab/bottle-toothbrush-comb\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4756\"\u003elucide-icons/lucide#4756\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(\u003ccode\u003e@​lucide/lab\u003c/code\u003e): Create automatic release flow for \u003ccode\u003e@lucide/lab\u003c/code\u003e by \u003ca href=\"https://github.com/ericfennis\"\u003e\u003ccode\u003e@​ericfennis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4792\"\u003elucide-icons/lucide#4792\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): removed \u003ccode\u003etrash\u003c/code\u003e icon in favour of \u003ccode\u003etrash-2\u003c/code\u003e by \u003ca href=\"https://github.com/jguddas\"\u003e\u003ccode\u003e@​jguddas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/3141\"\u003elucide-icons/lucide#3141\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): changed \u003ccode\u003eleaf\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4801\"\u003elucide-icons/lucide#4801\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lucide-icons/lucide/commit/94e4cb9d9db5907053ebf3636a97c45529cf776b\"\u003e\u003ccode\u003e94e4cb9\u003c/code\u003e\u003c/a\u003e chore(dependencies): Update dependencies (\u003ca href=\"https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4806\"\u003e#4806\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lucide-icons/lucide/commit/99d25bdee231922e73e19525f57a585d1682fab2\"\u003e\u003ccode\u003e99d25bd\u003c/code\u003e\u003c/a\u003e feat(packages): extract icon build logic into \u003ccode\u003e@lucide/shared\u003c/code\u003e (\u003ca href=\"https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4409\"\u003e#4409\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lucide-icons/lucide/commit/75b55160aa9edd7095dfed1a6e3d88e66fb2b153\"\u003e\u003ccode\u003e75b5516\u003c/code\u003e\u003c/a\u003e chore(dev): upgrade ESLint to latest compatible stack (v10) (\u003ca href=\"https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4378\"\u003e#4378\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/lucide-icons/lucide/commits/1.43.0/packages/lucide-react\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `next` from 16.3.0 to 16.3.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003enext's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.4\u003c/h2\u003e\n\u003cp\u003eFollow-up release to \u003ca href=\"https://github.com/vercel/next.js/releases/tag/v16.3.3\"\u003ev16.3.3\u003c/a\u003e re-enabling AVIF Image Optimization (\u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97949\"\u003e#97949\u003c/a\u003e).\u003c/p\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003etestmode: Fix infinite recursion in testmode passthrough fetch (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97691\"\u003e#97691\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix build error when aliasing typescript to \u003ccode\u003e@​typescript/typescript6\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97997\"\u003e#97997\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix unset crossOrigin in Turbopack manifests (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97930\"\u003e#97930\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.3\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eCritical:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36\"\u003eUnauthenticated Remote Code Execution on windows-hosted servers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4\"\u003eUnauthenticated Remote Code Execution in Image Optimization API when AVIF files are used\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.2\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Scope app-entry export validation to files inside the app directory (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97357\"\u003e#97357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[backport] Fix catch-all index page being served for every other slug (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97416\"\u003e#97416\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: don't trace embedded WASM loader helpers (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97353\"\u003e#97353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97463\"\u003e#97463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: retain conditions when replacing resolve request keys (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97453\"\u003e#97453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Fix Turbopack worker chunk loading with asset prefix (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97419\"\u003e#97419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97603\"\u003e#97603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/lubieowoce\"\u003e\u003ccode\u003e@​lubieowoce\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[16.x] Turbopack: don't strip async-module runtime from shared runtime chunks by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96653\"\u003evercel/next.js#96653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] [turbopack] Add \u003ccode\u003eturbopack_ecmascript\u003c/code\u003e and \u003ccode\u003eturbopack_wasm\u003c/code\u003e's embeded FS to \u003ccode\u003einternal_assets_conditions\u003c/code\u003e by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96655\"\u003evercel/next.js#96655\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] [turbopack] Collapse nested promises in the analyzer by \u003ca href=\"https://github.com/sampoder\"\u003e\u003ccode\u003e@​sampoder\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96675\"\u003evercel/next.js#96675\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] fix(next/image): preserve image response after optimization by \u003ca href=\"https://github.com/styfle\"\u003e\u003ccode\u003e@​styfle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96733\"\u003evercel/next.js#96733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.3.x] Default deploy e2e tests to the repo next version by \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96900\"\u003evercel/next.js#96900\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Bump \u003ccode\u003e@​swc/helpers\u003c/code\u003e by \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96885\"\u003evercel/next.js#96885\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [turbopack] Raise registration calls in hoisted modules to the top by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97308\"\u003evercel/next.js#97308\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Fix missing styled-jsx styles in Pages Router SSR on adapter builds by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97302\"\u003evercel/next.js#97302\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [turbopack] Fix HMR for dynamic imports evaluated from layouts by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97317\"\u003evercel/next.js#97317\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Restore the live \u003ccode\u003eheaders()\u003c/code\u003e view of the incoming request by \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97311\"\u003evercel/next.js#97311\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/299180d3315c7ebd7b199d2b1a265b5986c5fc7d\"\u003e\u003ccode\u003e299180d\u003c/code\u003e\u003c/a\u003e v16.3.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/12e173dd73ed6c39622281c7282c8364234ad94f\"\u003e\u003ccode\u003e12e173d\u003c/code\u003e\u003c/a\u003e [16.3.x] Re-enable AVIF image optimization and require sharp 0.35.4 (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97949\"\u003e#97949\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/5d9022edd29e32d7061bc56cf713ffe8769cd900\"\u003e\u003ccode\u003e5d9022e\u003c/code\u003e\u003c/a\u003e [backport] Fix unset crossOrigin in Turbopack manifests (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97930\"\u003e#97930\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/d8f45609fa74e56f24958d45d93d3426511f957f\"\u003e\u003ccode\u003ed8f4560\u003c/code\u003e\u003c/a\u003e [16.3.x] Fix build error when aliasing typescript to \u003ccode\u003e@​typescript/typescript6\u003c/code\u003e ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/656aebfb58ce194fb603f18942dad6e94d15b21c\"\u003e\u003ccode\u003e656aebf\u003c/code\u003e\u003c/a\u003e [16.3] testmode: Fix infinite recursion in testmode passthrough fetch (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97691\"\u003e#97691\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/f37c1d656553b8950330b6683ab242a5c610135c\"\u003e\u003ccode\u003ef37c1d6\u003c/code\u003e\u003c/a\u003e [16.3.x] ci: remove pull_request_stats workflow (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97975\"\u003e#97975\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/a9a1cb7859f178f830ad3773b303130c21b19586\"\u003e\u003ccode\u003ea9a1cb7\u003c/code\u003e\u003c/a\u003e v16.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/968b9fcb26bdeb8e0a861a9df05361474666d51b\"\u003e\u003ccode\u003e968b9fc\u003c/code\u003e\u003c/a\u003e [16.3.x] Fix ISR misses with backslashes in segments when deployed on Windows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/3a15b4ac6ac8e70b1a9b18ecc18e8434462899b3\"\u003e\u003ccode\u003e3a15b4a\u003c/code\u003e\u003c/a\u003e [16.3.x] [next/image]: disable avif image optimization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/7378b51ea05a6745d3676bee00cb4c63aac3dd16\"\u003e\u003ccode\u003e7378b51\u003c/code\u003e\u003c/a\u003e Backport/docs fixes 16.3 (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97649\"\u003e#97649\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/compare/v16.3.0...v16.3.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `resend` from 6.19.0 to 6.26.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/resend/resend-node/releases\"\u003eresend's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.26.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(webhooks): add events.replay() by \u003ca href=\"https://github.com/gabrielmfern\"\u003e\u003ccode\u003e@​gabrielmfern\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/resend/resend-node/pull/1087\"\u003eresend/resend-node#1087\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/resend/resend-node/compare/v6.25.0...v6.26.0\"\u003ehttps://github.com/resend/resend-node/compare/v6.25.0...v6.26.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.25.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: allow CNAME type on domain SPF records by \u003ca href=\"https://github.com/vieiralucas\"\u003e\u003ccode\u003e@​vieiralucas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/resend/resend-node/pull/1085\"\u003eresend/resend-node#1085\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/resend/resend-node/compare/v6.24.0...v6.25.0\"\u003ehttps://github.com/resend/resend-node/compare/v6.24.0...v6.25.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.24.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(webhooks): promote event endpoints to stable by \u003ca href=\"https://github.com/gabrielmfern\"\u003e\u003ccode\u003e@​gabrielmfern\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/resend/resend-node/pull/1083\"\u003eresend/resend-node#1083\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/resend/resend-node/compare/v6.23.0...v6.24.0\"\u003ehttps://github.com/resend/resend-node/compare/v6.23.0...v6.24.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.23.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(segments): add segments.update() by \u003ca href=\"https://github.com/dielduarte\"\u003e\u003ccode\u003e@​dielduarte\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/resend/resend-node/pull/1084\"\u003eresend/resend-node#1084\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/resend/resend-node/compare/v6.22.1...v6.23.0\"\u003ehttps://github.com/resend/resend-node/compare/v6.22.1...v6.23.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.22.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: allow null contact first_name and last_name on webhook events by \u003ca href=\"https://github.com/gabrielmfern\"\u003e\u003ccode\u003e@​gabrielmfern\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/resend/resend-node/pull/1073\"\u003eresend/resend-node#1073\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump version to 6.22.1 by \u003ca href=\"https://github.com...\n\n_Description has been truncated_","html_url":"https://github.com/orbisdei/v2/pull/136","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/orbisdei%2Fv2/issues/136","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/136/packages"}},{"old_version":"6.27.0","new_version":"8.10.2","update_type":"major","path":"/clients/typescript","pr_created_at":"2026-09-12T00:22:56.000Z","version_change":"6.27.0 → 8.10.2","issue":{"uuid":"5430067211","node_id":"PR_kwDOS43PYc8AAAABDNsKuA","number":347,"state":"open","title":"chore(deps): bump undici from 6.27.0 to 8.10.2 in /clients/typescript","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-12T00:22:56.000Z","updated_at":"2026-09-12T00:23:18.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"undici","old_version":"6.27.0","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"}],"path":"/clients/typescript","ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 6.27.0 to 8.10.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm\"\u003eGHSA-vp8m-p9jh-q5pm\u003c/a\u003e: cache and deduplication interceptors could use caller-controlled request metadata instead of the authoritative dispatcher origin, enabling cross-origin cache poisoning and data disclosure. Undici now derives interceptor identities from the dispatcher origin and bypasses origin-dependent interceptors when no authoritative origin exists. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/caf6194d3dae989b731ed87ab85f182befe5eb80\"\u003ecaf6194d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e8f5868fb\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e66e12816\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6\"\u003e4411a238\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/662d0ea671fe64139e79533c913fce412765e1d7\"\u003e662d0ea6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003ecb75bbb3\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e7aac7f12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003ee905b5b8\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e2be07bf9\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e6d583124\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e0160a719\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps-dev): bump undici from 6.27.0 to 6.28.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5653\"\u003enodejs/undici#5653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump jest from 30.4.2 to 30.5.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5750\"\u003enodejs/undici#5750\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/analyze from 4.37.3 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5752\"\u003enodejs/undici#5752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5754\"\u003enodejs/undici#5754\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(h2): cover stream reset with NGHTTP2_INTERNAL_ERROR by \u003ca href=\"https://github.com/zeexzeex\"\u003e\u003ccode\u003e@​zeexzeex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5725\"\u003enodejs/undici#5725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): reject invalid resumed responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5724\"\u003enodejs/undici#5724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: make stale-while-revalidate cache update test deterministic by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5722\"\u003enodejs/undici#5722\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid unbounded recursion in Set-Cookie attribute parser by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5757\"\u003enodejs/undici#5757\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: honor SOCKS5 connection timeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5733\"\u003enodejs/undici#5733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(eventsource): validate Last-Event-ID on reconnect by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5746\"\u003enodejs/undici#5746\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid duplicate release attempts by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5745\"\u003enodejs/undici#5745\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(cache): refetch when 304 adds vary fields by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5732\"\u003enodejs/undici#5732\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etypes: expose PendingInterceptor and PendingInterceptorsFormatter on the MockAgent namespace by \u003ca href=\"https://github.com/RaphaelFakhri\"\u003e\u003ccode\u003e@​RaphaelFakhri\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5721\"\u003enodejs/undici#5721\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(codeql): align CodeQL action versions to v4.37.9 by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5759\"\u003enodejs/undici#5759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5760\"\u003enodejs/undici#5760\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(proxy-agent): guard Proxy-Authorization in iterable header containers by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5758\"\u003enodejs/undici#5758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: name the parameters these two blocks describe by \u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): fail the connection on a non-200 h2 extended CONNECT response by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(node-fetch): re-enable the set-cookie header combining test by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5730\"\u003enodejs/undici#5730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward rawHeaders writes through RetryController by \u003ca href=\"https://github.com/official-burak\"\u003e\u003ccode\u003e@​official-burak\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5727\"\u003enodejs/undici#5727\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5738\"\u003enodejs/undici#5738\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/5e541e0b9df7563e5766bbd469fbfe383d9ae6ca\"\u003e\u003ccode\u003e5e541e0\u003c/code\u003e\u003c/a\u003e Bumped v8.10.2 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5771\"\u003e#5771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/eb04cc39954e63e9b46bdf824e6efad9fff2e7b5\"\u003e\u003ccode\u003eeb04cc3\u003c/code\u003e\u003c/a\u003e fix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5738\"\u003e#5738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003e\u003ccode\u003ee905b5b\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e\u003ccode\u003e0160a71\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e\u003ccode\u003e66e1281\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e\u003ccode\u003e7aac7f1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003e\u003ccode\u003ecb75bbb\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e\u003ccode\u003e6d58312\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e\u003ccode\u003e8f5868f\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e\u003ccode\u003e2be07bf\u003c/code\u003e\u003c/a\u003e fix(cache): reject unsafe method response caching\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v8.10.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=6.27.0\u0026new-version=8.10.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/SBALAVIGNESH123/sketchlog/pull/347","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/SBALAVIGNESH123%2Fsketchlog/issues/347","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/347/packages"}},{"old_version":"8.10.0","new_version":"8.10.2","update_type":"patch","path":null,"pr_created_at":"2026-09-12T00:03:43.000Z","version_change":"8.10.0 → 8.10.2","issue":{"uuid":"5429980099","node_id":"PR_kwDOOTUI_M8AAAABDNn8PA","number":1140,"state":"open","title":"Bump the prod group across 1 directory with 3 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-12T00:03:43.000Z","updated_at":"2026-09-12T00:04:50.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"prod","update_count":3,"packages":[{"name":"i18next","old_version":"26.4.0","new_version":"26.4.2","repository_url":"https://github.com/i18next/i18next"},{"name":"jose","old_version":"6.2.10","new_version":"6.2.11","repository_url":"https://github.com/panva/jose"},{"name":"undici","old_version":"8.10.0","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps the prod group with 3 updates in the / directory: [i18next](https://github.com/i18next/i18next), [jose](https://github.com/panva/jose) and [undici](https://github.com/nodejs/undici).\n\nUpdates `i18next` from 26.4.0 to 26.4.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/i18next/i18next/releases\"\u003ei18next's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev26.4.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: \u003ccode\u003e$\u0026amp;\u003c/code\u003e, \u003ccode\u003e$`\u003c/code\u003e, \u003ccode\u003e$'\u003c/code\u003e and \u003ccode\u003e$$\u003c/code\u003e inside a nested value (\u003ccode\u003e$t(key)\u003c/code\u003e) now stay literal. \u003ccode\u003enest()\u003c/code\u003e handed the resolved value straight to \u003ccode\u003eString.replace\u003c/code\u003e as the replacement argument, so those sequences were read as replacement patterns: \u003ccode\u003e$\u0026amp;\u003c/code\u003e re-inserted the \u003ccode\u003e$t(...)\u003c/code\u003e match, \u003ccode\u003e$`\u003c/code\u003e / \u003ccode\u003e$'\u003c/code\u003e inserted the text before / after it, and \u003ccode\u003e$$\u003c/code\u003e collapsed to \u003ccode\u003e$\u003c/code\u003e. Through \u003ccode\u003et()\u003c/code\u003e the \u003ccode\u003e$\u0026amp;\u003c/code\u003e case was worse than a wrong string: the nested lookup resets the shared nesting regexp, so the re-inserted \u003ccode\u003e$t(...)\u003c/code\u003e was matched again on every pass and \u003ccode\u003et()\u003c/code\u003e never returned — also under the default \u003ccode\u003eescapeValue: true\u003c/code\u003e when the value arrives via a variable forwarded through nesting options (\u003ccode\u003e$t(key, { \u0026quot;name\u0026quot;: \u0026quot;{{name}}\u0026quot; })\u003c/code\u003e with a name containing \u003ccode\u003e$\u0026amp;\u003c/code\u003e). The value is now \u003ccode\u003e$\u003c/code\u003e-escaped at the \u003ccode\u003eString.replace\u003c/code\u003e call, the same guard \u003ccode\u003einterpolate()\u003c/code\u003e already has, and a non-string value returned by a formatter in the nesting chain (\u003ccode\u003e$t(key, myFormat)\u003c/code\u003e) is stringified before that. Nested values are still not HTML-escaped (\u003ca href=\"https://redirect.github.com/i18next/i18next/issues/854\"\u003e#854\u003c/a\u003e). Thanks \u003ca href=\"https://github.com/mahirhir\"\u003e\u003ccode\u003e@​mahirhir\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/i18next/i18next/pull/2447\"\u003e#2447\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev26.4.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(types): the selector-form \u003ccode\u003ekeyPrefix\u003c/code\u003e overload of \u003ccode\u003egetFixedT()\u003c/code\u003e is now available under \u003ccode\u003eenableSelector: 'strict'\u003c/code\u003e. Its constraint was gated on \u003ccode\u003etrue | 'optimize'\u003c/code\u003e only, so under \u003ccode\u003e'strict'\u003c/code\u003e it collapsed to \u003ccode\u003enever\u003c/code\u003e, the overload dropped out, and the returned \u003ccode\u003et\u003c/code\u003e silently lost its \u003ccode\u003ekeyPrefix\u003c/code\u003e scope (\u003ccode\u003et(($) =\u0026gt; $.deep)\u003c/code\u003e failed with \u003ccode\u003eProperty 'deep' does not exist on type '{}'\u003c/code\u003e). The same call already typechecked under \u003ccode\u003etrue\u003c/code\u003e and \u003ccode\u003e'optimize'\u003c/code\u003e. Thanks \u003ca href=\"https://github.com/hovelopin\"\u003e\u003ccode\u003e@​hovelopin\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/i18next/i18next/pull/2446\"\u003e#2446\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/i18next/i18next/blob/master/CHANGELOG.md\"\u003ei18next's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e26.4.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: \u003ccode\u003e$\u0026amp;\u003c/code\u003e, \u003ccode\u003e$`\u003c/code\u003e, \u003ccode\u003e$'\u003c/code\u003e and \u003ccode\u003e$$\u003c/code\u003e inside a nested value (\u003ccode\u003e$t(key)\u003c/code\u003e) now stay literal. \u003ccode\u003enest()\u003c/code\u003e handed the resolved value straight to \u003ccode\u003eString.replace\u003c/code\u003e as the replacement argument, so those sequences were read as replacement patterns: \u003ccode\u003e$\u0026amp;\u003c/code\u003e re-inserted the \u003ccode\u003e$t(...)\u003c/code\u003e match, \u003ccode\u003e$`\u003c/code\u003e / \u003ccode\u003e$'\u003c/code\u003e inserted the text before / after it, and \u003ccode\u003e$$\u003c/code\u003e collapsed to \u003ccode\u003e$\u003c/code\u003e. Through \u003ccode\u003et()\u003c/code\u003e the \u003ccode\u003e$\u0026amp;\u003c/code\u003e case was worse than a wrong string: the nested lookup resets the shared nesting regexp, so the re-inserted \u003ccode\u003e$t(...)\u003c/code\u003e was matched again on every pass and \u003ccode\u003et()\u003c/code\u003e never returned — also under the default \u003ccode\u003eescapeValue: true\u003c/code\u003e when the value arrives via a variable forwarded through nesting options (\u003ccode\u003e$t(key, { \u0026quot;name\u0026quot;: \u0026quot;{{name}}\u0026quot; })\u003c/code\u003e with a name containing \u003ccode\u003e$\u0026amp;\u003c/code\u003e). The value is now \u003ccode\u003e$\u003c/code\u003e-escaped at the \u003ccode\u003eString.replace\u003c/code\u003e call, the same guard \u003ccode\u003einterpolate()\u003c/code\u003e already has, and a non-string value returned by a formatter in the nesting chain (\u003ccode\u003e$t(key, myFormat)\u003c/code\u003e) is stringified before that. Nested values are still not HTML-escaped (\u003ca href=\"https://redirect.github.com/i18next/i18next/issues/854\"\u003e#854\u003c/a\u003e). Thanks \u003ca href=\"https://github.com/mahirhir\"\u003e\u003ccode\u003e@​mahirhir\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/i18next/i18next/pull/2447\"\u003e#2447\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e26.4.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(types): the selector-form \u003ccode\u003ekeyPrefix\u003c/code\u003e overload of \u003ccode\u003egetFixedT()\u003c/code\u003e is now available under \u003ccode\u003eenableSelector: 'strict'\u003c/code\u003e. Its constraint was gated on \u003ccode\u003etrue | 'optimize'\u003c/code\u003e only, so under \u003ccode\u003e'strict'\u003c/code\u003e it collapsed to \u003ccode\u003enever\u003c/code\u003e, the overload dropped out, and the returned \u003ccode\u003et\u003c/code\u003e silently lost its \u003ccode\u003ekeyPrefix\u003c/code\u003e scope (\u003ccode\u003et(($) =\u0026gt; $.deep)\u003c/code\u003e failed with \u003ccode\u003eProperty 'deep' does not exist on type '{}'\u003c/code\u003e). The same call already typechecked under \u003ccode\u003etrue\u003c/code\u003e and \u003ccode\u003e'optimize'\u003c/code\u003e. Thanks \u003ca href=\"https://github.com/hovelopin\"\u003e\u003ccode\u003e@​hovelopin\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/i18next/i18next/pull/2446\"\u003e#2446\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next/commit/4dba50f20669c3678db0812255716eb7693ad2da\"\u003e\u003ccode\u003e4dba50f\u003c/code\u003e\u003c/a\u003e 26.4.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next/commit/e436b625a648e1a48ea27ecf5f2fba8020d67009\"\u003e\u003ccode\u003ee436b62\u003c/code\u003e\u003c/a\u003e build\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next/commit/d955fb086e9f4ded1200f51ecbb21034dbad1d92\"\u003e\u003ccode\u003ed955fb0\u003c/code\u003e\u003c/a\u003e fix: stringify formatter results in nested values, changelog v26.4.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next/commit/dfafa3ca725e1415ef20e7fb5b1b3e4468f3c425\"\u003e\u003ccode\u003edfafa3c\u003c/code\u003e\u003c/a\u003e fix: keep replacement patterns literal in nested values (\u003ca href=\"https://redirect.github.com/i18next/i18next/issues/2447\"\u003e#2447\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next/commit/3c9981e22dd471b6bca224aa1f60e04ba3f6153a\"\u003e\u003ccode\u003e3c9981e\u003c/code\u003e\u003c/a\u003e chore: keep dev-only and local files out of the npm package\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next/commit/c057ee048c55a61c095acc017365e997e4f723f8\"\u003e\u003ccode\u003ec057ee0\u003c/code\u003e\u003c/a\u003e 26.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next/commit/02e3e1659b7cc9fedaaf53797597483ef8003df2\"\u003e\u003ccode\u003e02e3e16\u003c/code\u003e\u003c/a\u003e changelog v26.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/i18next/i18next/commit/6f198f2508ba8986d1bbf25a8b922d01afcf0751\"\u003e\u003ccode\u003e6f198f2\u003c/code\u003e\u003c/a\u003e fix(types): allow selector keyPrefix in getFixedT under enableSelector 'stric...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/i18next/i18next/compare/v26.4.0...v26.4.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `jose` from 6.2.10 to 6.2.11\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/panva/jose/releases\"\u003ejose's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.2.11\u003c/h2\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003erender subpath indexes as tables (\u003ca href=\"https://github.com/panva/jose/commit/94589ee9efe6cf257a133765d753bbe8d55f6ed3\"\u003e94589ee\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eshorten API index descriptions (\u003ca href=\"https://github.com/panva/jose/commit/681482fcca7577c6a4b8df61c992f195f6e6ac1b\"\u003e681482f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003emodel JWE key management modes (\u003ca href=\"https://github.com/panva/jose/commit/e01dda65d5d272c8dd44710d0c70673c1530038e\"\u003ee01dda6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypes:\u003c/strong\u003e reduce declaration repetition (\u003ca href=\"https://github.com/panva/jose/commit/55b970fc08c9082041f40473470ee0fe0e8b0087\"\u003e55b970f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/panva/jose/blob/main/CHANGELOG.md\"\u003ejose's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/panva/jose/compare/v6.2.10...v6.2.11\"\u003e6.2.11\u003c/a\u003e (2026-09-04)\u003c/h2\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003erender subpath indexes as tables (\u003ca href=\"https://github.com/panva/jose/commit/94589ee9efe6cf257a133765d753bbe8d55f6ed3\"\u003e94589ee\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eshorten API index descriptions (\u003ca href=\"https://github.com/panva/jose/commit/681482fcca7577c6a4b8df61c992f195f6e6ac1b\"\u003e681482f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003emodel JWE key management modes (\u003ca href=\"https://github.com/panva/jose/commit/e01dda65d5d272c8dd44710d0c70673c1530038e\"\u003ee01dda6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypes:\u003c/strong\u003e reduce declaration repetition (\u003ca href=\"https://github.com/panva/jose/commit/55b970fc08c9082041f40473470ee0fe0e8b0087\"\u003e55b970f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/f5e56061ea6c20d66bf1caeb0111141ec2afa961\"\u003e\u003ccode\u003ef5e5606\u003c/code\u003e\u003c/a\u003e chore(release): 6.2.11\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/d60f1b4c50bf39a3fc581fbcd56e791a760fc674\"\u003e\u003ccode\u003ed60f1b4\u003c/code\u003e\u003c/a\u003e chore: bump packages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/55b970fc08c9082041f40473470ee0fe0e8b0087\"\u003e\u003ccode\u003e55b970f\u003c/code\u003e\u003c/a\u003e refactor(types): reduce declaration repetition\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/681482fcca7577c6a4b8df61c992f195f6e6ac1b\"\u003e\u003ccode\u003e681482f\u003c/code\u003e\u003c/a\u003e docs: shorten API index descriptions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/33c88179c0e270ab2e599d5dbd7d024b9742775e\"\u003e\u003ccode\u003e33c8817\u003c/code\u003e\u003c/a\u003e build: verify published subpath contract\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/542829d5b61d31bfe26b805af1167808ed848ba1\"\u003e\u003ccode\u003e542829d\u003c/code\u003e\u003c/a\u003e build: compact emitted ESM syntax\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/94589ee9efe6cf257a133765d753bbe8d55f6ed3\"\u003e\u003ccode\u003e94589ee\u003c/code\u003e\u003c/a\u003e docs: render subpath indexes as tables\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/a778a0b31b94c720818625f762a0cd34def13f99\"\u003e\u003ccode\u003ea778a0b\u003c/code\u003e\u003c/a\u003e test: cover root exports and algorithm facades\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/e01dda65d5d272c8dd44710d0c70673c1530038e\"\u003e\u003ccode\u003ee01dda6\u003c/code\u003e\u003c/a\u003e refactor: model JWE key management modes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/920bc40e5d7c81bfa48e74687e8bed221928ba24\"\u003e\u003ccode\u003e920bc40\u003c/code\u003e\u003c/a\u003e ci: test trigger-ci pushes\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/panva/jose/compare/v6.2.10...v6.2.11\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 8.10.0 to 8.10.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm\"\u003eGHSA-vp8m-p9jh-q5pm\u003c/a\u003e: cache and deduplication interceptors could use caller-controlled request metadata instead of the authoritative dispatcher origin, enabling cross-origin cache poisoning and data disclosure. Undici now derives interceptor identities from the dispatcher origin and bypasses origin-dependent interceptors when no authoritative origin exists. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/caf6194d3dae989b731ed87ab85f182befe5eb80\"\u003ecaf6194d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e8f5868fb\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e66e12816\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6\"\u003e4411a238\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/662d0ea671fe64139e79533c913fce412765e1d7\"\u003e662d0ea6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003ecb75bbb3\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e7aac7f12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003ee905b5b8\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e2be07bf9\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e6d583124\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e0160a719\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps-dev): bump undici from 6.27.0 to 6.28.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5653\"\u003enodejs/undici#5653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump jest from 30.4.2 to 30.5.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5750\"\u003enodejs/undici#5750\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/analyze from 4.37.3 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5752\"\u003enodejs/undici#5752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5754\"\u003enodejs/undici#5754\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(h2): cover stream reset with NGHTTP2_INTERNAL_ERROR by \u003ca href=\"https://github.com/zeexzeex\"\u003e\u003ccode\u003e@​zeexzeex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5725\"\u003enodejs/undici#5725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): reject invalid resumed responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5724\"\u003enodejs/undici#5724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: make stale-while-revalidate cache update test deterministic by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5722\"\u003enodejs/undici#5722\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid unbounded recursion in Set-Cookie attribute parser by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5757\"\u003enodejs/undici#5757\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: honor SOCKS5 connection timeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5733\"\u003enodejs/undici#5733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(eventsource): validate Last-Event-ID on reconnect by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5746\"\u003enodejs/undici#5746\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid duplicate release attempts by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5745\"\u003enodejs/undici#5745\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(cache): refetch when 304 adds vary fields by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5732\"\u003enodejs/undici#5732\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etypes: expose PendingInterceptor and PendingInterceptorsFormatter on the MockAgent namespace by \u003ca href=\"https://github.com/RaphaelFakhri\"\u003e\u003ccode\u003e@​RaphaelFakhri\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5721\"\u003enodejs/undici#5721\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(codeql): align CodeQL action versions to v4.37.9 by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5759\"\u003enodejs/undici#5759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5760\"\u003enodejs/undici#5760\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(proxy-agent): guard Proxy-Authorization in iterable header containers by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5758\"\u003enodejs/undici#5758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: name the parameters these two blocks describe by \u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): fail the connection on a non-200 h2 extended CONNECT response by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(node-fetch): re-enable the set-cookie header combining test by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5730\"\u003enodejs/undici#5730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward rawHeaders writes through RetryController by \u003ca href=\"https://github.com/official-burak\"\u003e\u003ccode\u003e@​official-burak\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5727\"\u003enodejs/undici#5727\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5738\"\u003enodejs/undici#5738\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/5e541e0b9df7563e5766bbd469fbfe383d9ae6ca\"\u003e\u003ccode\u003e5e541e0\u003c/code\u003e\u003c/a\u003e Bumped v8.10.2 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5771\"\u003e#5771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/eb04cc39954e63e9b46bdf824e6efad9fff2e7b5\"\u003e\u003ccode\u003eeb04cc3\u003c/code\u003e\u003c/a\u003e fix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5738\"\u003e#5738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003e\u003ccode\u003ee905b5b\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e\u003ccode\u003e0160a71\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e\u003ccode\u003e66e1281\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e\u003ccode\u003e7aac7f1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003e\u003ccode\u003ecb75bbb\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e\u003ccode\u003e6d58312\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e\u003ccode\u003e8f5868f\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e\u003ccode\u003e2be07bf\u003c/code\u003e\u003c/a\u003e fix(cache): reject unsafe method response caching\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v8.10.0...v8.10.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/DEFRA/epr-frontend/pull/1140","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/DEFRA%2Fepr-frontend/issues/1140","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1140/packages"}},{"old_version":"6.26.0","new_version":"6.28.1","update_type":"minor","path":null,"pr_created_at":"2026-09-11T23:39:07.000Z","version_change":"6.26.0 → 6.28.1","issue":{"uuid":"5429868392","node_id":"PR_kwDOTMBNAc8AAAABDNiawA","number":17,"state":"open","title":"Bump undici from 6.26.0 to 6.28.1","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":7,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T23:39:07.000Z","updated_at":"2026-09-11T23:41:19.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"undici","old_version":"6.26.0","new_version":"6.28.1","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 6.26.0 to 6.28.1.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.28.1\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2af0faf88b906d3127a360c3ac75164c0f95e5a5\"\u003e2af0faf8\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/07c60d9c7099a910451244afe42861bbdbdd974c\"\u003e07c60d9c\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/ce31bc824b578008faae5d3350da66c1b5f71548\"\u003ece31bc82\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eperf: reduce EventSourceStream parser allocations (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5032\"\u003e#5032\u003c/a\u003e) by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5647\"\u003enodejs/undici#5647\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v6.x] perf(h1): drop idle-socket timer floor with a ref'd setImmediate (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5707\"\u003e#5707\u003c/a\u003e) by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5770\"\u003enodejs/undici#5770\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v6.28.0...v6.28.1\"\u003ehttps://github.com/nodejs/undici/compare/v6.28.0...v6.28.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.28.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e740a0b7c\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003ecba3a52a\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e4fd5a0c6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003eaf748404\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e and \u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e affect the cache interceptor in Undici v7 and v8; Undici v6 is not in their affected version ranges.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ehttps://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.27.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e4 security advisories\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 6.27.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^6.27.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on patched version:\u003c/strong\u003e the v6 fixes shipped in \u003cstrong\u003ev6.27.0\u003c/strong\u003e, not \u003ccode\u003e6.26.0\u003c/code\u003e\n— \u003ccode\u003ev6.26.0\u003c/code\u003e contains only the chunked-EOF fix (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5308\"\u003e#5308\u003c/a\u003e) and the version bump, none\nof the security fixes below.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ffc8aa0fdd4c54024f384e57784d5047c8b4085a\"\u003e\u003ccode\u003effc8aa0\u003c/code\u003e\u003c/a\u003e Bumped v6.28.1 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5773\"\u003e#5773\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3866a3bc4ebaea2c6400db9193c2366072080dc4\"\u003e\u003ccode\u003e3866a3b\u003c/code\u003e\u003c/a\u003e perf(h1): drop idle-socket timer floor with a ref'd setImmediate (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5707\"\u003e#5707\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5770\"\u003e#5770\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ce31bc824b578008faae5d3350da66c1b5f71548\"\u003e\u003ccode\u003ece31bc8\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2af0faf88b906d3127a360c3ac75164c0f95e5a5\"\u003e\u003ccode\u003e2af0faf\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/07c60d9c7099a910451244afe42861bbdbdd974c\"\u003e\u003ccode\u003e07c60d9\u003c/code\u003e\u003c/a\u003e fix(websocket): destroy inflater after decompression limit\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/bd90fff2a6e1350ba87e9b70811c5337502d2e39\"\u003e\u003ccode\u003ebd90fff\u003c/code\u003e\u003c/a\u003e perf: reduce EventSourceStream parser allocations (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5032\"\u003e#5032\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5647\"\u003e#5647\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/01a912e49a50c48009ed2639d2a457a6ec26752a\"\u003e\u003ccode\u003e01a912e\u003c/code\u003e\u003c/a\u003e Bumped v6.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5591\"\u003e#5591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/481ecfc3280292ab7eb0abbc4d0139219126f15e\"\u003e\u003ccode\u003e481ecfc\u003c/code\u003e\u003c/a\u003e Use Node 22 and npm 11 to release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e\u003ccode\u003e740a0b7\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2698e492ed22c9ec704b5df573d612bdd03f6ca0\"\u003e\u003ccode\u003e2698e49\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v6.26.0...v6.28.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=6.26.0\u0026new-version=6.28.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Dustin4444/docs-16/network/alerts).\n\n\u003c/details\u003e\n\n\u003c!-- Reviewable:start --\u003e\n- - -\nThis change is [\u003cimg src=\"https://reviewable.io/review_button.svg\" height=\"34\" align=\"absmiddle\" alt=\"Reviewable\"/\u003e](https://reviewable.io/reviews/Dustin4444/docs-16/17)\n\u003c!-- Reviewable:end --\u003e\n","html_url":"https://github.com/Dustin4444/docs-16/pull/17","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Dustin4444%2Fdocs-16/issues/17","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/17/packages"}},{"old_version":"7.24.8","new_version":"7.29.0","update_type":"minor","path":null,"pr_created_at":"2026-09-11T23:33:51.000Z","version_change":"7.24.8 → 7.29.0","issue":{"uuid":"5429843665","node_id":"PR_kwDOR-cqY88AAAABDNhMeg","number":164,"state":"open","title":"chore(deps): bump the npm_and_yarn group across 1 directory with 3 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T23:33:51.000Z","updated_at":"2026-09-11T23:34:24.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":3,"packages":[{"name":"esbuild","old_version":"0.27.3","new_version":"0.28.1","repository_url":"https://github.com/evanw/esbuild"},{"name":"sharp","old_version":"0.34.5","new_version":"0.35.4"},{"name":"undici","old_version":"7.24.8","new_version":"7.29.0"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 1 update in the /workers/pilot-landing directory: [esbuild](https://github.com/evanw/esbuild).\n\nUpdates `esbuild` from 0.27.3 to 0.28.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/evanw/esbuild/releases\"\u003eesbuild's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.28.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eDisallow \u003ccode\u003e\\\u003c/code\u003e in local development server HTTP requests (\u003ca href=\"https://github.com/evanw/esbuild/security/advisories/GHSA-g7r4-m6w7-qqqr\"\u003eGHSA-g7r4-m6w7-qqqr\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a security issue where HTTP requests to esbuild's local development server could traverse outside of the serve directory on Windows using a \u003ccode\u003e\\\u003c/code\u003e backslash character. It happened due to the use of Go's \u003ccode\u003epath.Clean()\u003c/code\u003e function, which only handles Unix-style \u003ccode\u003e/\u003c/code\u003e characters. HTTP requests with paths containing \u003ccode\u003e\\\u003c/code\u003e are no longer allowed.\u003c/p\u003e\n\u003cp\u003eThanks to \u003ca href=\"https://github.com/dellalibera\"\u003e\u003ccode\u003e@​dellalibera\u003c/code\u003e\u003c/a\u003e for reporting this issue.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdd integrity checks to the Deno API (\u003ca href=\"https://github.com/evanw/esbuild/security/advisories/GHSA-gv7w-rqvm-qjhr\"\u003eGHSA-gv7w-rqvm-qjhr\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThe previous release of esbuild added integrity checks to esbuild's npm install script. This release also adds integrity checks to esbuild's Deno install script. Now esbuild's Deno API will also fail with an error if the downloaded esbuild binary contains something other than the expected content.\u003c/p\u003e\n\u003cp\u003eNote that esbuild's Deno API installs from \u003ccode\u003eregistry.npmjs.org\u003c/code\u003e by default, but allows the \u003ccode\u003eNPM_CONFIG_REGISTRY\u003c/code\u003e environment variable to override this with a custom package registry. This change means that the esbuild executable served by \u003ccode\u003eNPM_CONFIG_REGISTRY\u003c/code\u003e must now match the expected content.\u003c/p\u003e\n\u003cp\u003eThanks to \u003ca href=\"https://github.com/sondt99\"\u003e\u003ccode\u003e@​sondt99\u003c/code\u003e\u003c/a\u003e for reporting this issue.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAvoid inlining \u003ccode\u003eusing\u003c/code\u003e and \u003ccode\u003eawait using\u003c/code\u003e declarations (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4482\"\u003e#4482\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003ePreviously esbuild's minifier sometimes incorrectly inlined \u003ccode\u003eusing\u003c/code\u003e and \u003ccode\u003eawait using\u003c/code\u003e declarations into subsequent uses of that declaration, which then fails to dispose of the resource correctly. This bug happened because inlining was done for \u003ccode\u003elet\u003c/code\u003e and \u003ccode\u003econst\u003c/code\u003e declarations by avoiding doing it for \u003ccode\u003evar\u003c/code\u003e declarations, which no longer worked when more declaration types were added. Here's an example:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Original code\r\n{\r\n  using x = new Resource()\r\n  x.activate()\r\n}\r\n\u003cp\u003e// Old output (with --minify)\u003cbr /\u003e\nnew Resource().activate();\u003c/p\u003e\n\u003cp\u003e// New output (with --minify)\u003cbr /\u003e\n{using e=new Resource;e.activate()}\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix module evaluation when an error is thrown (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4461\"\u003e#4461\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/evanw/esbuild/pull/4467\"\u003e#4467\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eIf an error is thrown during module evaluation, esbuild previously didn't preserve the state of the module for subsequent module references. This was observable if \u003ccode\u003eimport()\u003c/code\u003e or \u003ccode\u003erequire()\u003c/code\u003e is used to import a module multiple times. The thrown error is supposed to be thrown by every call to \u003ccode\u003eimport()\u003c/code\u003e or \u003ccode\u003erequire()\u003c/code\u003e, not just the first. With this release, esbuild will now throw the same error every time you call \u003ccode\u003eimport()\u003c/code\u003e or \u003ccode\u003erequire()\u003c/code\u003e on a module that throws during its evaluation.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix some edge cases around the \u003ccode\u003enew\u003c/code\u003e operator (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4477\"\u003e#4477\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003ePreviously esbuild incorrectly printed certain edge cases involving complex expressions inside the target of a \u003ccode\u003enew\u003c/code\u003e expression (specifically an optional chain and/or a tagged template literal). The generated code for the \u003ccode\u003enew\u003c/code\u003e target was not correctly wrapped with parentheses, and either contained a syntax error or had different semantics. These edge cases have been fixed so that they now correctly wrap the \u003ccode\u003enew\u003c/code\u003e target in parentheses. Here is an example of some affected code:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Original code\r\nnew (foo()`bar`)()\r\nnew (foo()?.bar)()\r\n\u003cp\u003e// Old output\u003cbr /\u003e\nnew foo()\u003ccode\u003ebar\u003c/code\u003e();\u003cbr /\u003e\nnew (foo())?.bar();\u003c/p\u003e\n\u003cp\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/evanw/esbuild/blob/main/CHANGELOG.md\"\u003eesbuild's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.28.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eDisallow \u003ccode\u003e\\\u003c/code\u003e in local development server HTTP requests (\u003ca href=\"https://github.com/evanw/esbuild/security/advisories/GHSA-g7r4-m6w7-qqqr\"\u003eGHSA-g7r4-m6w7-qqqr\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThis release fixes a security issue where HTTP requests to esbuild's local development server could traverse outside of the serve directory on Windows using a \u003ccode\u003e\\\u003c/code\u003e backslash character. It happened due to the use of Go's \u003ccode\u003epath.Clean()\u003c/code\u003e function, which only handles Unix-style \u003ccode\u003e/\u003c/code\u003e characters. HTTP requests with paths containing \u003ccode\u003e\\\u003c/code\u003e are no longer allowed.\u003c/p\u003e\n\u003cp\u003eThanks to \u003ca href=\"https://github.com/dellalibera\"\u003e\u003ccode\u003e@​dellalibera\u003c/code\u003e\u003c/a\u003e for reporting this issue.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdd integrity checks to the Deno API (\u003ca href=\"https://github.com/evanw/esbuild/security/advisories/GHSA-gv7w-rqvm-qjhr\"\u003eGHSA-gv7w-rqvm-qjhr\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThe previous release of esbuild added integrity checks to esbuild's npm install script. This release also adds integrity checks to esbuild's Deno install script. Now esbuild's Deno API will also fail with an error if the downloaded esbuild binary contains something other than the expected content.\u003c/p\u003e\n\u003cp\u003eNote that esbuild's Deno API installs from \u003ccode\u003eregistry.npmjs.org\u003c/code\u003e by default, but allows the \u003ccode\u003eNPM_CONFIG_REGISTRY\u003c/code\u003e environment variable to override this with a custom package registry. This change means that the esbuild executable served by \u003ccode\u003eNPM_CONFIG_REGISTRY\u003c/code\u003e must now match the expected content.\u003c/p\u003e\n\u003cp\u003eThanks to \u003ca href=\"https://github.com/sondt99\"\u003e\u003ccode\u003e@​sondt99\u003c/code\u003e\u003c/a\u003e for reporting this issue.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAvoid inlining \u003ccode\u003eusing\u003c/code\u003e and \u003ccode\u003eawait using\u003c/code\u003e declarations (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4482\"\u003e#4482\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003ePreviously esbuild's minifier sometimes incorrectly inlined \u003ccode\u003eusing\u003c/code\u003e and \u003ccode\u003eawait using\u003c/code\u003e declarations into subsequent uses of that declaration, which then fails to dispose of the resource correctly. This bug happened because inlining was done for \u003ccode\u003elet\u003c/code\u003e and \u003ccode\u003econst\u003c/code\u003e declarations by avoiding doing it for \u003ccode\u003evar\u003c/code\u003e declarations, which no longer worked when more declaration types were added. Here's an example:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Original code\n{\n  using x = new Resource()\n  x.activate()\n}\n\u003cp\u003e// Old output (with --minify)\u003cbr /\u003e\nnew Resource().activate();\u003c/p\u003e\n\u003cp\u003e// New output (with --minify)\u003cbr /\u003e\n{using e=new Resource;e.activate()}\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix module evaluation when an error is thrown (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4461\"\u003e#4461\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/evanw/esbuild/pull/4467\"\u003e#4467\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eIf an error is thrown during module evaluation, esbuild previously didn't preserve the state of the module for subsequent module references. This was observable if \u003ccode\u003eimport()\u003c/code\u003e or \u003ccode\u003erequire()\u003c/code\u003e is used to import a module multiple times. The thrown error is supposed to be thrown by every call to \u003ccode\u003eimport()\u003c/code\u003e or \u003ccode\u003erequire()\u003c/code\u003e, not just the first. With this release, esbuild will now throw the same error every time you call \u003ccode\u003eimport()\u003c/code\u003e or \u003ccode\u003erequire()\u003c/code\u003e on a module that throws during its evaluation.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix some edge cases around the \u003ccode\u003enew\u003c/code\u003e operator (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4477\"\u003e#4477\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003ePreviously esbuild incorrectly printed certain edge cases involving complex expressions inside the target of a \u003ccode\u003enew\u003c/code\u003e expression (specifically an optional chain and/or a tagged template literal). The generated code for the \u003ccode\u003enew\u003c/code\u003e target was not correctly wrapped with parentheses, and either contained a syntax error or had different semantics. These edge cases have been fixed so that they now correctly wrap the \u003ccode\u003enew\u003c/code\u003e target in parentheses. Here is an example of some affected code:\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// Original code\nnew (foo()`bar`)()\nnew (foo()?.bar)()\n\u003cp\u003e// Old output\u003cbr /\u003e\nnew foo()\u003ccode\u003ebar\u003c/code\u003e();\u003cbr /\u003e\nnew (foo())?.bar();\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/bb9db84c02433fbe37b3509f53f9f3e3cc48725e\"\u003e\u003ccode\u003ebb9db84\u003c/code\u003e\u003c/a\u003e publish 0.28.1 to npm\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/9ff053e53b8eeb990f59355dbea365277ac45ee2\"\u003e\u003ccode\u003e9ff053e\u003c/code\u003e\u003c/a\u003e security: add integrity checks to the Deno API\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/0a9bf2135b67c7e28989a5ba19f0f000805a5ab5\"\u003e\u003ccode\u003e0a9bf21\u003c/code\u003e\u003c/a\u003e enforce non-negative size in gzip parser\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/e2a1a7132058ee067fe736eac15f695861b8654e\"\u003e\u003ccode\u003ee2a1a71\u003c/code\u003e\u003c/a\u003e security: forbid \u003ccode\u003e\\\\\u003c/code\u003e in local dev server requests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/83a2cbfc35809f4fd5152da59572d7bed7739d78\"\u003e\u003ccode\u003e83a2cbf\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4482\"\u003e#4482\u003c/a\u003e: don't inline \u003ccode\u003eusing\u003c/code\u003e declarations\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/308ad745d824c77bc607603451b257d0f2fd9a38\"\u003e\u003ccode\u003e308ad74\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4471\"\u003e#4471\u003c/a\u003e: renaming of nested \u003ccode\u003evar\u003c/code\u003e declarations\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/f013f5f99a015bce92ec48d49181d4ad3177b29b\"\u003e\u003ccode\u003ef013f5f\u003c/code\u003e\u003c/a\u003e fix some typos\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/aafd6e48b1088336a5f5a17e930be7e840d43d8c\"\u003e\u003ccode\u003eaafd6e4\u003c/code\u003e\u003c/a\u003e chore: fix some minor issues in comments (\u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4462\"\u003e#4462\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/15300c30b5e22f7cfcbed850c246d35095658386\"\u003e\u003ccode\u003e15300c3\u003c/code\u003e\u003c/a\u003e follow up: cjs evaluation fixes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/evanw/esbuild/commit/1bda0c31d7697c0af44b3ab39b81e599e559a395\"\u003e\u003ccode\u003e1bda0c3\u003c/code\u003e\u003c/a\u003e fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4461\"\u003e#4461\u003c/a\u003e, fix \u003ca href=\"https://redirect.github.com/evanw/esbuild/issues/4467\"\u003e#4467\u003c/a\u003e: esm evaluation fixes\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/evanw/esbuild/compare/v0.27.3...v0.28.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `sharp` from 0.34.5 to 0.35.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lovell/sharp/releases\"\u003esharp's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.35.4\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\"\u003ehttps://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.35.4-rc.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpgrade to libvips v8.18.6 for upstream bug fixes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7f1a0a22cc285fe180766f4935d50b55af6e8432\"\u003e\u003ccode\u003e7f1a0a2\u003c/code\u003e\u003c/a\u003e Release v0.35.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/f927818924bc5a9493d822a4e8b23ec5857c52e1\"\u003e\u003ccode\u003ef927818\u003c/code\u003e\u003c/a\u003e Upgrade to sharp-libvips v1.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e80209240d005c71e1173a50dd9cd4db4ce2a9e6\"\u003e\u003ccode\u003ee802092\u003c/code\u003e\u003c/a\u003e Prerelease v0.35.4-rc.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e13eb2f97a0a22f1ef726e8d0cd33f7c56835945\"\u003e\u003ccode\u003ee13eb2f\u003c/code\u003e\u003c/a\u003e CI: Fix wasm32 build (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4589\"\u003e#4589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/a82a0b3d58bc25854ad1e925e6eb0a50725d1489\"\u003e\u003ccode\u003ea82a0b3\u003c/code\u003e\u003c/a\u003e Upgrade to libvips v8.18.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/8044fe43e36d0ea7f8beb89f79a37bb0f3342e84\"\u003e\u003ccode\u003e8044fe4\u003c/code\u003e\u003c/a\u003e Bound resize dimensions to coordinate limit\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/147f8591a153bc4a1e199c3fe3150fac2931b30c\"\u003e\u003ccode\u003e147f859\u003c/code\u003e\u003c/a\u003e Docs: changelog entries for \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4578\"\u003e#4578\u003c/a\u003e \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ee5bfb853de75a611c64381783b04032a3a897d8\"\u003e\u003ccode\u003eee5bfb8\u003c/code\u003e\u003c/a\u003e Tests: use yauzl directly rather than via extract-zip wrapper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7a7788928f8a2a429f45039010a87cee35401694\"\u003e\u003ccode\u003e7a77889\u003c/code\u003e\u003c/a\u003e Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4588\"\u003e#4588\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ea5bef24c187b2c7ee3fe3cad3b45c8cb67a46fd\"\u003e\u003ccode\u003eea5bef2\u003c/code\u003e\u003c/a\u003e Improve support for input Streams finishing before output is requested (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/lovell/sharp/compare/v0.34.5...v0.35.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.24.8 to 7.29.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.28.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e7 security advisories\u003c/strong\u003e, all shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 7.28.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^7.28.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe v7 line is \u003cstrong\u003enot\u003c/strong\u003e affected by GHSA-38rv-x7px-6hhq (CVE-2026-9675), which is\nan 8.x-only regression.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on GHSA-hm92-r4w5-c3mj:\u003c/strong\u003e this fix shipped in \u003cstrong\u003ev7.28.0\u003c/strong\u003e, not the\nearlier 7.2x line — the vulnerable single-pool code was still present through\n\u003ccode\u003ev7.27.2\u003c/code\u003e. The per-origin pool fix is\n\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5041\"\u003e#5041\u003c/a\u003e).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAdvisory\u003c/th\u003e\n\u003cth\u003eCVE\u003c/th\u003e\n\u003cth\u003eSeverity (CVSS)\u003c/th\u003e\n\u003cth\u003eFixed in\u003c/th\u003e\n\u003cth\u003eFix commit\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-12151\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8cb10f98\"\u003e\u003ccode\u003e8cb10f98\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g\"\u003eGHSA-vmh5-mc38-953g\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9697\u003c/td\u003e\n\u003ctd\u003eHigh (7.4)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/04201f89\"\u003e\u003ccode\u003e04201f89\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj\"\u003eGHSA-hm92-r4w5-c3mj\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6734\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3805b8f8\"\u003e\u003ccode\u003e3805b8f8\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6\"\u003eGHSA-pr7r-676h-xcf6\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9678\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/85a24055\"\u003e\u003ccode\u003e85a24055\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv\"\u003eGHSA-p88m-4jfj-68fv\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9679\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m\"\u003eGHSA-g8m3-5g58-fq7m\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-11525\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d0574cc4\"\u003e\u003ccode\u003ed0574cc4\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52\"\u003eGHSA-35p6-xmwp-9g52\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6733\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e7.28.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/ea8930cf\"\u003e\u003ccode\u003eea8930cf\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f9eba0ad9134e1c0977848476bba9d49734696e4\"\u003e\u003ccode\u003ef9eba0a\u003c/code\u003e\u003c/a\u003e Bumped v7.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5430\"\u003e#5430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.24.8...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Medal-Social/Pilot/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Medal-Social/pilot/pull/164","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Medal-Social%2Fpilot/issues/164","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/164/packages"}},{"old_version":"7.28.0","new_version":"7.29.1","update_type":"minor","path":null,"pr_created_at":"2026-09-11T18:25:56.000Z","version_change":"7.28.0 → 7.29.1","issue":{"uuid":"5427702766","node_id":"PR_kwDORH_RdM8AAAABDL0acw","number":103,"state":"closed","title":"chore(deps): bump the npm_and_yarn group across 2 directories with 10 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":"2026-09-11T18:29:01.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-11T18:25:56.000Z","updated_at":"2026-09-11T18:32:39.000Z","time_to_close":185,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":10,"packages":[{"name":"nodemailer","old_version":"9.0.3","new_version":"9.1.1","repository_url":"https://github.com/nodemailer/nodemailer"},{"name":"typeorm","old_version":"0.3.30","new_version":"0.3.31","repository_url":"https://github.com/typeorm/typeorm"},{"name":"next","old_version":"16.2.9","new_version":"16.3.5"},{"name":"postcss","old_version":"8.5.16","new_version":"8.5.28"},{"name":"undici","old_version":"7.28.0","new_version":"7.29.1","repository_url":"https://github.com/nodejs/undici"},{"name":"browserslist","old_version":"4.28.4","new_version":"4.28.9"},{"name":"form-data","old_version":"4.0.5","new_version":"4.0.6"},{"name":"js-yaml","old_version":"3.14.2","new_version":"3.15.2"},{"name":"nanoid","old_version":"3.3.15","new_version":"3.3.19"},{"name":"sharp","old_version":"0.34.5","new_version":"0.35.4"},{"name":"nodemailer","old_version":"9.0.3","new_version":"9.1.1","repository_url":"https://github.com/nodemailer/nodemailer"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 2 updates in the / directory: [nodemailer](https://github.com/nodemailer/nodemailer) and [typeorm](https://github.com/typeorm/typeorm).\nBumps the npm_and_yarn group with 2 updates in the /backend directory: [typeorm](https://github.com/typeorm/typeorm) and [undici](https://github.com/nodejs/undici).\n\nUpdates `nodemailer` from 9.0.3 to 9.1.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodemailer/nodemailer/releases\"\u003enodemailer's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev9.1.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.1.0...v9.1.1\"\u003e9.1.1\u003c/a\u003e (2026-09-01)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e apply the message access policy in resolveContent (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/dc48ed395c4d6c79ee5c95eb6eff17bafe391474\"\u003edc48ed3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e keep message data from reopening the access sandbox (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/ab7ef348b9a97b1fd70e7bfbeb56d4ea4a07946b\"\u003eab7ef34\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e inherit the access policy from the tree a node hangs in (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/262d550b1e121e3ff4ef6675d6771a5b2b4ddcec\"\u003e262d550\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev9.1.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.0.6...v9.1.0\"\u003e9.1.0\u003c/a\u003e (2026-08-31)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e cap recipients per message with maxRecipients (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/7279ac8dee4f66c032981e6e51e3e7210ad0dcbf\"\u003e7279ac8\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eaddressparser:\u003c/strong\u003e handle address lists in linear time (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/9116da9528c6524cefaed75185602a7e85d20434\"\u003e9116da9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eaddressparser:\u003c/strong\u003e terminate the domain at an RFC 5322 comment (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/902b63e935435c30f4025901c0902dce64cd8880\"\u003e902b63e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e apply UTS-46 mapping when encoding a domain (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/259c32d7d266301e3377a212776c3fff993c0148\"\u003e259c32d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e dedupe envelope recipients in linear time (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/7cc38af418ffa6fc7e86085195ca5ca681694b3e\"\u003e7cc38af\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e flatten parsed addresses without concat.apply (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/83b8c48cbdb8b3116f2e1ba84af755b2c5661c0f\"\u003e83b8c48\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e keep the recipient dedupe linear across address headers (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/34da64282dcdc9b0581c721a27ab2fa226673150\"\u003e34da642\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e keep URL delimiters away from the domain mapper (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/b212ac4e27bce8182478044fcb8d1642ccdad46e\"\u003eb212ac4\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev9.0.6\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.0.5...v9.0.6\"\u003e9.0.6\u003c/a\u003e (2026-08-27)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eaddressparser:\u003c/strong\u003e recover the addr-spec from an angle-addr holding whitespace (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/e989a22ca4f5161929bf37be8fb07de635016fa7\"\u003ee989a22\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eharden copies of user supplied keys and URL fetching (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/2f667f4272cb2d7cb479b2e3903ab10600fc0eae\"\u003e2f667f4\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev9.0.5\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.0.4...v9.0.5\"\u003e9.0.5\u003c/a\u003e (2026-08-07)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eci:\u003c/strong\u003e retrigger the workflows dropped during the Actions outage (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/85d16c103ec69e237c7e55c0e3103f439c135ce3\"\u003e85d16c1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e escape specials in List-* header comments (\u003ca href=\"https://redirect.github.com/nodemailer/nodemailer/issues/1842\"\u003e#1842\u003c/a\u003e) (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/75913bba032623046dd7fa037b8b880e388d8357\"\u003e75913bb\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-funcs:\u003c/strong\u003e star the continuation key of a restarted parameter line (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/36bcf1a21a92b5a283c780e35aacd3080292d98d\"\u003e36bcf1a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e keep control chars out of header values and msg-id headers (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/15cf6d1c15cdf60f551618fd54fb727ea7aac94c\"\u003e15cf6d1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime:\u003c/strong\u003e encode DEL in header parameters and List-* comments (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/cf69430ffac1d246bfbab564daf321f31ed9e1dd\"\u003ecf69430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime:\u003c/strong\u003e keep control chars out of the remaining header positions (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/5ed9d26f85eecb48f4b3ae74ad33ed2abf002040\"\u003e5ed9d26\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodemailer/nodemailer/blob/master/CHANGELOG.md\"\u003enodemailer's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.1.0...v9.1.1\"\u003e9.1.1\u003c/a\u003e (2026-09-01)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e apply the message access policy in resolveContent (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/dc48ed395c4d6c79ee5c95eb6eff17bafe391474\"\u003edc48ed3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e keep message data from reopening the access sandbox (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/ab7ef348b9a97b1fd70e7bfbeb56d4ea4a07946b\"\u003eab7ef34\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e inherit the access policy from the tree a node hangs in (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/262d550b1e121e3ff4ef6675d6771a5b2b4ddcec\"\u003e262d550\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.0.6...v9.1.0\"\u003e9.1.0\u003c/a\u003e (2026-08-31)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e cap recipients per message with maxRecipients (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/7279ac8dee4f66c032981e6e51e3e7210ad0dcbf\"\u003e7279ac8\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eaddressparser:\u003c/strong\u003e handle address lists in linear time (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/9116da9528c6524cefaed75185602a7e85d20434\"\u003e9116da9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eaddressparser:\u003c/strong\u003e terminate the domain at an RFC 5322 comment (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/902b63e935435c30f4025901c0902dce64cd8880\"\u003e902b63e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e apply UTS-46 mapping when encoding a domain (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/259c32d7d266301e3377a212776c3fff993c0148\"\u003e259c32d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e dedupe envelope recipients in linear time (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/7cc38af418ffa6fc7e86085195ca5ca681694b3e\"\u003e7cc38af\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e flatten parsed addresses without concat.apply (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/83b8c48cbdb8b3116f2e1ba84af755b2c5661c0f\"\u003e83b8c48\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e keep the recipient dedupe linear across address headers (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/34da64282dcdc9b0581c721a27ab2fa226673150\"\u003e34da642\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e keep URL delimiters away from the domain mapper (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/b212ac4e27bce8182478044fcb8d1642ccdad46e\"\u003eb212ac4\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.0.5...v9.0.6\"\u003e9.0.6\u003c/a\u003e (2026-08-27)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eaddressparser:\u003c/strong\u003e recover the addr-spec from an angle-addr holding whitespace (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/e989a22ca4f5161929bf37be8fb07de635016fa7\"\u003ee989a22\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eharden copies of user supplied keys and URL fetching (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/2f667f4272cb2d7cb479b2e3903ab10600fc0eae\"\u003e2f667f4\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.0.4...v9.0.5\"\u003e9.0.5\u003c/a\u003e (2026-08-07)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eci:\u003c/strong\u003e retrigger the workflows dropped during the Actions outage (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/85d16c103ec69e237c7e55c0e3103f439c135ce3\"\u003e85d16c1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e escape specials in List-* header comments (\u003ca href=\"https://redirect.github.com/nodemailer/nodemailer/issues/1842\"\u003e#1842\u003c/a\u003e) (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/75913bba032623046dd7fa037b8b880e388d8357\"\u003e75913bb\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-funcs:\u003c/strong\u003e star the continuation key of a restarted parameter line (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/36bcf1a21a92b5a283c780e35aacd3080292d98d\"\u003e36bcf1a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e keep control chars out of header values and msg-id headers (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/15cf6d1c15cdf60f551618fd54fb727ea7aac94c\"\u003e15cf6d1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime:\u003c/strong\u003e encode DEL in header parameters and List-* comments (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/cf69430ffac1d246bfbab564daf321f31ed9e1dd\"\u003ecf69430\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime:\u003c/strong\u003e keep control chars out of the remaining header positions (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/5ed9d26f85eecb48f4b3ae74ad33ed2abf002040\"\u003e5ed9d26\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime:\u003c/strong\u003e normalize an address parsed out of a string as well (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/63685f7dd4aefa75cc72a36f983f32f61cd6733e\"\u003e63685f7\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime:\u003c/strong\u003e normalize an address so header and envelope agree (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/a9343b47e42b9ccb27911ad8e73d4119c6170c85\"\u003ea9343b4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime:\u003c/strong\u003e stop a header key callback and the dkim tags from injecting (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/b7d772ea4ec12ee82e65a9b919af882bf0f125d9\"\u003eb7d772e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/ad4513f2a179e0484f9c95948211c186ba3ce7c9\"\u003e\u003ccode\u003ead4513f\u003c/code\u003e\u003c/a\u003e chore(master): release 9.1.1 (\u003ca href=\"https://redirect.github.com/nodemailer/nodemailer/issues/1850\"\u003e#1850\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/c3e261f2a3c032f582ec2f76a19d468f42ef2fcc\"\u003e\u003ccode\u003ec3e261f\u003c/code\u003e\u003c/a\u003e docs: replace dead Node.js c-ares dependencies link (\u003ca href=\"https://redirect.github.com/nodemailer/nodemailer/issues/1845\"\u003e#1845\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/c158a388739b61baa6570fb4a3e70bd65d6d2a5f\"\u003e\u003ccode\u003ec158a38\u003c/code\u003e\u003c/a\u003e docs: mark 9.x as the supported security line (\u003ca href=\"https://redirect.github.com/nodemailer/nodemailer/issues/1846\"\u003e#1846\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/262d550b1e121e3ff4ef6675d6771a5b2b4ddcec\"\u003e\u003ccode\u003e262d550\u003c/code\u003e\u003c/a\u003e fix(mime-node): inherit the access policy from the tree a node hangs in\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/ab7ef348b9a97b1fd70e7bfbeb56d4ea4a07946b\"\u003e\u003ccode\u003eab7ef34\u003c/code\u003e\u003c/a\u003e fix(mailer): keep message data from reopening the access sandbox\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/dc48ed395c4d6c79ee5c95eb6eff17bafe391474\"\u003e\u003ccode\u003edc48ed3\u003c/code\u003e\u003c/a\u003e fix(mailer): apply the message access policy in resolveContent\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/efd6e29c10c6e0c25c57bd2f2a71302838235a4f\"\u003e\u003ccode\u003eefd6e29\u003c/code\u003e\u003c/a\u003e chore(master): release 9.1.0 (\u003ca href=\"https://redirect.github.com/nodemailer/nodemailer/issues/1849\"\u003e#1849\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/1f9533b33eafec5c38b0fc2a2e7338b950d9fe77\"\u003e\u003ccode\u003e1f9533b\u003c/code\u003e\u003c/a\u003e chore(deps): update dev dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/b212ac4e27bce8182478044fcb8d1642ccdad46e\"\u003e\u003ccode\u003eb212ac4\u003c/code\u003e\u003c/a\u003e fix(mime-node): keep URL delimiters away from the domain mapper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/6aa7e3fc5cfa587ae8694048afccdb5f1e3d2a43\"\u003e\u003ccode\u003e6aa7e3f\u003c/code\u003e\u003c/a\u003e refactor: fold review findings into the address parsing changes\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.0.3...v9.1.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `typeorm` from 0.3.30 to 0.3.31\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/typeorm/typeorm/releases\"\u003etypeorm's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.3.31\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ecache:\u003c/strong\u003e release query runner on error in storeInCache (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12545\"\u003e#12545\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/a84b9b3d39c44cc0e5809b4680a5f046bda602cd\"\u003ea84b9b3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ecorrect grammar in AlreadyHasActiveConnectionError message (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12554\"\u003e#12554\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/304d1290a4b6bd47d7d38269bae6a8514f378c9c\"\u003e304d129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eentity-manager:\u003c/strong\u003e default invalidWhereValuesBehavior to throw on the write path (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12690\"\u003e#12690\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/44d8052ba4d226364c26e722826340d4ceb1419b\"\u003e44d8052\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eentity-manager:\u003c/strong\u003e validate where criteria in increment/decrement (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12692\"\u003e#12692\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/8a51b756bf31c885da1e1d92cb17d94819c7040a\"\u003e8a51b75\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emongodb:\u003c/strong\u003e use cursor.transform for doc to entity transformation and skip load broadcast in next if toArray (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/11926\"\u003e#11926\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/0bbefc914ef69b3826a4a2075b0b008c9a02e807\"\u003e0bbefc9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003emove hashing function to PlatformTools (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12648\"\u003e#12648\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/c456cbd5d40aa2e797314bd202956449f64efbac\"\u003ec456cbd\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003emultiple recursive cte problems (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12490\"\u003e#12490\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/7c26654f430a7190c331242d68e75111fb334ea3\"\u003e7c26654\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enormalization of FindOptionsWhere for arrays and Buffers (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12577\"\u003e#12577\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/a8173fcdf325c44bf3eb2101c6318b45c573102b\"\u003ea8173fc\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003epersistence:\u003c/strong\u003e preserve select false columns on the in-memory entity after save() (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12501\"\u003e#12501\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/324c46cd8669270dd5f22173cd78a7cab591349c\"\u003e324c46c\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003epostgres:\u003c/strong\u003e improve normalizeDatetimeFunction for tstzrange data type (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12182\"\u003e#12182\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/bf47c9f1171b15523292e8914cfbdcfee542ef07\"\u003ebf47c9f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003equery-builder:\u003c/strong\u003e reject empty where criteria on update and delete operations (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12629\"\u003e#12629\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/81b946625d84bcf3ce720fea7d406003270169ee\"\u003e81b9466\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003equery-builder:\u003c/strong\u003e wrap inner joins under left joins correctly (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/11137\"\u003e#11137\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/d5f4b9d7e0f0aca63a9dd66e7ae26a15f7e8eee0\"\u003ed5f4b9d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eremove \u003ccode\u003erequire()\u003c/code\u003e calls that break bundlers (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12647\"\u003e#12647\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/30f9fc717bcfaa472d56680437105a6b9581014d\"\u003e30f9fc7\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etree-entity:\u003c/strong\u003e tree entity schema propagation in internal TreeRepository methods (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12590\"\u003e#12590\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/7fb7c2c7c30d57489921eed458dfb97a5d08d4b8\"\u003e7fb7c2c\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/typeorm/typeorm/compare/0.3.30...0.3.31\"\u003ehttps://github.com/typeorm/typeorm/compare/0.3.30...0.3.31\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/typeorm/typeorm/blob/0.3.31/CHANGELOG.md\"\u003etypeorm's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/typeorm/typeorm/compare/0.3.30...0.3.31\"\u003e0.3.31\u003c/a\u003e (2026-07-13)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003edocs:\u003c/strong\u003e correct project name in release flow (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12519\"\u003e#12519\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/3b9faa31ced080db2073cd92c42905dd402fa636\"\u003e3b9faa3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edocs:\u003c/strong\u003e resolve docs workflow issues (\u003ca href=\"https://github.com/typeorm/typeorm/commit/c3c09b043f68ad4b19cc7b02bbeb85e2f720305c\"\u003ec3c09b0\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edocs:\u003c/strong\u003e resolve docs workflow issues (\u003ca href=\"https://github.com/typeorm/typeorm/commit/f7b4b634647bd1a3e340fa421760183ebfb867be\"\u003ef7b4b63\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eentity-manager:\u003c/strong\u003e validate where criteria in increment/decrement (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12692\"\u003e#12692\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/a69a8c6816a493461f043c3bce8364a51fbf91ce\"\u003ea69a8c6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emigration:\u003c/strong\u003e escape backslashes and interpolation in generated template literals (\u003ca href=\"https://github.com/typeorm/typeorm/commit/b175f9b8be422edd2a2ac035ba90c3f2ce782dfe\"\u003eb175f9b\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enormalization of FindOptionsWhere for arrays and Buffers (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12577\"\u003e#12577\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/a309182c4495c8606dea96ed71ab3f2236663d64\"\u003ea309182\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003epersistence:\u003c/strong\u003e preserve select false columns on the in-memory entity after save() (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12501\"\u003e#12501\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/d8e91274662b85effbf6c79ff5d7379970839d27\"\u003ed8e9127\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003equery-builder:\u003c/strong\u003e reject empty where criteria on update and delete operations (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12629\"\u003e#12629\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/dfd972b80b9c79f4df429cd4a3cf171481928874\"\u003edfd972b\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etree-entity:\u003c/strong\u003e tree entity schema propagation in internal TreeRepository methods (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12590\"\u003e#12590\u003c/a\u003e) (\u003ca href=\"https://github.com/typeorm/typeorm/commit/e1f93da606576660b7e907c9f8d90520394ed495\"\u003ee1f93da\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typeorm/typeorm/commit/797320375fb83b2e9af4a6455e0b1b4483be329d\"\u003e\u003ccode\u003e7973203\u003c/code\u003e\u003c/a\u003e ci: publish to npm from \u003ccode\u003ev0\u003c/code\u003e using the \u003ccode\u003elegacy\u003c/code\u003e tag\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typeorm/typeorm/commit/92e92767e3b9567bb97ca7552c752e8a57c15518\"\u003e\u003ccode\u003e92e9276\u003c/code\u003e\u003c/a\u003e ci: use \u003ccode\u003enpm@11\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typeorm/typeorm/commit/099c23ef51caf86407a06c7292881316337d7db3\"\u003e\u003ccode\u003e099c23e\u003c/code\u003e\u003c/a\u003e chore: prepare release 0.3.31 (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12676\"\u003e#12676\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typeorm/typeorm/commit/b175f9b8be422edd2a2ac035ba90c3f2ce782dfe\"\u003e\u003ccode\u003eb175f9b\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typeorm/typeorm/commit/a69a8c6816a493461f043c3bce8364a51fbf91ce\"\u003e\u003ccode\u003ea69a8c6\u003c/code\u003e\u003c/a\u003e fix(entity-manager): validate where criteria in increment/decrement (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12692\"\u003e#12692\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typeorm/typeorm/commit/dfd972b80b9c79f4df429cd4a3cf171481928874\"\u003e\u003ccode\u003edfd972b\u003c/code\u003e\u003c/a\u003e fix(query-builder): reject empty where criteria on update and delete operatio...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typeorm/typeorm/commit/a2d43639fdd762192a4d25716b6750a5618dfaf0\"\u003e\u003ccode\u003ea2d4363\u003c/code\u003e\u003c/a\u003e chore: update deps (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12661\"\u003e#12661\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typeorm/typeorm/commit/e1f93da606576660b7e907c9f8d90520394ed495\"\u003e\u003ccode\u003ee1f93da\u003c/code\u003e\u003c/a\u003e fix(tree-entity): tree entity schema propagation in internal TreeRepository m...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typeorm/typeorm/commit/a309182c4495c8606dea96ed71ab3f2236663d64\"\u003e\u003ccode\u003ea309182\u003c/code\u003e\u003c/a\u003e fix: normalization of FindOptionsWhere for arrays and Buffers (\u003ca href=\"https://redirect.github.com/typeorm/typeorm/issues/12577\"\u003e#12577\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typeorm/typeorm/commit/d8e91274662b85effbf6c79ff5d7379970839d27\"\u003e\u003ccode\u003ed8e9127\u003c/code\u003e\u003c/a\u003e fix(persistence): preserve select false columns on the in-memory entity after...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/typeorm/typeorm/compare/0.3.30...0.3.31\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `next` from 16.2.9 to 16.3.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003enext's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.4\u003c/h2\u003e\n\u003cp\u003eFollow-up release to \u003ca href=\"https://github.com/vercel/next.js/releases/tag/v16.3.3\"\u003ev16.3.3\u003c/a\u003e re-enabling AVIF Image Optimization (\u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97949\"\u003e#97949\u003c/a\u003e).\u003c/p\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003etestmode: Fix infinite recursion in testmode passthrough fetch (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97691\"\u003e#97691\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix build error when aliasing typescript to \u003ccode\u003e@​typescript/typescript6\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97997\"\u003e#97997\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix unset crossOrigin in Turbopack manifests (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97930\"\u003e#97930\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.3\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eCritical:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36\"\u003eUnauthenticated Remote Code Execution on windows-hosted servers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4\"\u003eUnauthenticated Remote Code Execution in Image Optimization API when AVIF files are used\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.2\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Scope app-entry export validation to files inside the app directory (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97357\"\u003e#97357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[backport] Fix catch-all index page being served for every other slug (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97416\"\u003e#97416\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: don't trace embedded WASM loader helpers (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97353\"\u003e#97353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97463\"\u003e#97463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: retain conditions when replacing resolve request keys (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97453\"\u003e#97453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Fix Turbopack worker chunk loading with asset prefix (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97419\"\u003e#97419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97603\"\u003e#97603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/lubieowoce\"\u003e\u003ccode\u003e@​lubieowoce\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[16.x] Turbopack: don't strip async-module runtime from shared runtime chunks by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96653\"\u003evercel/next.js#96653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] [turbopack] Add \u003ccode\u003eturbopack_ecmascript\u003c/code\u003e and \u003ccode\u003eturbopack_wasm\u003c/code\u003e's embeded FS to \u003ccode\u003einternal_assets_conditions\u003c/code\u003e by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96655\"\u003evercel/next.js#96655\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] [turbopack] Collapse nested promises in the analyzer by \u003ca href=\"https://github.com/sampoder\"\u003e\u003ccode\u003e@​sampoder\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96675\"\u003evercel/next.js#96675\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] fix(next/image): preserve image response after optimization by \u003ca href=\"https://github.com/styfle\"\u003e\u003ccode\u003e@​styfle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96733\"\u003evercel/next.js#96733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.3.x] Default deploy e2e tests to the repo next version by \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96900\"\u003evercel/next.js#96900\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Bump \u003ccode\u003e@​swc/helpers\u003c/code\u003e by \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96885\"\u003evercel/next.js#96885\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [turbopack] Raise registration calls in hoisted modules to the top by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97308\"\u003evercel/next.js#97308\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Fix missing styled-jsx styles in Pages Router SSR on adapter builds by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97302\"\u003evercel/next.js#97302\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [turbopack] Fix HMR for dynamic imports evaluated from layouts by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97317\"\u003evercel/next.js#97317\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Restore the live \u003ccode\u003eheaders()\u003c/code\u003e view of the incoming request by \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97311\"\u003evercel/next.js#97311\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/ca2c75eb7f8d9dd012a8bb83c06132149fe221f9\"\u003e\u003ccode\u003eca2c75e\u003c/code\u003e\u003c/a\u003e v16.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/14fb290de65077e9f1e22ef56d8de6cc1e63d436\"\u003e\u003ccode\u003e14fb290\u003c/code\u003e\u003c/a\u003e [backport] Fix use cache prerender signal retention (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98448\"\u003e#98448\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/2b1f28dbe1de344807ec0946a85171bc890a6047\"\u003e\u003ccode\u003e2b1f28d\u003c/code\u003e\u003c/a\u003e [16.3.x] Add CSP nonce to script tags of loading and template files (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98403\"\u003e#98403\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/4b56cee3f01d3b249edcd798b51895d5126a4170\"\u003e\u003ccode\u003e4b56cee\u003c/code\u003e\u003c/a\u003e [16.3.x] Backport docs fixes (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98317\"\u003e#98317\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/5568a02a7d47f9cb088e58350f2c2e68d9e93a00\"\u003e\u003ccode\u003e5568a02\u003c/code\u003e\u003c/a\u003e [backport] docs: local development: Rewrite docker section, add Windows Dev D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/93249ab2144132abfd4a8d611dad5b5978107ee2\"\u003e\u003ccode\u003e93249ab\u003c/code\u003e\u003c/a\u003e [16.3.X] Emit whole-app server NFTs when \u003ccode\u003eoutput: 'standalone'\u003c/code\u003e is used with ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/6549fd7c4e15a8883b0ad1c2ef67dec287a44f12\"\u003e\u003ccode\u003e6549fd7\u003c/code\u003e\u003c/a\u003e [16.3.x] next/image: reject empty image on read/write to disk cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98186\"\u003e#98186\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/d9eac96e7526ff0b9cb51db9801f06e741fe1960\"\u003e\u003ccode\u003ed9eac96\u003c/code\u003e\u003c/a\u003e [16.3.x] next/image: skip 0-byte entries when initializing disk LRU cache (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/9\"\u003e#9\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/84b35feccb2b53a563e41ad2dfe7a5fe08c58d3f\"\u003e\u003ccode\u003e84b35fe\u003c/code\u003e\u003c/a\u003e [test] Fix 16.3 deploy test assertions (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/98133\"\u003e#98133\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/14f9c1ac4e084a44633c354476ddeaf70969cd90\"\u003e\u003ccode\u003e14f9c1a\u003c/code\u003e\u003c/a\u003e [16.3.x][ci] Run flake detection and new deploy tests when merged and on back...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/compare/v16.2.9...v16.3.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.16 to 8.5.28\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.28\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes types regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed removing any comments starting with \u003ccode\u003e/*#\u003c/code\u003e (by \u003ca href=\"https://github.com/dylanpulver\"\u003e\u003ccode\u003e@​dylanpulver\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e*\u003c/code\u003e hack before a comment in Custom Properties (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed empty values in the middle of \u003ccode\u003elist.comma()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed whitespace-only values in \u003ccode\u003elist.space()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed rule’s end position on space before semicolon (by \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/romainmenke\"\u003e\u003ccode\u003e@​romainmenke\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed Chinese text in deprecation warning (by \u003ca href=\"https://github.com/Jesse205\"\u003e\u003ccode\u003e@​Jesse205\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.28\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes types regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed removing any comments starting with \u003ccode\u003e/*#\u003c/code\u003e (by \u003ca href=\"https://github.com/dylanpulver\"\u003e\u003ccode\u003e@​dylanpulver\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e*\u003c/code\u003e hack before a comment in Custom Properties (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed empty values in the middle of \u003ccode\u003elist.comma()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed whitespace-only values in \u003ccode\u003elist.space()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed rule’s end position on space before semicolon (by \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/romainmenke\"\u003e\u003ccode\u003e@​romainmenke\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed Chinese text in deprecation warning (by \u003ca href=\"https://github.com/Jesse205\"\u003e\u003ccode\u003e@​Jesse205\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/e544bffc4f4b3966d8ec69c41744b3ed65afc64a\"\u003e\u003ccode\u003ee544bff\u003c/code\u003e\u003c/a\u003e Release 8.5.28 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f8fc2525717a6a7216659f7be43c525f60c6a15a\"\u003e\u003ccode\u003ef8fc252\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/5039fd78962d285abea5d7b3aebef32f053781ce\"\u003e\u003ccode\u003e5039fd7\u003c/code\u003e\u003c/a\u003e Add missed release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/ae40ca499cf6a9afdbb264c0ec09e71fe934e2af\"\u003e\u003ccode\u003eae40ca4\u003c/code\u003e\u003c/a\u003e Release 8.5.27 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/62b1626bb7fbb28eda616d002cbd525d239b18ba\"\u003e\u003ccode\u003e62b1626\u003c/code\u003e\u003c/a\u003e Fix linter\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/1dba9384515a2dbc64517697c2f738b6d5c3f9a4\"\u003e\u003ccode\u003e1dba938\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3e82edc9f037faa41647342dceceba9b841f9881\"\u003e\u003ccode\u003e3e82edc\u003c/code\u003e\u003c/a\u003e Keep non-annotation comments when the processor has no plugins (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2150\"\u003e#2150\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/6d23bc362203118478bc8051b81f2910907ebe6e\"\u003e\u003ccode\u003e6d23bc3\u003c/code\u003e\u003c/a\u003e Fix link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/508e9976be81536292e7666741e1c35e876b9a6a\"\u003e\u003ccode\u003e508e997\u003c/code\u003e\u003c/a\u003e Add GitHub Sponsors link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/e993739dc49b6055f7dfc59b161d75702f0b2b8b\"\u003e\u003ccode\u003ee993739\u003c/code\u003e\u003c/a\u003e Add CodeRabbit sponsor (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2145\"\u003e#2145\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.16...8.5.28\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 7.28.0 to 7.29.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ehttps://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9e38fc121d2eb26086d41c7d9379b47a6fada1c5\"\u003e\u003ccode\u003e9e38fc1\u003c/code\u003e\u003c/a\u003e Bumped v7.29.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5590\"\u003e#5590\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d887e3433a939422c8858aa3892e2e478316a7d1\"\u003e\u003ccode\u003ed887e34\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e\u003ccode\u003e33928bc\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e\u003ccode\u003e98011a8\u003c/code\u003e\u003c/a\u003e fix(cache): harden cache directive parsing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e\u003ccode\u003e4a9dafb\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e\u003ccode\u003e1b5a531\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e\u003ccode\u003e466e99d\u003c/code\u003e\u003c/a\u003e test: cover crash on mixed unqualified and qualified private cache directives\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e\u003ccode\u003e9f10f1e\u003c/code\u003e\u003c/a\u003e fix: handle empty qualified private cache directive\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e\u003ccode\u003e3bf91dd\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `browserslist` from 4.28.4 to 4.28.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/releases\"\u003ebrowserslist's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eincluding kaios\u003c/code\u003e in baseline queries (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved parsing performance.\u003c/li\u003e\n\u003cli\u003eFixed unbounded memory growth (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed prototype write issue (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Electron version queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003e\u0026gt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;=\u003c/code\u003e queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md\"\u003ebrowserslist's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eincluding kaios\u003c/code\u003e in baseline queries (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved parsing performance.\u003c/li\u003e\n\u003cli\u003eFixed unbounded memory growth (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed prototype write issue (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Electron version queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003e\u0026gt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;=\u003c/code\u003e queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/12ed5252dabc14fee4e97b465894b2f90910ca62\"\u003e\u003ccode\u003e12ed525\u003c/code\u003e\u003c/a\u003e Release 4.28.9 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/b1d8cf9d7a7dc76f6585425a8360218289194297\"\u003e\u003ccode\u003eb1d8cf9\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/21517b651c915cdbbfb8c122268bc36f5cabb7ef\"\u003e\u003ccode\u003e21517b6\u003c/code\u003e\u003c/a\u003e Improve \u003ccode\u003eor\u003c/code\u003e parsing performance\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/f2f2e6cfb01bb4942941d328737546f4e2ae41ad\"\u003e\u003ccode\u003ef2f2e6c\u003c/code\u003e\u003c/a\u003e Release 4.28.8 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/d0787c88fa29ba895fea51cfe921232c7b5d1377\"\u003e\u003ccode\u003ed0787c8\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/fcf8fa9857b30ccdf801a548f5d09d3c4ff0d43f\"\u003e\u003ccode\u003efcf8fa9\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/browserslist/browserslist/issues/939\"\u003e#939\u003c/a\u003e from Jaybhade/fix/baseline-kaios-without-downstream\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/57ecd64454e9252afdd6a7e76926e13dda48a38c\"\u003e\u003ccode\u003e57ecd64\u003c/code\u003e\u003c/a\u003e fix: support \u0026quot;including kaios\u0026quot; without downstream\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/093a0f67bb0becda55235d767b134df3197c54a1\"\u003e\u003ccode\u003e093a0f6\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/b637868045806d2fba4c24eb0060e4cc8b1db276\"\u003e\u003ccode\u003eb637868\u003c/code\u003e\u003c/a\u003e Release 4.28.7 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/313f4659b9f985ade89d1d6a54a860371c41cc46\"\u003e\u003ccode\u003e313f465\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/browserslist/browserslist/compare/4.28.4...4.28.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `form-data` from 4.0.5 to 4.0.6\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/form-data/form-data/blob/master/CHANGELOG.md\"\u003eform-data's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/form-data/form-data/compare/v4.0.5...v4.0.6\"\u003ev4.0.6\u003c/a\u003e - 2026-06-12\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] escape CR, LF, and \u003ccode\u003e\u0026quot;\u003c/code\u003e in field names and filenames \u003ca href=\"https://github.com/form-data/form-data/commit/8dff42c6da654ed4e7ad4acb7f8ccd3831217c99\"\u003e\u003ccode\u003e8dff42c\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003etape\u003c/code\u003e \u003ca href=\"https://github.com/form-data/form-data/commit/f31d21ef10bf46e46344c3ee4f99acbef6be43e1\"\u003e\u003ccode\u003ef31d21e\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Deps] update \u003ccode\u003ehasown\u003c/code\u003e, \u003ccode\u003emime-types\u003c/code\u003e \u003ca href=\"https://github.com/form-data/form-data/commit/92ae0eb5da94d6f01925d5f4fcffb2a1e50ed7cd\"\u003e\u003ccode\u003e92ae0eb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003ejs-randomness-predictor\u003c/code\u003e \u003ca href=\"https://github.com/form-data/form-data/commit/67b0f65c2e0b065a511d42227d35e4d367644e97\"\u003e\u003ccode\u003e67b0f65\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/form-data/form-data/commit/64190db548c0179e37206858e39f27cf513e9435\"\u003e\u003ccode\u003e64190db\u003c/code\u003e\u003c/a\u003e v4.0.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/form-data/form-data/commit/92ae0eb5da94d6f01925d5f4fcffb2a1e50ed7cd\"\u003e\u003ccode\u003e92ae0eb\u003c/code\u003e\u003c/a\u003e [Deps] update \u003ccode\u003ehasown\u003c/code\u003e, \u003ccode\u003emime-types\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/form-data/form-data/commit/f31d21ef10bf46e46344c3ee4f99acbef6be43e1\"\u003e\u003ccode\u003ef31d21e\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003etape\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/form-data/form-data/commit/8dff42c6da654ed4e7ad4acb7f8ccd3831217c99\"\u003e\u003ccode\u003e8dff42c\u003c/code\u003e\u003c/a\u003e [Fix] escape CR, LF, and \u003ccode\u003e\u0026quot;\u003c/code\u003e in field names and filenames\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/form-data/form-data/commit/67b0f65c2e0b065a511d42227d35e4d367644e97\"\u003e\u003ccode\u003e67b0f65\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003ejs-randomness-predictor\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/form-data/form-data/compare/v4.0.5...v4.0.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `js-yaml` from 3.14.2 to 3.15.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md\"\u003ejs-yaml's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.15.2 - 2026-08-26\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Hard-limit merge sequence size to 100.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Count empty mappings in merge sequences toward \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e\nto limit CPU usage, \u003ca href=\"https://redirect.github.com/nodeca/js-yaml/issues/797\"\u003e#797\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.15.1 - 2026-07-31\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Remove quadratic complexity from \u003ccode\u003e!!omap\u003c/code\u003e duplicate key detection.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.15.0 - 2026-06-27\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003emaxTotalMergeKeys\u003c/code\u003e (10000) loader option to limit the total number of\nkeys processed by YAML merge (\u003ccode\u003e\u0026lt;\u0026lt;\u003c/code\u003e) across one \u003ccode\u003esafeLoad()\u003c/code\u003e / \u003ccode\u003esafeLoadAll()\u003c/code\u003e\ncall.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/5c45bd6e960603c13644f5cc8b572ca257723b36\"\u003e\u003ccode\u003e5c45bd6\u003c/code\u003e\u003c/a\u003e 3.15.2 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/5a708f9f4f22e78b87ebe363848cfa4fa4818c0d\"\u003e\u003ccode\u003e5a708f9\u003c/code\u003e\u003c/a\u003e dist rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/3485bc06ff8a0251505f44a00414d90df2466639\"\u003e\u003ccode\u003e3485bc0\u003c/code\u003e\u003c/a\u003e Backport merge limits from v5.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/f34812f1cea794f8c21e0a4e1f3a2584b720f305\"\u003e\u003ccode\u003ef34812f\u003c/code\u003e\u003c/a\u003e Update .gitignore\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/ab85ae2c622bc6d8cdbceccafe9f9b7df80463ed\"\u003e\u003ccode\u003eab85ae2\u003c/code\u003e\u003c/a\u003e 3.15.1 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/30a5e7647a4454f7bac969bfbbe7eac9921a4279\"\u003e\u003ccode\u003e30a5e76\u003c/code\u003e\u003c/a\u003e dist rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/22a8071ef032117bc6249c330b240ac3aa2d3ded\"\u003e\u003ccode\u003e22a8071\u003c/code\u003e\u003c/a\u003e Backport quadratic complexity fix for !!omap\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/c34b6c40027a769eb0d67958ae615268a1d55f54\"\u003e\u003ccode\u003ec34b6c4\u003c/code\u003e\u003c/a\u003e 3.15.0 released\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/21e13d363f33501c7ee6ca988b88c29084999f72\"\u003e\u003ccode\u003e21e13d3\u003c/code\u003e\u003c/a\u003e dist rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodeca/js-yaml/commit/4165c62630d64fe4f25fb0d03139c7e137b24b1c\"\u003e\u003ccode\u003e4165c62\u003c/code\u003e\u003c/a\u003e Add v3-legacy tag for publish\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodeca/js-yaml/compare/3.14.2...3.15.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nanoid` from 3.3.15 to 3.3.19\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/releases\"\u003enanoid's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/blob/main/CHANGELOG.md\"\u003enanoid's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID (by \u003ca href=\"https://github.com/geoffrey-diederichs\"\u003e\u003ccode\u003e@​geoffrey-diederichs\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/eb63bd6775188dc35d143bf24868be094f19b5ee\"\u003e\u003ccode\u003eeb63bd6\u003c/code\u003e\u003c/a\u003e Release 3.3.19 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9067e0361a643ab2c94ddd67606efbf275f6c0dd\"\u003e\u003ccode\u003e9067e03\u003c/code\u003e\u003c/a\u003e Sync CJS and ESM\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9ad98052b316c5e707f8098ace509d2ae165e54d\"\u003e\u003ccode\u003e9ad9805\u003c/code\u003e\u003c/a\u003e Release 3.3.18 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/55e50a0621ec084b4bb4000ea4e86e1191bd3da8\"\u003e\u003ccode\u003e55e50a0\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e10f8d40ce9d1ab47f66d65a16b48086432730d0\"\u003e\u003ccode\u003ee10f8d4\u003c/code\u003e\u003c/a\u003e Update index.native.js (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/606\"\u003e#606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/73d67168136b36fd3b644159b0cff149da4905d9\"\u003e\u003ccode\u003e73d6716\u003c/code\u003e\u003c/a\u003e Release 3.3.17 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/f9d13f150847d117877adee3460a46eceb0cf49b\"\u003e\u003ccode\u003ef9d13f1\u003c/code\u003e\u003c/a\u003e Sync 0 size behaviour with PostCSS 5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9760e112757cf7d46a79abd7a133bc4958757bb8\"\u003e\u003ccode\u003e9760e11\u003c/code\u003e\u003c/a\u003e Release 3.3.16 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66d\"\u003e\u003ccode\u003ee835c9b\u003c/code\u003e\u003c/a\u003e fix(non-secure): clamp negative size to prevent infinite loop (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/601\"\u003e#601\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/96dd086eb24396a275fa93ee78d73b2fece35809\"\u003e\u003ccode\u003e96dd086\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ai/nanoid/compare/3.3.15...3.3.19\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `sharp` from 0.34.5 to 0.35.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lovell/sharp/releases\"\u003esharp's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.35.4\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\"\u003ehttps://github.com/lovell/sharp-libvips/releases/tag/v1.3.3\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.35.4-rc.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpgrade to libvips v8.18.6 for upstream bug fixes.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound resize dimensions to coordinate limit.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eBound composite left and top to coordinate limit.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4564\"\u003e#4564\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRound palette bit depth up for png and gif colours.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4569\"\u003e#4569\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure tiff.subifd input option is used.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4572\"\u003e#4572\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eEnsure \u003ccode\u003einfo.pages\u003c/code\u003e is correct when limiting input page range.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4578\"\u003e#4578\u003c/a\u003e\n\u003ca href=\"https://github.com/metsw24-max\"\u003e\u003ccode\u003e@​metsw24-max\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImprove support for input Streams finishing before output is requested.\n\u003ca href=\"https://redirect.github.com/lovell/sharp/pull/4584\"\u003e#4584\u003c/a\u003e\n\u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7f1a0a22cc285fe180766f4935d50b55af6e8432\"\u003e\u003ccode\u003e7f1a0a2\u003c/code\u003e\u003c/a\u003e Release v0.35.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/f927818924bc5a9493d822a4e8b23ec5857c52e1\"\u003e\u003ccode\u003ef927818\u003c/code\u003e\u003c/a\u003e Upgrade to sharp-libvips v1.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e80209240d005c71e1173a50dd9cd4db4ce2a9e6\"\u003e\u003ccode\u003ee802092\u003c/code\u003e\u003c/a\u003e Prerelease v0.35.4-rc.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/e13eb2f97a0a22f1ef726e8d0cd33f7c56835945\"\u003e\u003ccode\u003ee13eb2f\u003c/code\u003e\u003c/a\u003e CI: Fix wasm32 build (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4589\"\u003e#4589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/a82a0b3d58bc25854ad1e925e6eb0a50725d1489\"\u003e\u003ccode\u003ea82a0b3\u003c/code\u003e\u003c/a\u003e Upgrade to libvips v8.18.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/8044fe43e36d0ea7f8beb89f79a37bb0f3342e84\"\u003e\u003ccode\u003e8044fe4\u003c/code\u003e\u003c/a\u003e Bound resize dimensions to coordinate limit\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/147f8591a153bc4a1e199c3fe3150fac2931b30c\"\u003e\u003ccode\u003e147f859\u003c/code\u003e\u003c/a\u003e Docs: changelog entries for \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4578\"\u003e#4578\u003c/a\u003e \u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ee5bfb853de75a611c64381783b04032a3a897d8\"\u003e\u003ccode\u003eee5bfb8\u003c/code\u003e\u003c/a\u003e Tests: use yauzl directly rather than via extract-zip wrapper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/7a7788928f8a2a429f45039010a87cee35401694\"\u003e\u003ccode\u003e7a77889\u003c/code\u003e\u003c/a\u003e Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4588\"\u003e#4588\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lovell/sharp/commit/ea5bef24c187b2c7ee3fe3cad3b45c8cb67a46fd\"\u003e\u003ccode\u003eea5bef2\u003c/code\u003e\u003c/a\u003e Improve support for input Streams finishing before output is requested (\u003ca href=\"https://redirect.github.com/lovell/sharp/issues/4584\"\u003e#4584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/lovell/sharp/compare/v0.34.5...v0.35.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nodemailer` from 9.0.3 to 9.1.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodemailer/nodemailer/releases\"\u003enodemailer's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev9.1.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.1.0...v9.1.1\"\u003e9.1.1\u003c/a\u003e (2026-09-01)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e apply the message access policy in resolveContent (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/dc48ed395c4d6c79ee5c95eb6eff17bafe391474\"\u003edc48ed3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e keep message data from reopening the access sandbox (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/ab7ef348b9a97b1fd70e7bfbeb56d4ea4a07946b\"\u003eab7ef34\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e inherit the access policy from the tree a node hangs in (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/262d550b1e121e3ff4ef6675d6771a5b2b4ddcec\"\u003e262d550\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev9.1.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.0.6...v9.1.0\"\u003e9.1.0\u003c/a\u003e (2026-08-31)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e cap recipients per message with maxRecipients (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/7279ac8dee4f66c032981e6e51e3e7210ad0dcbf\"\u003e7279ac8\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eaddressparser:\u003c/strong\u003e handle address lists in linear time (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/9116da9528c6524cefaed75185602a7e85d20434\"\u003e9116da9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eaddressparser:\u003c/strong\u003e terminate the domain at an RFC 5322 comment (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/902b63e935435c30f4025901c0902dce64cd8880\"\u003e902b63e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e apply UTS-46 mapping when encoding a domain (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/259c32d7d266301e3377a212776c3fff993c0148\"\u003e259c32d\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e dedupe envelope recipients in linear time (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/7cc38af418ffa6fc7e86085195ca5ca681694b3e\"\u003e7cc38af\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e flatten parsed addresses without concat.apply (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/83b8c48cbdb8b3116f2e1ba84af755b2c5661c0f\"\u003e83b8c48\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e keep the recipient dedupe linear across address headers (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/34da64282dcdc9b0581c721a27ab2fa226673150\"\u003e34da642\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-node:\u003c/strong\u003e keep URL delimiters away from the domain mapper (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/b212ac4e27bce8182478044fcb8d1642ccdad46e\"\u003eb212ac4\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev9.0.6\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.0.5...v9.0.6\"\u003e9.0.6\u003c/a\u003e (2026-08-27)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eaddressparser:\u003c/strong\u003e recover the addr-spec from an angle-addr holding whitespace (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/e989a22ca4f5161929bf37be8fb07de635016fa7\"\u003ee989a22\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eharden copies of user supplied keys and URL fetching (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/2f667f4272cb2d7cb479b2e3903ab10600fc0eae\"\u003e2f667f4\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev9.0.5\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/nodemailer/nodemailer/compare/v9.0.4...v9.0.5\"\u003e9.0.5\u003c/a\u003e (2026-08-07)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eci:\u003c/strong\u003e retrigger the workflows dropped during the Actions outage (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/85d16c103ec69e237c7e55c0e3103f439c135ce3\"\u003e85d16c1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emailer:\u003c/strong\u003e escape specials in List-* header comments (\u003ca href=\"https://redirect.github.com/nodemailer/nodemailer/issues/1842\"\u003e#1842\u003c/a\u003e) (\u003ca href=\"https://github.com/nodemailer/nodemailer/commit/75913bba032623046dd7fa037b8b880e388d8357\"\u003e75913bb\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003emime-funcs:\u003c/strong\u003e star the continuation key of a restarted parameter line (\u003ca href=\"...\n\n_Description has been truncated_","html_url":"https://github.com/iam-dev/oms-nest/pull/103","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/iam-dev%2Foms-nest/issues/103","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/103/packages"}},{"old_version":"8.10.0","new_version":"8.10.2","update_type":"patch","path":null,"pr_created_at":"2026-09-11T18:19:40.000Z","version_change":"8.10.0 → 8.10.2","issue":{"uuid":"5427651950","node_id":"PR_kwDOQlxMks8AAAABDLxzYQ","number":177,"state":"open","title":"Chore(deps): bump the minor-and-patch group across 1 directory with 17 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T18:19:40.000Z","updated_at":"2026-09-11T18:24:41.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Chore(deps): bump","group_name":"minor-and-patch","update_count":17,"packages":[{"name":"@swc/core","old_version":"1.16.1","new_version":"1.16.2","repository_url":"https://github.com/swc-project/swc"},{"name":"eslint","old_version":"10.9.1","new_version":"10.10.0","repository_url":"https://github.com/eslint/eslint"},{"name":"squawk-cli","old_version":"2.63.0","new_version":"2.64.0","repository_url":"https://github.com/sbdchd/squawk"},{"name":"tuffgal","old_version":"0.2.0-alpha.8","new_version":"0.3.0-alpha.1","repository_url":"https://github.com/nschneble/tuffgal"},{"name":"typescript-eslint","old_version":"8.68.0","new_version":"8.70.0","repository_url":"https://github.com/typescript-eslint/typescript-eslint"},{"name":"pg-boss","old_version":"12.28.0","new_version":"12.30.0","repository_url":"https://github.com/timgit/pg-boss"},{"name":"undici","old_version":"8.10.0","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"},{"name":"@eslint/eslintrc","old_version":"3.3.6","new_version":"3.3.7","repository_url":"https://github.com/eslint/eslintrc"},{"name":"@types/node","old_version":"26.4.0","new_version":"26.5.0","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"globals","old_version":"17.11.0","new_version":"17.12.0","repository_url":"https://github.com/sindresorhus/globals"},{"name":"jest","old_version":"30.4.2","new_version":"30.5.1","repository_url":"https://github.com/jestjs/jest"},{"name":"react-router","old_version":"8.3.0","new_version":"8.3.1","repository_url":"https://github.com/remix-run/react-router"},{"name":"@testing-library/user-event","old_version":"14.6.6","new_version":"14.6.7","repository_url":"https://github.com/testing-library/user-event"},{"name":"@types/react-dom","old_version":"19.2.5","new_version":"19.2.7","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"@vitejs/plugin-react","old_version":"6.1.0","new_version":"6.1.1","repository_url":"https://github.com/vitejs/vite-plugin-react"},{"name":"eslint-plugin-react-refresh","old_version":"0.5.5","new_version":"0.5.6","repository_url":"https://github.com/ArnaudBarre/eslint-plugin-react-refresh"},{"name":"subset-font","old_version":"2.5.0","new_version":"2.7.0","repository_url":"https://github.com/papandreou/subset-font"}],"path":null,"ecosystem":"npm"},"body":"Bumps the minor-and-patch group with 17 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@swc/core](https://github.com/swc-project/swc/tree/HEAD/packages/core) | `1.16.1` | `1.16.2` |\n| [eslint](https://github.com/eslint/eslint) | `10.9.1` | `10.10.0` |\n| [squawk-cli](https://github.com/sbdchd/squawk) | `2.63.0` | `2.64.0` |\n| [tuffgal](https://github.com/nschneble/tuffgal) | `0.2.0-alpha.8` | `0.3.0-alpha.1` |\n| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.68.0` | `8.70.0` |\n| [pg-boss](https://github.com/timgit/pg-boss) | `12.28.0` | `12.30.0` |\n| [undici](https://github.com/nodejs/undici) | `8.10.0` | `8.10.2` |\n| [@eslint/eslintrc](https://github.com/eslint/eslintrc) | `3.3.6` | `3.3.7` |\n| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.4.0` | `26.5.0` |\n| [globals](https://github.com/sindresorhus/globals) | `17.11.0` | `17.12.0` |\n| [jest](https://github.com/jestjs/jest/tree/HEAD/packages/jest) | `30.4.2` | `30.5.1` |\n| [react-router](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router) | `8.3.0` | `8.3.1` |\n| [@testing-library/user-event](https://github.com/testing-library/user-event) | `14.6.6` | `14.6.7` |\n| [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom) | `19.2.5` | `19.2.7` |\n| [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) | `6.1.0` | `6.1.1` |\n| [eslint-plugin-react-refresh](https://github.com/ArnaudBarre/eslint-plugin-react-refresh) | `0.5.5` | `0.5.6` |\n| [subset-font](https://github.com/papandreou/subset-font) | `2.5.0` | `2.7.0` |\n\n\nUpdates `@swc/core` from 1.16.1 to 1.16.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/swc-project/swc/blob/main/CHANGELOG.md\"\u003e@​swc/core's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.16.2] - 2026-09-04\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/compat)\u003c/strong\u003e Preserve for-of var binding scope (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12158\"\u003e#12158\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/f6d5bd12bf267dbb2e1551ccacd82b198e6edc6f\"\u003ef6d5bd1\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/decorators)\u003c/strong\u003e Drop params from getter replacing decorated private method (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12161\"\u003e#12161\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/d56f5943861178b91ff6e718bddb10e997da1a8c\"\u003ed56f594\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/flow)\u003c/strong\u003e Preserve Flow component type semantics (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12090\"\u003e#12090\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/c8d5b497c4895367b0902bde42b3f6a3fa5b7c24\"\u003ec8d5b49\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/minifier)\u003c/strong\u003e Mark for update and test as executed multiple time (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12131\"\u003e#12131\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/1260e362fd9bb15cf93b2d3ce595290c7ff272cf\"\u003e1260e36\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/minifier)\u003c/strong\u003e Report for loop var decl as assign (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12136\"\u003e#12136\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/783bbc29c8ccbc7d2dfa73860dd2765ee09d459d\"\u003e783bbc2\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/minifier)\u003c/strong\u003e Don't replace value-used console.*.bind() calls with undefined (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12138\"\u003e#12138\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/ed742230471f5462da9f24a8a4c1566d8fa8ef68\"\u003eed74223\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/minifier)\u003c/strong\u003e Drop spans of cached \u003ccode\u003eglobals\u003c/code\u003e values (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12129\"\u003e#12129\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/9a306b890ac9d4fc8698faf6c55ff95e82983585\"\u003e9a306b8\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/minifier)\u003c/strong\u003e Preserve effects of returned value calls (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12140\"\u003e#12140\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/c37b5a954794cf0e4cfa419868899385f067bc05\"\u003ec37b5a9\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/minifier)\u003c/strong\u003e Avoid JSX sequence inlining loop (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12149\"\u003e#12149\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/4e79b94930d7fc21b794f3c480fea4c9f8f8344e\"\u003e4e79b94\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/minifier)\u003c/strong\u003e Preserve bindings in copied inline arrows (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12141\"\u003e#12141\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/cf7b5c96430be5fc5fab4820c6bf75eb53f5c712\"\u003ecf7b5c9\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/minifier)\u003c/strong\u003e Preserve do-while control-flow targets (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12160\"\u003e#12160\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/f62c437dc2546d8cf3aa8211970f72693a357d0c\"\u003ef62c437\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/minifier)\u003c/strong\u003e Preserve pure annotation ownership (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12180\"\u003e#12180\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/ec780f927369cc81dfa3a1aca73802d7e5885a96\"\u003eec780f9\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/parser)\u003c/strong\u003e Retry ambiguous Program parsing (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12142\"\u003e#12142\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/141a3201322dd3cf1acb317fe1c8889cdeda9358\"\u003e141a320\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/parser)\u003c/strong\u003e Preserve await grammar boundaries (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12156\"\u003e#12156\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/c7326832e57d2d3effe9eb1b3c415424ae68bf21\"\u003ec732683\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e(es/quote)\u003c/strong\u003e Restore await parsing (\u003ca href=\"https://redirect.github.com/swc-project/swc/issues/12163\"\u003e#12163\u003c/a\u003e) (\u003ca href=\"https://github.com/swc-project/swc/commit/918f5174a17425cd49c3eedc1e761ebdf1fc3d2e\"\u003e918f517\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/swc-project/swc/commit/5ae9149e67e86d2b23eae6b46cf1f8585778f7af\"\u003e\u003ccode\u003e5ae9149\u003c/code\u003e\u003c/a\u003e chore: Publish \u003ccode\u003e1.16.2\u003c/code\u003e with \u003ccode\u003eswc_core\u003c/code\u003e \u003ccode\u003ev78.0.0\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/swc-project/swc/commit/5c24a37d7a9306a79225ba5da7b4bebf49a91b55\"\u003e\u003ccode\u003e5c24a37\u003c/code\u003e\u003c/a\u003e chore: Publish \u003ccode\u003e1.16.2-nightly-20260904.1\u003c/code\u003e with \u003ccode\u003eswc_core\u003c/code\u003e \u003ccode\u003ev78.0.0\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/swc-project/swc/commits/v1.16.2/packages/core\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `eslint` from 10.9.1 to 10.10.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/eslint/eslint/releases\"\u003eeslint's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev10.10.0\u003c/h2\u003e\n\u003ch2\u003eFeatures\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/264b4346d1963701df0c398b4aeb2f6e8b2af93e\"\u003e\u003ccode\u003e264b434\u003c/code\u003e\u003c/a\u003e feat: add \u003ccode\u003ed\u003c/code\u003e and \u003ccode\u003ev\u003c/code\u003e flags to \u003ccode\u003eno-unexpected-multiline\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21305\"\u003e#21305\u003c/a\u003e) (Gihyeon Jeong / 정기현)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/c6cc6c592f30901345d94ef75e0d42c1894fae6c\"\u003e\u003ccode\u003ec6cc6c5\u003c/code\u003e\u003c/a\u003e feat: check \u003ccode\u003eObject.prototype\u003c/code\u003e property names in \u003ccode\u003enew-cap\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21269\"\u003e#21269\u003c/a\u003e) (crimsonjay0)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/5661fa65fde9fd4c14f0b730e3cee6a42fc657c1\"\u003e\u003ccode\u003e5661fa6\u003c/code\u003e\u003c/a\u003e feat: no-extra-bind false negatives with class fields and static blocks (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21260\"\u003e#21260\u003c/a\u003e) (synthex-byte)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/bb47dc6da2399a8f76c0c0c3273e6bc314c480e5\"\u003e\u003ccode\u003ebb47dc6\u003c/code\u003e\u003c/a\u003e fix: update dependency file-entry-cache to v11 (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/20801\"\u003e#20801\u003c/a\u003e) (Milos Djermanovic)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/427ac0a014066c36aa57fa8fa9af20fd9fb591e1\"\u003e\u003ccode\u003e427ac0a\u003c/code\u003e\u003c/a\u003e fix: use format strings in debug calls (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21247\"\u003e#21247\u003c/a\u003e) (Francesco Trotta)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/9d8153223dbf47b9aecdc1474202aaee4845f146\"\u003e\u003ccode\u003e9d81532\u003c/code\u003e\u003c/a\u003e fix: support \u003ccode\u003e__proto__\u003c/code\u003e in \u003ccode\u003e/* exported */\u003c/code\u003e comments (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21261\"\u003e#21261\u003c/a\u003e) (sethamus)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/87e0a082438264ad90b87fd74165ab4fd90f63ef\"\u003e\u003ccode\u003e87e0a08\u003c/code\u003e\u003c/a\u003e fix: prefer-object-has-own autofix breaks when Object is shadowed (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21282\"\u003e#21282\u003c/a\u003e) (김채영)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/8e2cb142217f2efee1d10dcc02bfb75145ae775d\"\u003e\u003ccode\u003e8e2cb14\u003c/code\u003e\u003c/a\u003e fix: \u003ccode\u003enew-cap\u003c/code\u003e false positive for \u003ccode\u003eUTC\u003c/code\u003e calls with \u003ccode\u003eproperties: false\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21275\"\u003e#21275\u003c/a\u003e) (Pixel)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/9f4a364ab0ade048dfce1f37792b1d461d866e55\"\u003e\u003ccode\u003e9f4a364\u003c/code\u003e\u003c/a\u003e fix: Ignore static imports in no-unreachable (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21276\"\u003e#21276\u003c/a\u003e) (Taha Kotil)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/2417cad57d7d1bc4cf3ecf0f0575cfb10ff2011c\"\u003e\u003ccode\u003e2417cad\u003c/code\u003e\u003c/a\u003e docs: Update README (GitHub Actions Bot)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/9cecb8a0a2348070abf72321965d41919c7cc626\"\u003e\u003ccode\u003e9cecb8a\u003c/code\u003e\u003c/a\u003e docs: document \u003ccode\u003e\\c\u003c/code\u003e control letter escapes in no-control-regex (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21286\"\u003e#21286\u003c/a\u003e) (한국)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/8724829f69f8ed80c876e3a5a017da199ce78739\"\u003e\u003ccode\u003e8724829\u003c/code\u003e\u003c/a\u003e docs: update compat table links (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21263\"\u003e#21263\u003c/a\u003e) (fnx)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/5634542be580750ffb1a5766470f9e9c72719696\"\u003e\u003ccode\u003e5634542\u003c/code\u003e\u003c/a\u003e docs: Clarify eqeqeq suggestion behavior (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21256\"\u003e#21256\u003c/a\u003e) (Müslüm Yılmaz)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eChores\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/b3d876b46083d67899eb1d9613118c1c583632a2\"\u003e\u003ccode\u003eb3d876b\u003c/code\u003e\u003c/a\u003e chore: disable npm audit in ecosystem tests (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21306\"\u003e#21306\u003c/a\u003e) (Francesco Trotta)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/1696682791661c13167eb905da2f38d1b8f4a3bf\"\u003e\u003ccode\u003e1696682\u003c/code\u003e\u003c/a\u003e ci: restore EMFILE test on Node.js 26 (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21297\"\u003e#21297\u003c/a\u003e) (Marry (Subin Yang))\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/2c7f5d6f47a92e8c0847af103e40fdb2f4dc61ef\"\u003e\u003ccode\u003e2c7f5d6\u003c/code\u003e\u003c/a\u003e chore: update github/codeql-action action to v4.37.9 (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21296\"\u003e#21296\u003c/a\u003e) (renovate[bot])\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/3c753f18b461bfbf36d41a79a7863c093ef48489\"\u003e\u003ccode\u003e3c753f1\u003c/code\u003e\u003c/a\u003e chore: update eslint (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21289\"\u003e#21289\u003c/a\u003e) (renovate[bot])\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/1c734690bf6f4f9c542bec428d5a1a5c6cc4a19b\"\u003e\u003ccode\u003e1c73469\u003c/code\u003e\u003c/a\u003e chore: update ecosystem plugins (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21280\"\u003e#21280\u003c/a\u003e) (ESLint Bot)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/08a02be429e21fc93d86c8dd16cec6dc945ea2c1\"\u003e\u003ccode\u003e08a02be\u003c/code\u003e\u003c/a\u003e test: add error locations to \u003ccode\u003eno-extra-boolean-cast\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21266\"\u003e#21266\u003c/a\u003e) (lumir)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/77bb1db8e730b7da2347c647d60f215706aa349a\"\u003e\u003ccode\u003e77bb1db\u003c/code\u003e\u003c/a\u003e chore: update github/codeql-action action to v4.37.8 (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21270\"\u003e#21270\u003c/a\u003e) (renovate[bot])\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/007e81ac0ad66bd0be4887d88a276df292ae0bed\"\u003e\u003ccode\u003e007e81a\u003c/code\u003e\u003c/a\u003e ci: skip EMFILE test on Node.js 26 (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21265\"\u003e#21265\u003c/a\u003e) (lumir)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/0430280e7cca9dc0fdbf0bc50464e98e84285c49\"\u003e\u003ccode\u003e0430280\u003c/code\u003e\u003c/a\u003e chore: improve ecosystem tests compatibility on Windows (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21178\"\u003e#21178\u003c/a\u003e) (crimsonjay0)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/3f20a57c6293371b6193d3fb6746c2b7b2ac2689\"\u003e\u003ccode\u003e3f20a57\u003c/code\u003e\u003c/a\u003e 10.10.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/f4e5284803854423c4c2536696888c28ce4a151f\"\u003e\u003ccode\u003ef4e5284\u003c/code\u003e\u003c/a\u003e Build: changelog update for 10.10.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/bb47dc6da2399a8f76c0c0c3273e6bc314c480e5\"\u003e\u003ccode\u003ebb47dc6\u003c/code\u003e\u003c/a\u003e fix: update dependency file-entry-cache to v11 (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/20801\"\u003e#20801\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/427ac0a014066c36aa57fa8fa9af20fd9fb591e1\"\u003e\u003ccode\u003e427ac0a\u003c/code\u003e\u003c/a\u003e fix: use format strings in debug calls (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21247\"\u003e#21247\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/b3d876b46083d67899eb1d9613118c1c583632a2\"\u003e\u003ccode\u003eb3d876b\u003c/code\u003e\u003c/a\u003e chore: disable npm audit in ecosystem tests (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21306\"\u003e#21306\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/9d8153223dbf47b9aecdc1474202aaee4845f146\"\u003e\u003ccode\u003e9d81532\u003c/code\u003e\u003c/a\u003e fix: support \u003ccode\u003e__proto__\u003c/code\u003e in \u003ccode\u003e/* exported */\u003c/code\u003e comments (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21261\"\u003e#21261\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/264b4346d1963701df0c398b4aeb2f6e8b2af93e\"\u003e\u003ccode\u003e264b434\u003c/code\u003e\u003c/a\u003e feat: add \u003ccode\u003ed\u003c/code\u003e and \u003ccode\u003ev\u003c/code\u003e flags to \u003ccode\u003eno-unexpected-multiline\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21305\"\u003e#21305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/1696682791661c13167eb905da2f38d1b8f4a3bf\"\u003e\u003ccode\u003e1696682\u003c/code\u003e\u003c/a\u003e ci: restore EMFILE test on Node.js 26 (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21297\"\u003e#21297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/2c7f5d6f47a92e8c0847af103e40fdb2f4dc61ef\"\u003e\u003ccode\u003e2c7f5d6\u003c/code\u003e\u003c/a\u003e chore: update github/codeql-action action to v4.37.9 (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21296\"\u003e#21296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslint/commit/87e0a082438264ad90b87fd74165ab4fd90f63ef\"\u003e\u003ccode\u003e87e0a08\u003c/code\u003e\u003c/a\u003e fix: prefer-object-has-own autofix breaks when Object is shadowed (\u003ca href=\"https://redirect.github.com/eslint/eslint/issues/21282\"\u003e#21282\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/eslint/eslint/compare/v10.9.1...v10.10.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `squawk-cli` from 2.63.0 to 2.64.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/sbdchd/squawk/releases\"\u003esquawk-cli's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eUpdate prefer-robust-stmts to be alembic version aware + code formatter\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003elinter: prefer-robust-stmts aware of alembic version update transactions (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1311\"\u003e#1311\u003c/a\u003e). Thanks \u003ca href=\"https://github.com/DylanGriffith\"\u003e\u003ccode\u003e@​DylanGriffith\u003c/code\u003e\u003c/a\u003e!\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003efmt: support for all statements (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1321\"\u003e#1321\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1319\"\u003e#1319\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1317\"\u003e#1317\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1312\"\u003e#1312\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1310\"\u003e#1310\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1309\"\u003e#1309\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1307\"\u003e#1307\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1306\"\u003e#1306\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1305\"\u003e#1305\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1303\"\u003e#1303\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1302\"\u003e#1302\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1300\"\u003e#1300\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1299\"\u003e#1299\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eide: add formatting support (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1315\"\u003e#1315\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eide: code action isnull -\u0026gt; is null, notnull -\u0026gt; is not null (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1296\"\u003e#1296\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eide: code actions for func params (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1322\"\u003e#1322\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eide: code action to convert \u003ccode\u003edefault\u003c/code\u003e to \u003ccode\u003e=\u003c/code\u003e in function syntax (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1316\"\u003e#1316\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eide: code actions for :=/=\u0026gt; \u0026amp; value/: rewrites (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1313\"\u003e#1313\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eparser: validation for variadic, function defaults, params (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1325\"\u003e#1325\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1324\"\u003e#1324\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1323\"\u003e#1323\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eparser: validate string literal type cast (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1320\"\u003e#1320\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eplayground: add code formatting output (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1326\"\u003e#1326\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eparser: split bit \u0026amp; time type ast nodes (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1297\"\u003e#1297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eparser: add nodes for interval \u0026amp; array bounds (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1301\"\u003e#1301\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eparser: improve parsing of operators in using and exclude (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1304\"\u003e#1304\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eparser: refactor percent type out of ast::Type (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1318\"\u003e#1318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eparser: refactor char type into character and varchar nodes (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1295\"\u003e#1295\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003esyntax: fix unquoting \u0026amp; add more funcs (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1298\"\u003e#1298\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/sbdchd/squawk/blob/master/CHANGELOG.md\"\u003esquawk-cli's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.64.0 - 2026-08-31\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003elinter: prefer-robust-stmts aware of alembic version update transactions (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1311\"\u003e#1311\u003c/a\u003e). Thanks \u003ca href=\"https://github.com/DylanGriffith\"\u003e\u003ccode\u003e@​DylanGriffith\u003c/code\u003e\u003c/a\u003e!\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003efmt: support for all statements (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1321\"\u003e#1321\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1319\"\u003e#1319\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1317\"\u003e#1317\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1312\"\u003e#1312\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1310\"\u003e#1310\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1309\"\u003e#1309\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1307\"\u003e#1307\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1306\"\u003e#1306\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1305\"\u003e#1305\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1303\"\u003e#1303\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1302\"\u003e#1302\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1300\"\u003e#1300\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1299\"\u003e#1299\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eide: add formatting support (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1315\"\u003e#1315\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eide: code action isnull -\u0026gt; is null, notnull -\u0026gt; is not null (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1296\"\u003e#1296\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eide: code actions for func params (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1322\"\u003e#1322\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eide: code action to convert \u003ccode\u003edefault\u003c/code\u003e to \u003ccode\u003e=\u003c/code\u003e in function syntax (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1316\"\u003e#1316\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eide: code actions for :=/=\u0026gt; \u0026amp; value/: rewrites (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1313\"\u003e#1313\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eparser: validation for variadic, function defaults, params (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1325\"\u003e#1325\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1324\"\u003e#1324\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1323\"\u003e#1323\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eparser: validate string literal type cast (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1320\"\u003e#1320\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eplayground: add code formatting output (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1326\"\u003e#1326\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eparser: split bit \u0026amp; time type ast nodes (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1297\"\u003e#1297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eparser: add nodes for interval \u0026amp; array bounds (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1301\"\u003e#1301\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eparser: improve parsing of operators in using and exclude (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1304\"\u003e#1304\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eparser: refactor percent type out of ast::Type (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1318\"\u003e#1318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eparser: refactor char type into character and varchar nodes (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1295\"\u003e#1295\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003esyntax: fix unquoting \u0026amp; add more funcs (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1298\"\u003e#1298\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbdchd/squawk/commit/0c55115ca14b5051cb39bbb8996f9b240f82f4b8\"\u003e\u003ccode\u003e0c55115\u003c/code\u003e\u003c/a\u003e release: 2.64.0 (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1327\"\u003e#1327\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbdchd/squawk/commit/f1fa317b752fea0fb5dc10c134213ee9d1060dd9\"\u003e\u003ccode\u003ef1fa317\u003c/code\u003e\u003c/a\u003e playground: add code formatting output (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1326\"\u003e#1326\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbdchd/squawk/commit/7d219a5d8ecfecb10fa0fe819b8a077097283d0d\"\u003e\u003ccode\u003e7d219a5\u003c/code\u003e\u003c/a\u003e parser: add validation for variadic (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1325\"\u003e#1325\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbdchd/squawk/commit/9ced3719da27a6871cef00d0480be659e3fd318d\"\u003e\u003ccode\u003e9ced371\u003c/code\u003e\u003c/a\u003e parser: add validation for function defaults (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1324\"\u003e#1324\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbdchd/squawk/commit/a96667a7dfa6a817bcee68aedcf599fe284fd0ae\"\u003e\u003ccode\u003ea96667a\u003c/code\u003e\u003c/a\u003e parser: add validation for params (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1323\"\u003e#1323\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbdchd/squawk/commit/7cc4f56a14b962f659f673240b5cbb9ed6821caf\"\u003e\u003ccode\u003e7cc4f56\u003c/code\u003e\u003c/a\u003e ide: code actions for func params (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1322\"\u003e#1322\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbdchd/squawk/commit/707a17d8473767f5499a6bc6aa67f8e4191fd159\"\u003e\u003ccode\u003e707a17d\u003c/code\u003e\u003c/a\u003e fmt: avoid quoting things that don't need quoting (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1321\"\u003e#1321\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbdchd/squawk/commit/ba6210126cde692eaa594893032758719d3a5a08\"\u003e\u003ccode\u003eba62101\u003c/code\u003e\u003c/a\u003e parser: validate string literal type cast (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1320\"\u003e#1320\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbdchd/squawk/commit/a573962f257c3b67b87692285bbdd4b90bd70830\"\u003e\u003ccode\u003ea573962\u003c/code\u003e\u003c/a\u003e parser: test typed literals \u0026amp; simplify type modifier formatting (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1319\"\u003e#1319\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbdchd/squawk/commit/79be8ee9b97e8acf2ba6b033e096324ca93824a9\"\u003e\u003ccode\u003e79be8ee\u003c/code\u003e\u003c/a\u003e parser: refactor percent type out of ast::Type (\u003ca href=\"https://redirect.github.com/sbdchd/squawk/issues/1318\"\u003e#1318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/sbdchd/squawk/compare/v2.63.0...v2.64.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tuffgal` from 0.2.0-alpha.8 to 0.3.0-alpha.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nschneble/tuffgal/releases\"\u003etuffgal's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.3.0-alpha.1\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003ediff.maxDiffPixels\u003c/code\u003e, a per-action budget for how many pixels may differ and still pass. An action now passes only when it clears both mean SSIM at or above \u003ccode\u003essimThreshold\u003c/code\u003e and differing pixels at or under \u003ccode\u003emaxDiffPixels\u003c/code\u003e.\u003c/p\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003eBreaking default.\u003c/strong\u003e \u003ccode\u003emaxDiffPixels\u003c/code\u003e defaults to \u003ccode\u003e0\u003c/code\u003e, so a run that used to pass on SSIM tolerance alone can now report \u003ccode\u003echanged\u003c/code\u003e.\u003c/p\u003e\n\u003ch2\u003ev0.2.2-alpha.1\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003ebrowserArgs\u003c/code\u003e config option; extra command-line flags are now passed directly through to \u003ccode\u003echromium.launch()\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eThe motivating case is \u003ccode\u003e--force-color-profile=srgb\u003c/code\u003e because without it Chromium renders through whatever ICC profile the host OS reports, and a laptop and CI container can shift baseline pixels for a reason that has nothing to do with what's being tested.\u003c/p\u003e\n\u003cp\u003eIf you omit the field, nothing changes from before.\u003c/p\u003e\n\u003ch2\u003ev0.2.1-alpha.1\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eA \u003ccode\u003eneeds\u003c/code\u003e label that no story \u003ccode\u003eproduces\u003c/code\u003e fails the run when declared in \u003ccode\u003eseededLabels\u003c/code\u003e and \u003ccode\u003e\u0026lt;paths.authState\u0026gt;/\u0026lt;label\u0026gt;.json\u003c/code\u003e is on disk\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nschneble/tuffgal/blob/main/CHANGELOG.md\"\u003etuffgal's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[0.3.0-alpha.1] – 2026-09-03\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003ediff.maxDiffPixels\u003c/code\u003e, a per-action budget for how many pixels may differ\nand still pass. An action now passes only when it clears both mean SSIM at\nor above \u003ccode\u003essimThreshold\u003c/code\u003e and differing pixels at or under \u003ccode\u003emaxDiffPixels\u003c/code\u003e.\u003c/p\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003eBreaking default.\u003c/strong\u003e \u003ccode\u003emaxDiffPixels\u003c/code\u003e defaults to \u003ccode\u003e0\u003c/code\u003e, so a run that used\nto pass on SSIM tolerance alone can now report \u003ccode\u003echanged\u003c/code\u003e.\u003c/p\u003e\n\u003ch2\u003e[0.2.2-alpha.1] – 2026-09-01\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003ebrowserArgs\u003c/code\u003e config option; extra command-line flags are now passed\ndirectly through to \u003ccode\u003echromium.launch()\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eThe motivating case is \u003ccode\u003e--force-color-profile=srgb\u003c/code\u003e because without it\nChromium renders through whatever ICC profile the host OS reports, and a\nlaptop and CI container can shift baseline pixels for a reason that has\nnothing to do with what's being tested.\u003c/p\u003e\n\u003cp\u003eIf you omit the field, nothing changes from before.\u003c/p\u003e\n\u003ch2\u003e[0.2.1-alpha.1] – 2026-08-27\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eA \u003ccode\u003eneeds\u003c/code\u003e label that no story \u003ccode\u003eproduces\u003c/code\u003e fails the run when declared in\n\u003ccode\u003eseededLabels\u003c/code\u003e and \u003ccode\u003e\u0026lt;paths.authState\u0026gt;/\u0026lt;label\u0026gt;.json\u003c/code\u003e is on disk\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nschneble/tuffgal/commit/1fec44c48002ad31d9ae0fc3ff89a602e10504f3\"\u003e\u003ccode\u003e1fec44c\u003c/code\u003e\u003c/a\u003e Add a maxDiffPixels gate beside the SSIM gate (\u003ca href=\"https://redirect.github.com/nschneble/tuffgal/issues/51\"\u003e#51\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nschneble/tuffgal/commit/d4e1cbeae1af6a833223163f387518c855b5bbd8\"\u003e\u003ccode\u003ed4e1cbe\u003c/code\u003e\u003c/a\u003e Add browser args config option for Chromium launch flags (\u003ca href=\"https://redirect.github.com/nschneble/tuffgal/issues/49\"\u003e#49\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nschneble/tuffgal/commit/407b30ace0b584d4d954f7547c1b264d269f690d\"\u003e\u003ccode\u003e407b30a\u003c/code\u003e\u003c/a\u003e Bump monocart-coverage-reports from 2.12.12 to 2.13.0 (\u003ca href=\"https://redirect.github.com/nschneble/tuffgal/issues/48\"\u003e#48\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nschneble/tuffgal/commit/f164ddbdd1443c8183d1ef9336b43e4298a4a2d1\"\u003e\u003ccode\u003ef164ddb\u003c/code\u003e\u003c/a\u003e Bump eslint from 10.8.1 to 10.9.1 (\u003ca href=\"https://redirect.github.com/nschneble/tuffgal/issues/47\"\u003e#47\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nschneble/tuffgal/commit/d97c9aa2f3b1627f9d6c25d5c8fbb65bf6dc50f2\"\u003e\u003ccode\u003ed97c9aa\u003c/code\u003e\u003c/a\u003e Split scheduler.ts into planner/executor files (\u003ca href=\"https://redirect.github.com/nschneble/tuffgal/issues/46\"\u003e#46\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nschneble/tuffgal/commit/608af997afc3d41cdf23c9cbbf9378c0e63d1cd0\"\u003e\u003ccode\u003e608af99\u003c/code\u003e\u003c/a\u003e Collapse runScheduledStory's positional params (\u003ca href=\"https://redirect.github.com/nschneble/tuffgal/issues/45\"\u003e#45\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nschneble/tuffgal/commit/5390daa455cf6e234cc2741faf53a9aa4c862f57\"\u003e\u003ccode\u003e5390daa\u003c/code\u003e\u003c/a\u003e Bump tsx from 4.23.8 to 4.23.12 (\u003ca href=\"https://redirect.github.com/nschneble/tuffgal/issues/39\"\u003e#39\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nschneble/tuffgal/commit/a163f1dd45cc9913cd258ab6e4813dff5a79bc76\"\u003e\u003ccode\u003ea163f1d\u003c/code\u003e\u003c/a\u003e Bump typescript-eslint from 8.66.0 to 8.68.0 (\u003ca href=\"https://redirect.github.com/nschneble/tuffgal/issues/38\"\u003e#38\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nschneble/tuffgal/commit/1b0f2558ba3e5b736c70ed4f593bd01797b41026\"\u003e\u003ccode\u003e1b0f255\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003e@​types/node\u003c/code\u003e from 26.1.2 to 26.3.0 (\u003ca href=\"https://redirect.github.com/nschneble/tuffgal/issues/36\"\u003e#36\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nschneble/tuffgal/commit/403c26b2440d8d120798a64ff3d2354ff3ca5b67\"\u003e\u003ccode\u003e403c26b\u003c/code\u003e\u003c/a\u003e Accept a pre-seeded label with no producing story (\u003ca href=\"https://redirect.github.com/nschneble/tuffgal/issues/42\"\u003e#42\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nschneble/tuffgal/compare/v0.2.0-alpha.8...v0.3.0-alpha.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `typescript-eslint` from 8.68.0 to 8.70.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases\"\u003etypescript-eslint's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.70.0\u003c/h2\u003e\n\u003ch2\u003e8.70.0 (2026-09-07)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-generated-empty-object-type] add rule (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12730\"\u003e#12730\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ewebsite:\u003c/strong\u003e generate per-page social preview cards (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12734\"\u003e#12734\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003euse stable release of pnpm 12 (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12808\"\u003e#12808\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate pnpm to 12.3.4 and dedupe Docusaurus packages (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12829\"\u003e#12829\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [member-ordering] don't report fields that read fields declared before them (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12729\"\u003e#12729\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-unnecessary-condition] no false positive on RHS of a nested logical expression (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12728\"\u003e#12728\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-deprecated] report deprecated imported values used in object shorthand properties (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12780\"\u003e#12780\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eproject-service:\u003c/strong\u003e avoid discarded tsserver logs (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12748\"\u003e#12748\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypescript-estree:\u003c/strong\u003e clarify the parserOptions.project error message (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12817\"\u003e#12817\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBarry \u003ca href=\"https://github.com/barry166\"\u003e\u003ccode\u003e@​barry166\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEvyatar Daud \u003ca href=\"https://github.com/StyleShit\"\u003e\u003ccode\u003e@​StyleShit\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJosh Goldberg\u003c/li\u003e\n\u003cli\u003eJosh Goldberg ✨ \u003ca href=\"https://github.com/JoshuaKGoldberg\"\u003e\u003ccode\u003e@​JoshuaKGoldberg\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eKirk Waiblinger \u003ca href=\"https://github.com/kirkwaiblinger\"\u003e\u003ccode\u003e@​kirkwaiblinger\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUlrich Stark \u003ca href=\"https://github.com/ulrichstark\"\u003e\u003ccode\u003e@​ulrichstark\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e송재욱\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003ev8.69.0\u003c/h2\u003e\n\u003ch2\u003e8.69.0 (2026-08-31)\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-misused-promises] add flagUnions option for checkConditionals (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12603\"\u003e#12603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-mixed-enums] use scope analysis instead of type checking for merged namespaces (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12731\"\u003e#12731\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [unified-signatures] compare type parameters by constraint instead of name (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12741\"\u003e#12741\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-meaningless-void-operator] report void on non-call expressions (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12727\"\u003e#12727\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ewebsite:\u003c/strong\u003e respect allowJs playground config (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12744\"\u003e#12744\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAbdu Alim Arlikhozhaev \u003ca href=\"https://github.com/Arlikhozhaev\"\u003e\u003ccode\u003e@​Arlikhozhaev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEvyatar Daud \u003ca href=\"https://github.com/StyleShit\"\u003e\u003ccode\u003e@​StyleShit\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md\"\u003etypescript-eslint's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.70.0 (2026-09-07)\u003c/h2\u003e\n\u003ch3\u003e🩹 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeslint-plugin:\u003c/strong\u003e [no-deprecated] report deprecated imported values used in object shorthand properties (\u003ca href=\"https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12780\"\u003e#12780\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e❤️ Thank You\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUlrich Stark \u003ca href=\"https://github.com/ulrichstark\"\u003e\u003ccode\u003e@​ulrichstark\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.70.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003ch2\u003e8.69.0 (2026-08-31)\u003c/h2\u003e\n\u003cp\u003eThis was a version bump only for typescript-eslint to align it with other projects, there were no code changes.\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.69.0\"\u003eGitHub Releases\u003c/a\u003e for more information.\u003c/p\u003e\n\u003cp\u003eYou can read about our \u003ca href=\"https://typescript-eslint.io/users/versioning\"\u003eversioning strategy\u003c/a\u003e and \u003ca href=\"https://typescript-eslint.io/users/releases\"\u003ereleases\u003c/a\u003e on our website.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/7ee76085c22e923c0036b8e0733a3ca7dfd82b60\"\u003e\u003ccode\u003e7ee7608\u003c/code\u003e\u003c/a\u003e chore(release): publish 8.70.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/4586535ab24d7d5e9b3ba87e4adb8636f9314aca\"\u003e\u003ccode\u003e4586535\u003c/code\u003e\u003c/a\u003e fix(eslint-plugin): [no-deprecated] report deprecated imported values used in...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commit/9a6e546823e5d8f2dc015df2aa66c0230615e209\"\u003e\u003ccode\u003e9a6e546\u003c/code\u003e\u003c/a\u003e chore(release): publish 8.69.0\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.0/packages/typescript-eslint\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pg-boss` from 12.28.0 to 12.30.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/timgit/pg-boss/releases\"\u003epg-boss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e12.30.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cp\u003eSchema version: \u003cstrong\u003e40\u003c/strong\u003e (a migration runs on upgrade — see \u003ca href=\"https://github.com/timgit/pg-boss/blob/HEAD/#upgrading\"\u003eUpgrading\u003c/a\u003e).\u003c/p\u003e\n\u003cp\u003eFetch is now an ordered index walk instead of a sort, and maintenance reports when vacuum has stopped keeping up with the queues. Options \u003ccode\u003epriority\u003c/code\u003e and \u003ccode\u003eorderByCreatedOn\u003c/code\u003e are now deprecated.\u003c/p\u003e\n\u003ch2\u003eHighlights\u003c/h2\u003e\n\u003ch3\u003eThe fetch index matches the fetch\u003c/h3\u003e\n\u003cp\u003eThe fetch orders by \u003ccode\u003epriority desc, created_on\u003c/code\u003e, but the index led with \u003ccode\u003estart_after\u003c/code\u003e, so every poll read all eligible rows and sorted them. On a 500k-row job table that is a \u003ccode\u003etop-N heapsort\u003c/code\u003e over 5,257 buffers:\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eLimit (actual time=44.880..47.794 rows=1)\r\n  Buffers: shared hit=5257\r\n  -\u0026gt;  Sort  Sort Key: priority DESC, created_on\r\n        Sort Method: top-N heapsort\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eThe index now leads with the sort keys and keeps \u003ccode\u003estart_after\u003c/code\u003e as a trailing key column, so the same fetch is an ordered walk that stops at the first row:\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eLimit (actual time=0.079..0.080 rows=1)\r\n  Buffers: shared hit=16\r\n  -\u0026gt;  Index Scan using job_common_i11\r\n        Index Cond: ((name = 'q') AND (start_after \u0026lt; now()))\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003e\u003cstrong\u003e47.8 ms → 0.11 ms\u003c/strong\u003e, 5,257 buffers → 16. Cost is 27% more index (15 MB → 19 MB at 500k rows).\u003c/p\u003e\n\u003ch3\u003e\u003ccode\u003epriority\u003c/code\u003e and \u003ccode\u003eorderByCreatedOn\u003c/code\u003e are deprecated\u003c/h3\u003e\n\u003cp\u003eBoth of these options were created to optimize perf, based on the previous index. As of this release, they are \u003cstrong\u003eignored\u003c/strong\u003e  and will be rejected in the next major. Jobs are always fetched in priority and creation order.\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// no longer changes anything, and emits a DeprecationWarning once per option per instance\r\nawait boss.fetch('my-queue', { priority: false })\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cpre\u003e\u003ccode\u003e(node:1234) [PGBOSS_DEP_FETCH_SORT] DeprecationWarning: priority: false is deprecated and now ignored\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eRun with \u003ccode\u003e--trace-deprecation\u003c/code\u003e to find the call site, or \u003ccode\u003e--throw-deprecation\u003c/code\u003e to fail a build on it. It is a Node deprecation rather than a pg-boss \u003ccode\u003ewarning\u003c/code\u003e event, which stays reserved for database and queue health.\u003c/p\u003e\n\u003cp\u003eIf you set \u003ccode\u003epriority: false\u003c/code\u003e for throughput, remove it: it was measured roughly \u003cstrong\u003e180x slower\u003c/strong\u003e than the default, since no index leads with \u003ccode\u003ecreated_on\u003c/code\u003e.\u003c/p\u003e\n\u003ch3\u003eVacuum health is monitored\u003c/h3\u003e\n\u003cp\u003eA primary failure pattern of Postgres-hosted queues is a busy server that is unable to perform maintenance via autovacuum.  Until now pg-boss reported a symptom via a warning about a queue's backlog, but the remedy for this wasn't clear.  One easy solution to this warning is to increase workers, concurrency, or batch size.  If the actual cause was related to a busy server, adding more polling workers or increasing busyness could instead make this issue worse, or at best not improve anything.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timgit/pg-boss/commit/180a54b65ce492bf990e524cda2d38b19f0df3f4\"\u003e\u003ccode\u003e180a54b\u003c/code\u003e\u003c/a\u003e Job fetch index tuning and vacuum monitoring (\u003ca href=\"https://redirect.github.com/timgit/pg-boss/issues/885\"\u003e#885\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timgit/pg-boss/commit/20fdc8aeed2fb6294eb03a71f319d1eee4ce3ba5\"\u003e\u003ccode\u003e20fdc8a\u003c/code\u003e\u003c/a\u003e added reindex to maintenance (\u003ca href=\"https://redirect.github.com/timgit/pg-boss/issues/883\"\u003e#883\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timgit/pg-boss/commit/4a1d22bf31cacb42397c4b60184ff9f000f13d89\"\u003e\u003ccode\u003e4a1d22b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/timgit/pg-boss/issues/882\"\u003e#882\u003c/a\u003e from timgit/dependabot/github_actions/actions/checkou...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timgit/pg-boss/commit/ac393d655415d31a3309d19d5847e7f04510b71d\"\u003e\u003ccode\u003eac393d6\u003c/code\u003e\u003c/a\u003e Merge branch 'master' into dependabot/github_actions/actions/checkout-7.0.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timgit/pg-boss/commit/85aff3d672f1523a84c28f0cf0c31869806d1581\"\u003e\u003ccode\u003e85aff3d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/timgit/pg-boss/issues/881\"\u003e#881\u003c/a\u003e from timgit/dependabot/github_actions/actions/setup-n...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timgit/pg-boss/commit/e80d368f23b21ddbed066c1f1085182052d506c0\"\u003e\u003ccode\u003ee80d368\u003c/code\u003e\u003c/a\u003e ci: bump actions/checkout from 5.1.0 to 7.0.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timgit/pg-boss/commit/6a1e10805e6158f4df5205f678d83f876ad0c6f6\"\u003e\u003ccode\u003e6a1e108\u003c/code\u003e\u003c/a\u003e ci: bump actions/setup-node from 5.0.0 to 7.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timgit/pg-boss/commit/78089bbd51cce5e70282f6e5f9a9d937856ab414\"\u003e\u003ccode\u003e78089bb\u003c/code\u003e\u003c/a\u003e deps and versioning\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timgit/pg-boss/commit/749af4fe18e66c76a0121aff462ad0410f020005\"\u003e\u003ccode\u003e749af4f\u003c/code\u003e\u003c/a\u003e raise error during publish if any downstream queues throw\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/timgit/pg-boss/commit/e1918c0280325b0aa3f4c26910d379dfe96af364\"\u003e\u003ccode\u003ee1918c0\u003c/code\u003e\u003c/a\u003e update sponsors page for new tiers and logo sizes\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/timgit/pg-boss/compare/12.28.0...12.30.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `undici` from 8.10.0 to 8.10.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm\"\u003eGHSA-vp8m-p9jh-q5pm\u003c/a\u003e: cache and deduplication interceptors could use caller-controlled request metadata instead of the authoritative dispatcher origin, enabling cross-origin cache poisoning and data disclosure. Undici now derives interceptor identities from the dispatcher origin and bypasses origin-dependent interceptors when no authoritative origin exists. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/caf6194d3dae989b731ed87ab85f182befe5eb80\"\u003ecaf6194d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e8f5868fb\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e66e12816\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6\"\u003e4411a238\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/662d0ea671fe64139e79533c913fce412765e1d7\"\u003e662d0ea6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003ecb75bbb3\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e7aac7f12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003ee905b5b8\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e2be07bf9\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e6d583124\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e0160a719\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps-dev): bump undici from 6.27.0 to 6.28.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5653\"\u003enodejs/undici#5653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump jest from 30.4.2 to 30.5.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5750\"\u003enodejs/undici#5750\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/analyze from 4.37.3 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5752\"\u003enodejs/undici#5752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5754\"\u003enodejs/undici#5754\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(h2): cover stream reset with NGHTTP2_INTERNAL_ERROR by \u003ca href=\"https://github.com/zeexzeex\"\u003e\u003ccode\u003e@​zeexzeex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5725\"\u003enodejs/undici#5725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): reject invalid resumed responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5724\"\u003enodejs/undici#5724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: make stale-while-revalidate cache update test deterministic by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5722\"\u003enodejs/undici#5722\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid unbounded recursion in Set-Cookie attribute parser by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5757\"\u003enodejs/undici#5757\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: honor SOCKS5 connection timeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5733\"\u003enodejs/undici#5733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(eventsource): validate Last-Event-ID on reconnect by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5746\"\u003enodejs/undici#5746\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid duplicate release attempts by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5745\"\u003enodejs/undici#5745\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(cache): refetch when 304 adds vary fields by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5732\"\u003enodejs/undici#5732\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etypes: expose PendingInterceptor and PendingInterceptorsFormatter on the MockAgent namespace by \u003ca href=\"https://github.com/RaphaelFakhri\"\u003e\u003ccode\u003e@​RaphaelFakhri\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5721\"\u003enodejs/undici#5721\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(codeql): align CodeQL action versions to v4.37.9 by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5759\"\u003enodejs/undici#5759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5760\"\u003enodejs/undici#5760\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(proxy-agent): guard Proxy-Authorization in iterable header containers by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5758\"\u003enodejs/undici#5758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: name the parameters these two blocks describe by \u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): fail the connection on a non-200 h2 extended CONNECT response by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(node-fetch): re-enable the set-cookie header combining test by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5730\"\u003enodejs/undici#5730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward rawHeaders writes through RetryController by \u003ca href=\"https://github.com/official-burak\"\u003e\u003ccode\u003e@​official-burak\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5727\"\u003enodejs/undici#5727\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5738\"\u003enodejs/undici#5738\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/5e541e0b9df7563e5766bbd469fbfe383d9ae6ca\"\u003e\u003ccode\u003e5e541e0\u003c/code\u003e\u003c/a\u003e Bumped v8.10.2 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5771\"\u003e#5771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/eb04cc39954e63e9b46bdf824e6efad9fff2e7b5\"\u003e\u003ccode\u003eeb04cc3\u003c/code\u003e\u003c/a\u003e fix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5738\"\u003e#5738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003e\u003ccode\u003ee905b5b\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e\u003ccode\u003e0160a71\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e\u003ccode\u003e66e1281\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e\u003ccode\u003e7aac7f1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003e\u003ccode\u003ecb75bbb\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e\u003ccode\u003e6d58312\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e\u003ccode\u003e8f5868f\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e\u003ccode\u003e2be07bf\u003c/code\u003e\u003c/a\u003e fix(cache): reject unsafe method response caching\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v8.10.0...v8.10.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@eslint/eslintrc` from 3.3.6 to 3.3.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/eslint/eslintrc/releases\"\u003e@​eslint/eslintrc's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eeslintrc: v3.3.7\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/eslint/eslintrc/compare/eslintrc-v3.3.6...eslintrc-v3.3.7\"\u003e3.3.7\u003c/a\u003e (2026-09-01)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump js-yaml to 4.3.1 (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/239\"\u003e#239\u003c/a\u003e) (\u003ca href=\"https://github.com/eslint/eslintrc/commit/f27e7c94e6d9438bd51cb483d8d5da768e1cc0b9\"\u003ef27e7c9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate js-yaml to 4.3.2 to address security vulnerability (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/243\"\u003e#243\u003c/a\u003e) (\u003ca href=\"https://github.com/eslint/eslintrc/commit/bb0d97a338937b88fa99d6bbc0a904e34eda3d5f\"\u003ebb0d97a\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/eslint/eslintrc/blob/main/CHANGELOG.md\"\u003e@​eslint/eslintrc's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/eslint/eslintrc/compare/eslintrc-v3.3.6...eslintrc-v3.3.7\"\u003e3.3.7\u003c/a\u003e (2026-09-01)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump js-yaml to 4.3.1 (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/239\"\u003e#239\u003c/a\u003e) (\u003ca href=\"https://github.com/eslint/eslintrc/commit/f27e7c94e6d9438bd51cb483d8d5da768e1cc0b9\"\u003ef27e7c9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate js-yaml to 4.3.2 to address security vulnerability (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/243\"\u003e#243\u003c/a\u003e) (\u003ca href=\"https://github.com/eslint/eslintrc/commit/bb0d97a338937b88fa99d6bbc0a904e34eda3d5f\"\u003ebb0d97a\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/7943fa6dd55b236a539f658b88c763a4f9fbb38d\"\u003e\u003ccode\u003e7943fa6\u003c/code\u003e\u003c/a\u003e chore: release 3.3.7 🚀 (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/240\"\u003e#240\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/bb0d97a338937b88fa99d6bbc0a904e34eda3d5f\"\u003e\u003ccode\u003ebb0d97a\u003c/code\u003e\u003c/a\u003e fix: update js-yaml to 4.3.2 to address security vulnerability (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/243\"\u003e#243\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/5b4abc9c74dd92b9eb782ca81d559a88906509e9\"\u003e\u003ccode\u003e5b4abc9\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/f27e7c94e6d9438bd51cb483d8d5da768e1cc0b9\"\u003e\u003ccode\u003ef27e7c9\u003c/code\u003e\u003c/a\u003e fix: Bump js-yaml to 4.3.1 (\u003ca href=\"https://redirect.github.com/eslint/eslintrc/issues/239\"\u003e#239\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/b75e1d2425deebfd1ec7f952dda7d0c4f4d65d5c\"\u003e\u003ccode\u003eb75e1d2\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/302c13310e148268f990df3edbfd10dab44f2678\"\u003e\u003ccode\u003e302c133\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/e62e7661b0d9063e42a37af5551bbcb1897e188d\"\u003e\u003ccode\u003ee62e766\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/cf27f9fd8f775d94500f2569a5bfb6a7de9cdb33\"\u003e\u003ccode\u003ecf27f9f\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/c7f4cdf1ffa86e28b5b8bf09f9e8bc7fadbf87ff\"\u003e\u003ccode\u003ec7f4cdf\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eslint/eslintrc/commit/3319822ac925e018c47fcafa351b20ea0bf6eeff\"\u003e\u003ccode\u003e3319822\u003c/code\u003e\u003c/a\u003e docs: Update README sponsors\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/eslint/eslintrc/compare/eslintrc-v3.3.6...eslintrc-v3.3.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@types/node` from 26.4.0 to 26.5.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `globals` from 17.11.0 to 17.12.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/sindresorhus/globals/releases\"\u003eglobals's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev17.12.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate globals (2026-09-01) (\u003ca href=\"https://redirect.github.com/sindresorhus/globals/issues/353\"\u003e#353\u003c/a\u003e)  50a2119\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003e__webpack_layer__\u003c/code\u003e global (\u003ca href=\"https://redirect.github.com/sindresorhus/globals/issues/351\"\u003e#351\u003c/a\u003e)  779a11a\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/sindresorhus/globals/compare/v17.11.0...v17.12.0\"\u003ehttps://github.com/sindresorhus/globals/compare/v17.11.0...v17.12.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sindresorhus/globals/commit/98008c3200fc994ef3c074699e8ce0c9691fd071\"\u003e\u003ccode\u003e98008c3\u003c/code\u003e\u003c/a\u003e 17.12.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sindresorhus/globals/commit/50a2119777b37fef046c2e0bc24bca0bd9feb0be\"\u003e\u003ccode\u003e50a2119\u003c/code\u003e\u003c/a\u003e Update globals (2026-09-01) (\u003ca href=\"https://redirect.github.com/sindresorhus/globals/issues/353\"\u003e#353\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sindresorhus/globals/commit/779a11a345f072a7fbb76b8b92458987a9a8fa38\"\u003e\u003ccode\u003e779a11a\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003e__webpack_layer__\u003c/code\u003e global (\u003ca href=\"https://redirect.github.com/sindresorhus/globals/issues/351\"\u003e#351\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/sindresorhus/globals/compare/v17.11.0...v17.12.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `jest` from 30.4.2 to 30.5.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jestjs/jest/releases\"\u003ejest's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev30.5.1\u003c/h2\u003e\n\u003ch2\u003eFixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e[jest-config]\u003c/code\u003e Don't warn about global-only options in the config that supplies the global config - the root config a project resolves to, or the first entry of \u003ccode\u003e--projects\u003c/code\u003e when no root config is passed (\u003ca href=\"https://redirect.github.com/jestjs/jest/pull/16411\"\u003e#16411\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e[jest-config, jest-types]\u003c/code\u003e Stop accepting \u003ccode\u003ereporters\u003c/code\u003e, \u003ccode\u003ecoverageReporters\u003c/code\u003e, \u003ccode\u003eworkerIdleMemoryLimit\u003c/code\u003e, \u003ccode\u003ecwd\u003c/code\u003e and \u003ccode\u003erunnerOptions\u003c/code\u003e in a project config - they were silently ignored, and now warn like the other global-only options (\u003ca href=\"https://redirect.github.com/jestjs/jest/pull/16411\"\u003e#16411\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e[jest-config, jest-validate]\u003c/code\u003e Warn about \u003ccode\u003emaxWorkers\u003c/code\u003e and \u003ccode\u003ecoverageThreshold\u003c/code\u003e in a project config instead of dropping them without a word (\u003ca href=\"https://redirect.github.com/jestjs/jest/pull/16411\"\u003e#16411\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e[jest-resolve]\u003c/code\u003e Match \u003ccode\u003emoduleNameMapper\u003c/code\u003e patterns against the specifier as written again (reverting \u003ca href=\"https://redirect.github.com/jestjs/jest/pull/16390\"\u003e#16390\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/jestjs/jest/pull/16417\"\u003e#16417\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e[jest-runtime]\u003c/code\u003e Resolve package \u003ccode\u003eimports\u003c/code\u003e specifiers like \u003ccode\u003e#dep\u003c/code\u003e under ESM again (\u003ca href=\"https://redirect.github.com/jestjs/jest/pull/16413\"\u003e#16413\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eChore \u0026amp; Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e[jest-util]\u003c/code\u003e Name the \u003ccode\u003etestEnvironmentOptions.globalsCleanup\u003c/code\u003e option and link the docs from the \u003ccode\u003eJEST-01\u003c/code\u003e deprecation warning, and document the option's modes (\u003ca href=\"https://redirect.github.com/jestjs/jest/pull/16404\"\u003e#16404\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/HuzaifaChaudary\"\u003e\u003ccode\u003e@​HuzaifaChaudary\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/jestjs/jest/pull/16413\"\u003ejestjs/jest#16413\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/jestjs/jest/compare/v30.5.0...v30.5.1\"\u003ehttps://github.com/jestjs/jest/compare/v30.5.0...v30.5.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev30.5.0\u003c/h2\u003e\n\u003cp\u003eOn a personal note: King Harald V of Norway passed away this morning. He ascended the throne 35 years ago, two months before I was born. This release is dedicated to his memory. Hvil i fred 🇳🇴\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003eThis is a big release. It touches \u003ccode\u003ejest-runtime\u003c/code\u003e, \u003ccode\u003ejest-resolve\u003c/code\u003e and \u003ccode\u003ejest-haste-map\u003c/code\u003e in many places, and with this many changes there might be regressions 😬. If your suite behaves differently after upgrading, please \u003ca href=\"https://github.com/jestjs/jest/issues\"\u003eopen an issue\u003c/a\u003e.\u003c/p\u003e\n\u003ch1\u003eHighlights\u003c/h1\u003e\n\u003ch2\u003e\u003ccode\u003ewhenCalledWith\u003c/code\u003e\u003c/h2\u003e\n\u003cp\u003eMock functions can now configure return values per argument list, contributed by \u003ca href=\"https://github.com/timkindberg\"\u003e\u003ccode\u003e@​timkindberg\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/jestjs/jest/pull/16053\"\u003e#16053\u003c/a\u003e):\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003econst fn = jest.fn();\r\nfn.whenCalledWith('apple').mockReturnValue('red');\r\nfn.w...\n\n_Description has been truncated_","html_url":"https://github.com/nschneble/linklater/pull/177","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/nschneble%2Flinklater/issues/177","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/177/packages"}},{"old_version":"8.10.0","new_version":"8.10.2","update_type":"patch","path":null,"pr_created_at":"2026-09-11T17:14:29.000Z","version_change":"8.10.0 → 8.10.2","issue":{"uuid":"5427082744","node_id":"PR_kwDOPVYLUM8AAAABDLVD3g","number":1264,"state":"open","title":"chore(deps): bump undici from 8.10.0 to 8.10.2","user":"dependabot[bot]","labels":["dependencies","javascript","agent:clean"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T17:14:29.000Z","updated_at":"2026-09-11T17:15:58.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"undici","old_version":"8.10.0","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 8.10.0 to 8.10.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm\"\u003eGHSA-vp8m-p9jh-q5pm\u003c/a\u003e: cache and deduplication interceptors could use caller-controlled request metadata instead of the authoritative dispatcher origin, enabling cross-origin cache poisoning and data disclosure. Undici now derives interceptor identities from the dispatcher origin and bypasses origin-dependent interceptors when no authoritative origin exists. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/caf6194d3dae989b731ed87ab85f182befe5eb80\"\u003ecaf6194d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e8f5868fb\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e66e12816\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6\"\u003e4411a238\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/662d0ea671fe64139e79533c913fce412765e1d7\"\u003e662d0ea6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003ecb75bbb3\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e7aac7f12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003ee905b5b8\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e2be07bf9\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e6d583124\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e0160a719\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps-dev): bump undici from 6.27.0 to 6.28.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5653\"\u003enodejs/undici#5653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump jest from 30.4.2 to 30.5.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5750\"\u003enodejs/undici#5750\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/analyze from 4.37.3 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5752\"\u003enodejs/undici#5752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5754\"\u003enodejs/undici#5754\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(h2): cover stream reset with NGHTTP2_INTERNAL_ERROR by \u003ca href=\"https://github.com/zeexzeex\"\u003e\u003ccode\u003e@​zeexzeex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5725\"\u003enodejs/undici#5725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): reject invalid resumed responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5724\"\u003enodejs/undici#5724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: make stale-while-revalidate cache update test deterministic by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5722\"\u003enodejs/undici#5722\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid unbounded recursion in Set-Cookie attribute parser by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5757\"\u003enodejs/undici#5757\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: honor SOCKS5 connection timeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5733\"\u003enodejs/undici#5733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(eventsource): validate Last-Event-ID on reconnect by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5746\"\u003enodejs/undici#5746\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid duplicate release attempts by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5745\"\u003enodejs/undici#5745\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(cache): refetch when 304 adds vary fields by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5732\"\u003enodejs/undici#5732\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etypes: expose PendingInterceptor and PendingInterceptorsFormatter on the MockAgent namespace by \u003ca href=\"https://github.com/RaphaelFakhri\"\u003e\u003ccode\u003e@​RaphaelFakhri\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5721\"\u003enodejs/undici#5721\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(codeql): align CodeQL action versions to v4.37.9 by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5759\"\u003enodejs/undici#5759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5760\"\u003enodejs/undici#5760\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(proxy-agent): guard Proxy-Authorization in iterable header containers by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5758\"\u003enodejs/undici#5758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: name the parameters these two blocks describe by \u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): fail the connection on a non-200 h2 extended CONNECT response by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(node-fetch): re-enable the set-cookie header combining test by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5730\"\u003enodejs/undici#5730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward rawHeaders writes through RetryController by \u003ca href=\"https://github.com/official-burak\"\u003e\u003ccode\u003e@​official-burak\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5727\"\u003enodejs/undici#5727\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5738\"\u003enodejs/undici#5738\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/5e541e0b9df7563e5766bbd469fbfe383d9ae6ca\"\u003e\u003ccode\u003e5e541e0\u003c/code\u003e\u003c/a\u003e Bumped v8.10.2 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5771\"\u003e#5771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/eb04cc39954e63e9b46bdf824e6efad9fff2e7b5\"\u003e\u003ccode\u003eeb04cc3\u003c/code\u003e\u003c/a\u003e fix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5738\"\u003e#5738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003e\u003ccode\u003ee905b5b\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e\u003ccode\u003e0160a71\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e\u003ccode\u003e66e1281\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e\u003ccode\u003e7aac7f1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003e\u003ccode\u003ecb75bbb\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e\u003ccode\u003e6d58312\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e\u003ccode\u003e8f5868f\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e\u003ccode\u003e2be07bf\u003c/code\u003e\u003c/a\u003e fix(cache): reject unsafe method response caching\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v8.10.0...v8.10.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=8.10.0\u0026new-version=8.10.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/Nano-Collective/nanocoder/pull/1264","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Nano-Collective%2Fnanocoder/issues/1264","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1264/packages"}},{"old_version":"7.28.0","new_version":"8.10.2","update_type":"major","path":null,"pr_created_at":"2026-09-11T16:29:28.000Z","version_change":"7.28.0 → 8.10.2","issue":{"uuid":"5426665380","node_id":"PR_kwDOPbQ_jc8AAAABDK_aVQ","number":1308,"state":"open","title":"chore(deps): bump undici from 7.28.0 to 8.10.2","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T16:29:28.000Z","updated_at":"2026-09-11T16:31:10.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"undici","old_version":"7.28.0","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 7.28.0 to 8.10.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm\"\u003eGHSA-vp8m-p9jh-q5pm\u003c/a\u003e: cache and deduplication interceptors could use caller-controlled request metadata instead of the authoritative dispatcher origin, enabling cross-origin cache poisoning and data disclosure. Undici now derives interceptor identities from the dispatcher origin and bypasses origin-dependent interceptors when no authoritative origin exists. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/caf6194d3dae989b731ed87ab85f182befe5eb80\"\u003ecaf6194d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e8f5868fb\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e66e12816\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6\"\u003e4411a238\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/662d0ea671fe64139e79533c913fce412765e1d7\"\u003e662d0ea6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003ecb75bbb3\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e7aac7f12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003ee905b5b8\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e2be07bf9\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e6d583124\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e0160a719\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps-dev): bump undici from 6.27.0 to 6.28.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5653\"\u003enodejs/undici#5653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump jest from 30.4.2 to 30.5.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5750\"\u003enodejs/undici#5750\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/analyze from 4.37.3 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5752\"\u003enodejs/undici#5752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5754\"\u003enodejs/undici#5754\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(h2): cover stream reset with NGHTTP2_INTERNAL_ERROR by \u003ca href=\"https://github.com/zeexzeex\"\u003e\u003ccode\u003e@​zeexzeex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5725\"\u003enodejs/undici#5725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): reject invalid resumed responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5724\"\u003enodejs/undici#5724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: make stale-while-revalidate cache update test deterministic by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5722\"\u003enodejs/undici#5722\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid unbounded recursion in Set-Cookie attribute parser by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5757\"\u003enodejs/undici#5757\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: honor SOCKS5 connection timeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5733\"\u003enodejs/undici#5733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(eventsource): validate Last-Event-ID on reconnect by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5746\"\u003enodejs/undici#5746\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid duplicate release attempts by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5745\"\u003enodejs/undici#5745\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(cache): refetch when 304 adds vary fields by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5732\"\u003enodejs/undici#5732\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etypes: expose PendingInterceptor and PendingInterceptorsFormatter on the MockAgent namespace by \u003ca href=\"https://github.com/RaphaelFakhri\"\u003e\u003ccode\u003e@​RaphaelFakhri\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5721\"\u003enodejs/undici#5721\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(codeql): align CodeQL action versions to v4.37.9 by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5759\"\u003enodejs/undici#5759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5760\"\u003enodejs/undici#5760\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(proxy-agent): guard Proxy-Authorization in iterable header containers by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5758\"\u003enodejs/undici#5758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: name the parameters these two blocks describe by \u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): fail the connection on a non-200 h2 extended CONNECT response by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(node-fetch): re-enable the set-cookie header combining test by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5730\"\u003enodejs/undici#5730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward rawHeaders writes through RetryController by \u003ca href=\"https://github.com/official-burak\"\u003e\u003ccode\u003e@​official-burak\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5727\"\u003enodejs/undici#5727\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5738\"\u003enodejs/undici#5738\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/5e541e0b9df7563e5766bbd469fbfe383d9ae6ca\"\u003e\u003ccode\u003e5e541e0\u003c/code\u003e\u003c/a\u003e Bumped v8.10.2 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5771\"\u003e#5771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/eb04cc39954e63e9b46bdf824e6efad9fff2e7b5\"\u003e\u003ccode\u003eeb04cc3\u003c/code\u003e\u003c/a\u003e fix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5738\"\u003e#5738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003e\u003ccode\u003ee905b5b\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e\u003ccode\u003e0160a71\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e\u003ccode\u003e66e1281\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e\u003ccode\u003e7aac7f1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003e\u003ccode\u003ecb75bbb\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e\u003ccode\u003e6d58312\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e\u003ccode\u003e8f5868f\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e\u003ccode\u003e2be07bf\u003c/code\u003e\u003c/a\u003e fix(cache): reject unsafe method response caching\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v8.10.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=7.28.0\u0026new-version=8.10.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/hackerai-tech/hackerai/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/hackerai-tech/hackerai/pull/1308","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/hackerai-tech%2Fhackerai/issues/1308","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1308/packages"}},{"old_version":"7.29.0","new_version":"7.29.1","update_type":"patch","path":null,"pr_created_at":"2026-09-11T16:05:30.000Z","version_change":"7.29.0 → 7.29.1","issue":{"uuid":"5426437776","node_id":"PR_kwDOQzBxXc8AAAABDKzhQQ","number":3686,"state":"open","title":"chore(deps): bump the production-minor-and-patch group across 1 directory with 15 updates","user":"dependabot[bot]","labels":["dependencies","javascript","P2","status: ⏳ waiting on author","merge-risk: 🚨 automation","rating: 🦐 gold shrimp","needs-cli-release"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T16:05:30.000Z","updated_at":"2026-09-11T16:10:15.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"production-minor-and-patch","update_count":15,"packages":[{"name":"@openclaw/plugin-inspector","old_version":"0.3.23","new_version":"0.3.24","repository_url":"https://github.com/openclaw/plugin-inspector"},{"name":"@tanstack/react-router","old_version":"1.170.29","new_version":"1.170.33","repository_url":"https://github.com/TanStack/router"},{"name":"@tanstack/react-start","old_version":"1.168.46","new_version":"1.168.50","repository_url":"https://github.com/TanStack/router"},{"name":"@vercel/oidc","old_version":"3.8.4","new_version":"3.8.5","repository_url":"https://github.com/vercel/vercel"},{"name":"convex","old_version":"1.44.0","new_version":"1.45.0","repository_url":"https://github.com/get-convex/convex-backend"},{"name":"convex-helpers","old_version":"0.1.123","new_version":"0.1.124","repository_url":"https://github.com/get-convex/convex-helpers"},{"name":"ignore","old_version":"7.0.6","new_version":"7.0.9","repository_url":"https://github.com/kaelzhang/node-ignore"},{"name":"jose","old_version":"6.2.9","new_version":"6.2.12","repository_url":"https://github.com/panva/jose"},{"name":"lucide-react","old_version":"1.31.0","new_version":"1.43.0","repository_url":"https://github.com/lucide-icons/lucide"},{"name":"mermaid","old_version":"11.16.1","new_version":"11.17.2","repository_url":"https://github.com/mermaid-js/mermaid"},{"name":"resend","old_version":"6.20.0","new_version":"6.26.0","repository_url":"https://github.com/resend/resend-node"},{"name":"zod","old_version":"4.4.3","new_version":"4.5.4","repository_url":"https://github.com/colinhacks/zod"},{"name":"undici","old_version":"7.29.0","new_version":"7.29.1","repository_url":"https://github.com/nodejs/undici"},{"name":"@clack/prompts","old_version":"1.7.0","new_version":"1.8.0","repository_url":"https://github.com/bombshell-dev/clack"},{"name":"p-retry","old_version":"8.0.0","new_version":"8.0.1","repository_url":"https://github.com/sindresorhus/p-retry"}],"path":null,"ecosystem":"npm"},"body":"Bumps the production-minor-and-patch group with 15 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@openclaw/plugin-inspector](https://github.com/openclaw/plugin-inspector) | `0.3.23` | `0.3.24` |\n| [@tanstack/react-router](https://github.com/TanStack/router/tree/HEAD/packages/react-router) | `1.170.29` | `1.170.33` |\n| [@tanstack/react-start](https://github.com/TanStack/router/tree/HEAD/packages/react-start) | `1.168.46` | `1.168.50` |\n| [@vercel/oidc](https://github.com/vercel/vercel/tree/HEAD/packages/oidc) | `3.8.4` | `3.8.5` |\n| [convex](https://github.com/get-convex/convex-backend/tree/HEAD/npm-packages/convex) | `1.44.0` | `1.45.0` |\n| [convex-helpers](https://github.com/get-convex/convex-helpers/tree/HEAD/packages/convex-helpers) | `0.1.123` | `0.1.124` |\n| [ignore](https://github.com/kaelzhang/node-ignore) | `7.0.6` | `7.0.9` |\n| [jose](https://github.com/panva/jose) | `6.2.9` | `6.2.12` |\n| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.31.0` | `1.43.0` |\n| [mermaid](https://github.com/mermaid-js/mermaid) | `11.16.1` | `11.17.2` |\n| [resend](https://github.com/resend/resend-node) | `6.20.0` | `6.26.0` |\n| [zod](https://github.com/colinhacks/zod) | `4.4.3` | `4.5.4` |\n| [undici](https://github.com/nodejs/undici) | `7.29.0` | `7.29.1` |\n| [@clack/prompts](https://github.com/bombshell-dev/clack/tree/HEAD/packages/prompts) | `1.7.0` | `1.8.0` |\n| [p-retry](https://github.com/sindresorhus/p-retry) | `8.0.0` | `8.0.1` |\n\n\nUpdates `@openclaw/plugin-inspector` from 0.3.23 to 0.3.24\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/openclaw/plugin-inspector/releases\"\u003e@​openclaw/plugin-inspector's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eplugin-inspector v0.3.24\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRecognize compiled CommonJS plugin factory calls when checking expected channel registrations, preserving source references and excluding factory values passed to wrappers.\u003c/li\u003e\n\u003cli\u003eClassify widget presenters as metadata-only synthetic probes without invoking presentation callbacks.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVerification\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/@openclaw/plugin-inspector/v/0.3.24\"\u003enpm package 0.3.24\u003c/a\u003e · \u003ca href=\"https://registry.npmjs.org/@openclaw/plugin-inspector/-/plugin-inspector-0.3.24.tgz\"\u003eregistry tarball\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openclaw/plugin-inspector/actions/runs/33412907740\"\u003eSuccessful release workflow\u003c/a\u003e, source \u003ccode\u003e92db8c57e1d5544c522c7c882a33be1ad4e253b9\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eRegistry signatures and provenance verified for this package, tag, workflow, source commit, and run attempt. The complete uncompressed package archive matches the locally tested candidate.\u003c/li\u003e\n\u003cli\u003eTarball SHA-256: \u003ccode\u003e292232b5c2aa34a73ef110333a14240ec07b53a730be1d2d62cb4c76441e9404\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eIntegrity: \u003ccode\u003esha512-g74+lsc3vSinAKbaqlsSvsaWvzkFv71ZVWOzXp4uFDisR1g9fiv/HvoKQI3uenlV0aJr/oD+FZukTs/jyXlr/A==\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/openclaw/plugin-inspector/blob/main/CHANGELOG.md\"\u003e@​openclaw/plugin-inspector's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.3.24 - 2026-08-31\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRecognize compiled CommonJS plugin factory calls when checking expected channel registrations, preserving source references and excluding factory values passed to wrappers.\u003c/li\u003e\n\u003cli\u003eClassify widget presenters as metadata-only synthetic probes without invoking presentation callbacks.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openclaw/plugin-inspector/commit/92db8c57e1d5544c522c7c882a33be1ad4e253b9\"\u003e\u003ccode\u003e92db8c5\u003c/code\u003e\u003c/a\u003e chore: prepare plugin-inspector 0.3.24 (\u003ca href=\"https://redirect.github.com/openclaw/plugin-inspector/issues/67\"\u003e#67\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openclaw/plugin-inspector/commit/2c7629c625667f9939a811db0f6cd83db16f2121\"\u003e\u003ccode\u003e2c7629c\u003c/code\u003e\u003c/a\u003e fix: recognize compiled factories and classify widget presenters (\u003ca href=\"https://redirect.github.com/openclaw/plugin-inspector/issues/66\"\u003e#66\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openclaw/plugin-inspector/commit/1bc30801caa74d8cab760eb62638098c9d9402a7\"\u003e\u003ccode\u003e1bc3080\u003c/code\u003e\u003c/a\u003e chore(deps): refresh Crabbox pnpm to 12.1.0 (\u003ca href=\"https://redirect.github.com/openclaw/plugin-inspector/issues/65\"\u003e#65\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/openclaw/plugin-inspector/compare/v0.3.23...v0.3.24\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@tanstack/react-router` from 1.170.29 to 1.170.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/TanStack/router/releases\"\u003e@​tanstack/react-router's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​tanstack/react-router\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.33\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8165\"\u003e#8165\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/2f20c00224c5ba63467551914e0c37012588c4c2\"\u003e\u003ccode\u003e2f20c00\u003c/code\u003e\u003c/a\u003e - Exclude structural descendants below error and not-found boundaries from route lifecycle callbacks. Preserve lifecycle membership through invalidation, hydration, background reloads, and superseded navigation publication.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8209\"\u003e#8209\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/28a5e4504e4ea5cb1480667a4bea2588a53e110f\"\u003e\u003ccode\u003e28a5e45\u003c/code\u003e\u003c/a\u003e - Preserve falsy thrown values in React and Vue error boundaries. Type React and Vue boundary error components and \u003ccode\u003eonCatch\u003c/code\u003e callbacks as \u003ccode\u003eunknown\u003c/code\u003e. Solid boundary errors remain typed as \u003ccode\u003eError\u003c/code\u003e; SSR now wraps non-\u003ccode\u003eError\u003c/code\u003e loader errors to match Solid’s native boundary behavior, preserving the original value in \u003ccode\u003ecause\u003c/code\u003e. Router state and loader \u003ccode\u003eonError\u003c/code\u003e values are unchanged.\u003c/p\u003e\n\u003cp\u003eWhen upgrading React or Vue, narrow boundary errors (for example, with \u003ccode\u003eerror instanceof Error\u003c/code\u003e) before reading \u003ccode\u003emessage\u003c/code\u003e or \u003ccode\u003estack\u003c/code\u003e. \u003ccode\u003eErrorComponentProps\u0026lt;TError\u0026gt;\u003c/code\u003e remains available for values narrowed to a specific error type. Route \u003ccode\u003eonError\u003c/code\u003e types are unchanged.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8161\"\u003e#8161\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/f0b5eda544606686a8a8d675a686ca1366428b96\"\u003e\u003ccode\u003ef0b5eda\u003c/code\u003e\u003c/a\u003e - Retain successful not-found matches as terminal shared boundaries during client navigation, preserving route context while the destination loads.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8251\"\u003e#8251\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/0497caeef3ff7e1c1c6080eca38bca24e7ec320b\"\u003e\u003ccode\u003e0497cae\u003c/code\u003e\u003c/a\u003e - Use URL.canParse for absolute URL checks in links, navigation, redirects, and build configuration. Preserve a URL constructor fallback for older browsers.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8169\"\u003e#8169\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/0caf6b9a2b7e14b0b146c74cc27cb05c19d700a5\"\u003e\u003ccode\u003e0caf6b9\u003c/code\u003e\u003c/a\u003e - Fix route-scoped \u003ccode\u003euseMatch\u003c/code\u003e, \u003ccode\u003euseSearch\u003c/code\u003e, and \u003ccode\u003euseParams\u003c/code\u003e APIs to forward the \u003ccode\u003eshouldThrow\u003c/code\u003e option and preserve optional return types when \u003ccode\u003eshouldThrow: false\u003c/code\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8257\"\u003e#8257\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/cf166d160e6397007a979bfc7065b45ff69ea543\"\u003e\u003ccode\u003ecf166d1\u003c/code\u003e\u003c/a\u003e - Fix repeated \u003ccode\u003einnerHTML\u003c/code\u003e writes for unchanged styles and data scripts during React re-renders. This prevents unnecessary CSS parsing and Trusted Types errors during client navigation.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated dependencies [\u003ca href=\"https://github.com/TanStack/router/commit/edf0e16ebfe82ec6e8f68f403a1fda8de9e28889\"\u003e\u003ccode\u003eedf0e16\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/2f20c00224c5ba63467551914e0c37012588c4c2\"\u003e\u003ccode\u003e2f20c00\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/28a5e4504e4ea5cb1480667a4bea2588a53e110f\"\u003e\u003ccode\u003e28a5e45\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/08eff50c447a154a3373909009e9e4375cea17ce\"\u003e\u003ccode\u003e08eff50\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/216c0c48036fd1a33163b70dcabfed2b893808b0\"\u003e\u003ccode\u003e216c0c4\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/2f9150309bc472f4a75cbe98adcdb50c76b12c7a\"\u003e\u003ccode\u003e2f91503\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/f0b5eda544606686a8a8d675a686ca1366428b96\"\u003e\u003ccode\u003ef0b5eda\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/50eafcaebbbedb6fde3b2816de7a0ace8cde4832\"\u003e\u003ccode\u003e50eafca\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/0497caeef3ff7e1c1c6080eca38bca24e7ec320b\"\u003e\u003ccode\u003e0497cae\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/ee283480dfa51150a2e0b096a6eff94a89ff8b3f\"\u003e\u003ccode\u003eee28348\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/9035abc41163d83409ef582f7743a3c7be57dd93\"\u003e\u003ccode\u003e9035abc\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/c18e69081475a7c98f9d40bd0fe6da78ccb84598\"\u003e\u003ccode\u003ec18e690\u003c/code\u003e\u003c/a\u003e]:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/router-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.171.28\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/history\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.162.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/TanStack/router/blob/main/packages/react-router/CHANGELOG.md\"\u003e@​tanstack/react-router's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.170.33\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8165\"\u003e#8165\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/2f20c00224c5ba63467551914e0c37012588c4c2\"\u003e\u003ccode\u003e2f20c00\u003c/code\u003e\u003c/a\u003e - Exclude structural descendants below error and not-found boundaries from route lifecycle callbacks. Preserve lifecycle membership through invalidation, hydration, background reloads, and superseded navigation publication.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8209\"\u003e#8209\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/28a5e4504e4ea5cb1480667a4bea2588a53e110f\"\u003e\u003ccode\u003e28a5e45\u003c/code\u003e\u003c/a\u003e - Preserve falsy thrown values in React and Vue error boundaries. Type React and Vue boundary error components and \u003ccode\u003eonCatch\u003c/code\u003e callbacks as \u003ccode\u003eunknown\u003c/code\u003e. Solid boundary errors remain typed as \u003ccode\u003eError\u003c/code\u003e; SSR now wraps non-\u003ccode\u003eError\u003c/code\u003e loader errors to match Solid’s native boundary behavior, preserving the original value in \u003ccode\u003ecause\u003c/code\u003e. Router state and loader \u003ccode\u003eonError\u003c/code\u003e values are unchanged.\u003c/p\u003e\n\u003cp\u003eWhen upgrading React or Vue, narrow boundary errors (for example, with \u003ccode\u003eerror instanceof Error\u003c/code\u003e) before reading \u003ccode\u003emessage\u003c/code\u003e or \u003ccode\u003estack\u003c/code\u003e. \u003ccode\u003eErrorComponentProps\u0026lt;TError\u0026gt;\u003c/code\u003e remains available for values narrowed to a specific error type. Route \u003ccode\u003eonError\u003c/code\u003e types are unchanged.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8161\"\u003e#8161\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/f0b5eda544606686a8a8d675a686ca1366428b96\"\u003e\u003ccode\u003ef0b5eda\u003c/code\u003e\u003c/a\u003e - Retain successful not-found matches as terminal shared boundaries during client navigation, preserving route context while the destination loads.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8251\"\u003e#8251\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/0497caeef3ff7e1c1c6080eca38bca24e7ec320b\"\u003e\u003ccode\u003e0497cae\u003c/code\u003e\u003c/a\u003e - Use URL.canParse for absolute URL checks in links, navigation, redirects, and build configuration. Preserve a URL constructor fallback for older browsers.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8169\"\u003e#8169\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/0caf6b9a2b7e14b0b146c74cc27cb05c19d700a5\"\u003e\u003ccode\u003e0caf6b9\u003c/code\u003e\u003c/a\u003e - Fix route-scoped \u003ccode\u003euseMatch\u003c/code\u003e, \u003ccode\u003euseSearch\u003c/code\u003e, and \u003ccode\u003euseParams\u003c/code\u003e APIs to forward the \u003ccode\u003eshouldThrow\u003c/code\u003e option and preserve optional return types when \u003ccode\u003eshouldThrow: false\u003c/code\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8257\"\u003e#8257\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/cf166d160e6397007a979bfc7065b45ff69ea543\"\u003e\u003ccode\u003ecf166d1\u003c/code\u003e\u003c/a\u003e - Fix repeated \u003ccode\u003einnerHTML\u003c/code\u003e writes for unchanged styles and data scripts during React re-renders. This prevents unnecessary CSS parsing and Trusted Types errors during client navigation.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated dependencies [\u003ca href=\"https://github.com/TanStack/router/commit/edf0e16ebfe82ec6e8f68f403a1fda8de9e28889\"\u003e\u003ccode\u003eedf0e16\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/2f20c00224c5ba63467551914e0c37012588c4c2\"\u003e\u003ccode\u003e2f20c00\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/28a5e4504e4ea5cb1480667a4bea2588a53e110f\"\u003e\u003ccode\u003e28a5e45\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/08eff50c447a154a3373909009e9e4375cea17ce\"\u003e\u003ccode\u003e08eff50\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/216c0c48036fd1a33163b70dcabfed2b893808b0\"\u003e\u003ccode\u003e216c0c4\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/2f9150309bc472f4a75cbe98adcdb50c76b12c7a\"\u003e\u003ccode\u003e2f91503\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/f0b5eda544606686a8a8d675a686ca1366428b96\"\u003e\u003ccode\u003ef0b5eda\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/50eafcaebbbedb6fde3b2816de7a0ace8cde4832\"\u003e\u003ccode\u003e50eafca\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/0497caeef3ff7e1c1c6080eca38bca24e7ec320b\"\u003e\u003ccode\u003e0497cae\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/ee283480dfa51150a2e0b096a6eff94a89ff8b3f\"\u003e\u003ccode\u003eee28348\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/9035abc41163d83409ef582f7743a3c7be57dd93\"\u003e\u003ccode\u003e9035abc\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/c18e69081475a7c98f9d40bd0fe6da78ccb84598\"\u003e\u003ccode\u003ec18e690\u003c/code\u003e\u003c/a\u003e]:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/router-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.171.28\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/history\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.162.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.170.32\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8130\"\u003e#8130\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/cb281d70c1f5fe780f9d07bc500ea3a284a4e04b\"\u003e\u003ccode\u003ecb281d7\u003c/code\u003e\u003c/a\u003e - preserve context during reloads\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated dependencies [\u003ca href=\"https://github.com/TanStack/router/commit/fa652872812c9433ba8b9d9a285e51b535e7367c\"\u003e\u003ccode\u003efa65287\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/cb281d70c1f5fe780f9d07bc500ea3a284a4e04b\"\u003e\u003ccode\u003ecb281d7\u003c/code\u003e\u003c/a\u003e]:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/router-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.171.27\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.170.31\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies [\u003ca href=\"https://github.com/TanStack/router/commit/3e016ac84ffec8119f0c25cfdd1fb17e5292bd34\"\u003e\u003ccode\u003e3e016ac\u003c/code\u003e\u003c/a\u003e]:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/router-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.171.26\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.170.30\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8084\"\u003e#8084\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/5d3785dcc366b66b1c261b5d01e66af778ff1175\"\u003e\u003ccode\u003e5d3785d\u003c/code\u003e\u003c/a\u003e - preserve pending UI across retained routes\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/TanStack/router/pull/8068\"\u003e#8068\u003c/a\u003e \u003ca href=\"https://github.com/TanStack/router/commit/f75cada01707e51fb9650dd301bc04f8b2265a2a\"\u003e\u003ccode\u003ef75cada\u003c/code\u003e\u003c/a\u003e - direct export of CatchBoundary class component, remove function wrapper\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated dependencies [\u003ca href=\"https://github.com/TanStack/router/commit/5d3785dcc366b66b1c261b5d01e66af778ff1175\"\u003e\u003ccode\u003e5d3785d\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/63d2cc9155ff5374112f7d067d0b278bafeb8486\"\u003e\u003ccode\u003e63d2cc9\u003c/code\u003e\u003c/a\u003e]:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/router-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.171.25\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/a58e01c604e2d189ef8c8c1ad6ac8747e03aa88c\"\u003e\u003ccode\u003ea58e01c\u003c/code\u003e\u003c/a\u003e ci: Version Packages (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-router/issues/8182\"\u003e#8182\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/08eff50c447a154a3373909009e9e4375cea17ce\"\u003e\u003ccode\u003e08eff50\u003c/code\u003e\u003c/a\u003e fix(router-core): fix dangling references in published declarations (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-router/issues/8207\"\u003e#8207\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/cf166d160e6397007a979bfc7065b45ff69ea543\"\u003e\u003ccode\u003ecf166d1\u003c/code\u003e\u003c/a\u003e fix(react-router): avoid rewriting unchanged head assets (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-router/issues/8257\"\u003e#8257\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/07b3bc971de1538264dcb461aea28a80e8209efc\"\u003e\u003ccode\u003e07b3bc9\u003c/code\u003e\u003c/a\u003e test(react-router): cover pending and not-found context (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-router/issues/8243\"\u003e#8243\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/2f20c00224c5ba63467551914e0c37012588c4c2\"\u003e\u003ccode\u003e2f20c00\u003c/code\u003e\u003c/a\u003e fix(router-core): skip lifecycle callbacks below fallback boundaries (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-router/issues/8165\"\u003e#8165\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/0497caeef3ff7e1c1c6080eca38bca24e7ec320b\"\u003e\u003ccode\u003e0497cae\u003c/code\u003e\u003c/a\u003e perf(router): use URL.canParse for absolute URL checks (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-router/issues/8251\"\u003e#8251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/28a5e4504e4ea5cb1480667a4bea2588a53e110f\"\u003e\u003ccode\u003e28a5e45\u003c/code\u003e\u003c/a\u003e fix(router): handle unknown error boundary values (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-router/issues/8209\"\u003e#8209\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/f0b5eda544606686a8a8d675a686ca1366428b96\"\u003e\u003ccode\u003ef0b5eda\u003c/code\u003e\u003c/a\u003e fix(router-core): retain not-found boundary during navigation (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-router/issues/8161\"\u003e#8161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/0caf6b9a2b7e14b0b146c74cc27cb05c19d700a5\"\u003e\u003ccode\u003e0caf6b9\u003c/code\u003e\u003c/a\u003e fix: preserve shouldThrow in route-scoped hooks (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-router/issues/8169\"\u003e#8169\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/a5a5bacc8fdf30b7823caf0a94908c3e0db27aa2\"\u003e\u003ccode\u003ea5a5bac\u003c/code\u003e\u003c/a\u003e ci: Version Packages (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-router/issues/8133\"\u003e#8133\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/TanStack/router/commits/@tanstack/react-router@1.170.33/packages/react-router\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@tanstack/react-start` from 1.168.46 to 1.168.50\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/TanStack/router/releases\"\u003e@​tanstack/react-start's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​tanstack/react-start\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.168.50\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies [\u003ca href=\"https://github.com/TanStack/router/commit/2f20c00224c5ba63467551914e0c37012588c4c2\"\u003e\u003ccode\u003e2f20c00\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/28a5e4504e4ea5cb1480667a4bea2588a53e110f\"\u003e\u003ccode\u003e28a5e45\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/f0b5eda544606686a8a8d675a686ca1366428b96\"\u003e\u003ccode\u003ef0b5eda\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/37877da166fe4ce055c7b85e138b6681ebd7e8b4\"\u003e\u003ccode\u003e37877da\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/0497caeef3ff7e1c1c6080eca38bca24e7ec320b\"\u003e\u003ccode\u003e0497cae\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/0caf6b9a2b7e14b0b146c74cc27cb05c19d700a5\"\u003e\u003ccode\u003e0caf6b9\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/cf166d160e6397007a979bfc7065b45ff69ea543\"\u003e\u003ccode\u003ecf166d1\u003c/code\u003e\u003c/a\u003e]:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-router\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.33\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-plugin-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.171.40\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-client\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.168.31\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-rsc\u003c/code\u003e\u003ca href=\"https://github.com/0\"\u003e\u003ccode\u003e@​0\u003c/code\u003e\u003c/a\u003e.1.49\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-server\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.167.38\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-client-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.28\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-server-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.169.32\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/TanStack/router/blob/main/packages/react-start/CHANGELOG.md\"\u003e@​tanstack/react-start's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.168.50\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies [\u003ca href=\"https://github.com/TanStack/router/commit/2f20c00224c5ba63467551914e0c37012588c4c2\"\u003e\u003ccode\u003e2f20c00\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/28a5e4504e4ea5cb1480667a4bea2588a53e110f\"\u003e\u003ccode\u003e28a5e45\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/f0b5eda544606686a8a8d675a686ca1366428b96\"\u003e\u003ccode\u003ef0b5eda\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/37877da166fe4ce055c7b85e138b6681ebd7e8b4\"\u003e\u003ccode\u003e37877da\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/0497caeef3ff7e1c1c6080eca38bca24e7ec320b\"\u003e\u003ccode\u003e0497cae\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/0caf6b9a2b7e14b0b146c74cc27cb05c19d700a5\"\u003e\u003ccode\u003e0caf6b9\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/cf166d160e6397007a979bfc7065b45ff69ea543\"\u003e\u003ccode\u003ecf166d1\u003c/code\u003e\u003c/a\u003e]:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-router\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.33\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-plugin-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.171.40\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-client\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.168.31\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-rsc\u003c/code\u003e\u003ca href=\"https://github.com/0\"\u003e\u003ccode\u003e@​0\u003c/code\u003e\u003c/a\u003e.1.49\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-server\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.167.38\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-client-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.28\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-server-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.169.32\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.168.49\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies [\u003ca href=\"https://github.com/TanStack/router/commit/cb281d70c1f5fe780f9d07bc500ea3a284a4e04b\"\u003e\u003ccode\u003ecb281d7\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/a0041bb36e700b3263b894e4d1573d924383b56b\"\u003e\u003ccode\u003ea0041bb\u003c/code\u003e\u003c/a\u003e]:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-router\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.32\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-plugin-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.171.39\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-client\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.168.30\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-rsc\u003c/code\u003e\u003ca href=\"https://github.com/0\"\u003e\u003ccode\u003e@​0\u003c/code\u003e\u003c/a\u003e.1.48\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-server\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.167.37\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-client-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.27\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-server-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.169.31\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.168.48\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies []:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-router\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.31\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-client\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.168.29\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-rsc\u003c/code\u003e\u003ca href=\"https://github.com/0\"\u003e\u003ccode\u003e@​0\u003c/code\u003e\u003c/a\u003e.1.47\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-server\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.167.36\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-client-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.26\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-plugin-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.171.38\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-server-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.169.30\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.168.47\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies [\u003ca href=\"https://github.com/TanStack/router/commit/5d3785dcc366b66b1c261b5d01e66af778ff1175\"\u003e\u003ccode\u003e5d3785d\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/TanStack/router/commit/f75cada01707e51fb9650dd301bc04f8b2265a2a\"\u003e\u003ccode\u003ef75cada\u003c/code\u003e\u003c/a\u003e]:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-router\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.30\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-client\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.168.28\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-rsc\u003c/code\u003e\u003ca href=\"https://github.com/0\"\u003e\u003ccode\u003e@​0\u003c/code\u003e\u003c/a\u003e.1.46\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/react-start-server\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.167.35\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-client-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.170.25\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@​tanstack/start-plugin-core\u003c/code\u003e\u003ca href=\"https://github.com/1\"\u003e\u003ccode\u003e@​1\u003c/code\u003e\u003c/a\u003e.171.37\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/a58e01c604e2d189ef8c8c1ad6ac8747e03aa88c\"\u003e\u003ccode\u003ea58e01c\u003c/code\u003e\u003c/a\u003e ci: Version Packages (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-start/issues/8182\"\u003e#8182\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/a5a5bacc8fdf30b7823caf0a94908c3e0db27aa2\"\u003e\u003ccode\u003ea5a5bac\u003c/code\u003e\u003c/a\u003e ci: Version Packages (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-start/issues/8133\"\u003e#8133\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/4fcbcde90d1c356baa741a98f3947b36b821ecc6\"\u003e\u003ccode\u003e4fcbcde\u003c/code\u003e\u003c/a\u003e ci: Version Packages (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-start/issues/8119\"\u003e#8119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/a78f2af5b49ba21d50398611f55fa4195cb83e67\"\u003e\u003ccode\u003ea78f2af\u003c/code\u003e\u003c/a\u003e ci: Version Packages (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-start/issues/8079\"\u003e#8079\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TanStack/router/commit/f97188fdb4c3964bd47b556a904cd85e3142d06e\"\u003e\u003ccode\u003ef97188f\u003c/code\u003e\u003c/a\u003e chore: localize package dependencies (\u003ca href=\"https://github.com/TanStack/router/tree/HEAD/packages/react-start/issues/8078\"\u003e#8078\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/TanStack/router/commits/@tanstack/react-start@1.168.50/packages/react-start\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@vercel/oidc` from 3.8.4 to 3.8.5\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/vercel/blob/main/packages/oidc/CHANGELOG.md\"\u003e@​vercel/oidc's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.8.5\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies [7a3a2ef]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​vercel/cli-config\u003c/code\u003e\u003ca href=\"https://github.com/0\"\u003e\u003ccode\u003e@​0\u003c/code\u003e\u003c/a\u003e.2.4\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/vercel/commit/7978e3ccfed6daf3da1fd8adf4eb85f136e52f9e\"\u003e\u003ccode\u003e7978e3c\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/vercel/tree/HEAD/packages/oidc/issues/13861\"\u003e#13861\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/vercel/commit/d1ca3ed3ac1b9830403dc9dc3520e963ef8bec8e\"\u003e\u003ccode\u003ed1ca3ed\u003c/code\u003e\u003c/a\u003e Upgrade tests to run on Node 22 by default (\u003ca href=\"https://github.com/vercel/vercel/tree/HEAD/packages/oidc/issues/13856\"\u003e#13856\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/vercel/commit/814148b7a06bcbb2e9dda34772e70c991a1c6f42\"\u003e\u003ccode\u003e814148b\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/vercel/tree/HEAD/packages/oidc/issues/13782\"\u003e#13782\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/vercel/commit/821e4b8e8eded000b3d4e864594730e8741ef522\"\u003e\u003ccode\u003e821e4b8\u003c/code\u003e\u003c/a\u003e [oidc] add file extension to dynamic imports (\u003ca href=\"https://github.com/vercel/vercel/tree/HEAD/packages/oidc/issues/13815\"\u003e#13815\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/vercel/commit/17a7205fd554ef8af9680fa0aa111fa0489d8708\"\u003e\u003ccode\u003e17a7205\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/vercel/tree/HEAD/packages/oidc/issues/13763\"\u003e#13763\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/vercel/commit/0617e3ef5def33d0ec051432f87f60d5bb7ed604\"\u003e\u003ccode\u003e0617e3e\u003c/code\u003e\u003c/a\u003e Lower version of \u003ccode\u003e@​vercel/oidc\u003c/code\u003e so it stops breaking releases (\u003ca href=\"https://github.com/vercel/vercel/tree/HEAD/packages/oidc/issues/13729\"\u003e#13729\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/vercel/commit/775e077713cc30f65ab63e04279f743a06652c2c\"\u003e\u003ccode\u003e775e077\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/vercel/tree/HEAD/packages/oidc/issues/13682\"\u003e#13682\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/vercel/commit/a133e534e7dfd785beeeb0dcafed8d2c991e9f11\"\u003e\u003ccode\u003ea133e53\u003c/code\u003e\u003c/a\u003e Add refresh token behavior to getVercelOidcToken (\u003ca href=\"https://github.com/vercel/vercel/tree/HEAD/packages/oidc/issues/13608\"\u003e#13608\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/vercel/commit/444a0e21f754dea678ef3d115cf908da21217c73\"\u003e\u003ccode\u003e444a0e2\u003c/code\u003e\u003c/a\u003e Version Packages (\u003ca href=\"https://github.com/vercel/vercel/tree/HEAD/packages/oidc/issues/13605\"\u003e#13605\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/vercel/commit/fa8d4c76ea50c4844031f56209b21845818212fc\"\u003e\u003ccode\u003efa8d4c7\u003c/code\u003e\u003c/a\u003e create \u003ccode\u003e@​vercel/oidc\u003c/code\u003e and \u003ccode\u003e@​vercel/oidc-aws-credentials-provider\u003c/code\u003e  (\u003ca href=\"https://github.com/vercel/vercel/tree/HEAD/packages/oidc/issues/13548\"\u003e#13548\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/vercel/vercel/commits/@vercel/frameworks@3.8.5/packages/oidc\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `convex` from 1.44.0 to 1.45.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/get-convex/convex-backend/blob/main/npm-packages/convex/CHANGELOG.md\"\u003econvex's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.45.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eLocal deployments now upgrade to a new backend version in place, instead of\ngoing through a snapshot export and import. Upgrades no longer depend on the\nsize of your local data, and no longer prompt about transferring it.\u003c/li\u003e\n\u003cli\u003eThe Convex MCP server (\u003ccode\u003enpx convex mcp\u003c/code\u003e) now supports the stateless MCP\nprotocol (\u003ccode\u003e2026-07-28\u003c/code\u003e MCP specification).\u003c/li\u003e\n\u003cli\u003eAdded a new \u003ccode\u003egetServiceToken\u003c/code\u003e function that generates service tokens for\nfirst-party Convex services. This will be used by the upcoming Convex AI\ngateway.\u003c/li\u003e\n\u003cli\u003eImproved the error message when \u003ccode\u003enpx convex export\u003c/code\u003e fails because a snapshot\nexport is already in progress.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/get-convex/convex-backend/commits/HEAD/npm-packages/convex\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `convex-helpers` from 0.1.123 to 0.1.124\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/get-convex/convex-helpers/blob/main/packages/convex-helpers/CHANGELOG.md\"\u003econvex-helpers's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.1.124\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003evalidate\u003c/code\u003e now normalizes system table ids (e.g. \u003ccode\u003ev.id(\u0026quot;_storage\u0026quot;)\u003c/code\u003e) with\n\u003ccode\u003edb.system.normalizeId\u003c/code\u003e instead of throwing when passed a real \u003ccode\u003edb\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/get-convex/convex-helpers/commit/cd7c2e4dcab2e8d3c2375ce4c0c99ed4cc6cd35f\"\u003e\u003ccode\u003ecd7c2e4\u003c/code\u003e\u003c/a\u003e npm 0.1.124\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/get-convex/convex-helpers/commit/3c4e0e7d545a34e54302b8b27c084ff6c526b364\"\u003e\u003ccode\u003e3c4e0e7\u003c/code\u003e\u003c/a\u003e fix validation of system table ids (\u003ca href=\"https://github.com/get-convex/convex-helpers/tree/HEAD/packages/convex-helpers/issues/1003\"\u003e#1003\u003c/a\u003e) (\u003ca href=\"https://github.com/get-convex/convex-helpers/tree/HEAD/packages/convex-helpers/issues/1004\"\u003e#1004\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/get-convex/convex-helpers/commits/npm/0.1.124/packages/convex-helpers\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ignore` from 7.0.6 to 7.0.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/kaelzhang/node-ignore/releases\"\u003eignore's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e7.0.8\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003ePATCH\u003c/strong\u003e Brings pattern matching closer to \u003ccode\u003egit\u003c/code\u003e:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ePATCH\u003c/strong\u003e A backslash now makes the next character a literal, exactly as \u003ccode\u003egit\u003c/code\u003e does: \u003ccode\u003e\\*\u003c/code\u003e matches a literal \u003ccode\u003e*\u003c/code\u003e rather than acting as a wildcard, \u003ccode\u003e\\?\u003c/code\u003e matches a literal \u003ccode\u003e?\u003c/code\u003e, and \u003ccode\u003e\\d\u003c/code\u003e, \u003ccode\u003e\\b\u003c/code\u003e, \u003ccode\u003e\\/\u003c/code\u003e and the like are the plain characters instead of regular-expression escapes.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePATCH\u003c/strong\u003e Only a trailing run of spaces is stripped from a pattern — never tabs or other whitespace — and a line of only tabs is treated as a pattern rather than a blank line, matching \u003ccode\u003egit\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAn upgrade is recommended for all dependents.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kaelzhang/node-ignore/commit/821765efdf7752b186a03ed0450d9ee013cee099\"\u003e\u003ccode\u003e821765e\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://redirect.github.com/kaelzhang/node-ignore/issues/166\"\u003e#166\u003c/a\u003e: bump version 7.0.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kaelzhang/node-ignore/commit/e00d35eaee5184cc0176309b680bd252d321c5eb\"\u003e\u003ccode\u003ee00d35e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/kaelzhang/node-ignore/issues/167\"\u003e#167\u003c/a\u003e from bentbrain/fix-bom-blank-line\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kaelzhang/node-ignore/commit/9b6481f88753fd5361ad6c4b945f90e556ea2a49\"\u003e\u003ccode\u003e9b6481f\u003c/code\u003e\u003c/a\u003e fix(ignore): reject BOM-only blank lines before compilation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kaelzhang/node-ignore/commit/20b802ae9e60c304e7fc71e77ffc246be1a02974\"\u003e\u003ccode\u003e20b802a\u003c/code\u003e\u003c/a\u003e bump version 7.0.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kaelzhang/node-ignore/commit/0414358a20becef81d1bcad99df5c8260a3fd8d1\"\u003e\u003ccode\u003e0414358\u003c/code\u003e\u003c/a\u003e build: require 100% coverage of index.js as an explicit gate\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kaelzhang/node-ignore/commit/968aee6885ab2511b0759c2e135b062a4831ee97\"\u003e\u003ccode\u003e968aee6\u003c/code\u003e\u003c/a\u003e compat: check compatibility by running old versions' test suites\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kaelzhang/node-ignore/commit/8e462205940765a6524c5415df281b7725a82e31\"\u003e\u003ccode\u003e8e46220\u003c/code\u003e\u003c/a\u003e build: run the compatibility gate as part of \u003ccode\u003enpm test\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kaelzhang/node-ignore/commit/6e81fb231c76325b35ced3df461c95b5350d729e\"\u003e\u003ccode\u003e6e81fb2\u003c/code\u003e\u003c/a\u003e tidy up how wildcards compile\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kaelzhang/node-ignore/commit/ea3d5ebbe9f47932a5b149675ef26fd54dde0ccd\"\u003e\u003ccode\u003eea3d5eb\u003c/code\u003e\u003c/a\u003e fix: a backslash quotes the next character, and only spaces are trimmed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kaelzhang/node-ignore/commit/01cfbbb2ecc11665192da960ec1fe908d8ad3a47\"\u003e\u003ccode\u003e01cfbbb\u003c/code\u003e\u003c/a\u003e docs: document the known, deliberate differences from git\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/kaelzhang/node-ignore/compare/7.0.6...7.0.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `jose` from 6.2.9 to 6.2.12\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/panva/jose/releases\"\u003ejose's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.2.12\u003c/h2\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eclarify and shorten public API guidance (\u003ca href=\"https://github.com/panva/jose/commit/be62530328431519950a2b6a09ccd1c7de8a38f9\"\u003ebe62530\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003esimplify JWS and JWE operation cores (\u003ca href=\"https://github.com/panva/jose/commit/92e9640290085dd37c152aeb7c4d5b22e9df96ab\"\u003e92e9640\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eavoid copying AES-GCM output (\u003ca href=\"https://github.com/panva/jose/commit/6925d43e05c7d05b0c801fda9eb1835bb8d334ef\"\u003e6925d43\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ededuplicate pending jwks key imports (\u003ca href=\"https://github.com/panva/jose/commit/bf5138b12bf9f8b7dc18f4b26ad1b7395e7e5dd6\"\u003ebf5138b\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eencode single-signature JWS input once (\u003ca href=\"https://github.com/panva/jose/commit/7bc9a3380a7436197bb5d6b377ca232094541c5c\"\u003e7bc9a33\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enormalize General JWE shared headers once (\u003ca href=\"https://github.com/panva/jose/commit/78637bd28031869df8a01cbcd82273c115860e35\"\u003e78637bd\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enormalize jwks selection metadata once (\u003ca href=\"https://github.com/panva/jose/commit/fd3ae3f06efd4760df2631f1b0a08eb4fc448efd\"\u003efd3ae3f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse native encoding for larger ASCII strings (\u003ca href=\"https://github.com/panva/jose/commit/b23a6f378b26e960900761c244a5f383af22dddc\"\u003eb23a6f3\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.2.11\u003c/h2\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003erender subpath indexes as tables (\u003ca href=\"https://github.com/panva/jose/commit/94589ee9efe6cf257a133765d753bbe8d55f6ed3\"\u003e94589ee\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eshorten API index descriptions (\u003ca href=\"https://github.com/panva/jose/commit/681482fcca7577c6a4b8df61c992f195f6e6ac1b\"\u003e681482f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003emodel JWE key management modes (\u003ca href=\"https://github.com/panva/jose/commit/e01dda65d5d272c8dd44710d0c70673c1530038e\"\u003ee01dda6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypes:\u003c/strong\u003e reduce declaration repetition (\u003ca href=\"https://github.com/panva/jose/commit/55b970fc08c9082041f40473470ee0fe0e8b0087\"\u003e55b970f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.2.10\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ejose:\u003c/strong\u003e consume serialization members once (\u003ca href=\"https://github.com/panva/jose/commit/9bee285a6bc356b495c29ae0a5e70b24e723568e\"\u003e9bee285\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejose:\u003c/strong\u003e reject empty protected and JWE AAD members (\u003ca href=\"https://github.com/panva/jose/commit/8da41453dce79967c6e3f47a787039a7f94de8fe\"\u003e8da4145\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejose:\u003c/strong\u003e validate serialized header values (\u003ca href=\"https://github.com/panva/jose/commit/b711d8fe223e3e85520d6c822d7a417cd872b718\"\u003eb711d8f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwe:\u003c/strong\u003e conceal invalid decrypted CEK lengths (\u003ca href=\"https://github.com/panva/jose/commit/41fafe035a62d85f4b313e166100004dd09b111f\"\u003e41fafe0\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwe:\u003c/strong\u003e enforce AES-GCM tag boundaries (\u003ca href=\"https://github.com/panva/jose/commit/9a5b74454bf145a106312d519efe95b8a9b53a87\"\u003e9a5b744\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwe:\u003c/strong\u003e validate explicit encryption parameters (\u003ca href=\"https://github.com/panva/jose/commit/7a02697126e40757ed9e02ae786ec9a2b180aa5c\"\u003e7a02697\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwk:\u003c/strong\u003e accept empty octet-sequence keys (\u003ca href=\"https://github.com/panva/jose/commit/3f871e7859c1ce51d1afcbfeff92c354b8e96dd9\"\u003e3f871e7\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwk:\u003c/strong\u003e normalize key resolution inputs (\u003ca href=\"https://github.com/panva/jose/commit/f54ee7bad8e21c975606bc5e47b352921ac0d890\"\u003ef54ee7b\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwks:\u003c/strong\u003e enforce verification key metadata (\u003ca href=\"https://github.com/panva/jose/commit/f9ba5101383154147780da7acf1aabc705f75aaf\"\u003ef9ba510\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwks:\u003c/strong\u003e order overlapping remote reloads (\u003ca href=\"https://github.com/panva/jose/commit/9a1a913983aa44d065a423692a92148b2a6a36c3\"\u003e9a1a913\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwks:\u003c/strong\u003e reject invalid remote duration values (\u003ca href=\"https://github.com/panva/jose/commit/7bdb9e56e6a74b833af582532c6fff5bc727ec1c\"\u003e7bdb9e5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwk:\u003c/strong\u003e validate ext and key_ops parameters (\u003ca href=\"https://github.com/panva/jose/commit/4d91c37fdd36241785cb172774fa017bb8854458\"\u003e4d91c37\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejws:\u003c/strong\u003e reject mixed payload encoding modes (\u003ca href=\"https://github.com/panva/jose/commit/dc69713081a55a3d6955dd1d8c2cf184905febad\"\u003edc69713\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejws:\u003c/strong\u003e validate unencoded payload strings (\u003ca href=\"https://github.com/panva/jose/commit/541f28234442c5cbfc5f843a95ccd18a721f3697\"\u003e541f282\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwt:\u003c/strong\u003e enforce explicit verification policies (\u003ca href=\"https://github.com/panva/jose/commit/b3471826b02589656eaf71843671922644cc60e2\"\u003eb347182\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwt:\u003c/strong\u003e prevent replacing protected headers (\u003ca href=\"https://github.com/panva/jose/commit/ae07d09bcbac91825e27cde9989b603af3495263\"\u003eae07d09\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwt:\u003c/strong\u003e reject invalid duration inputs (\u003ca href=\"https://github.com/panva/jose/commit/282f9aaa496e57f55417bca15e13c369b3f242fb\"\u003e282f9aa\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwt:\u003c/strong\u003e validate builder claim values (\u003ca href=\"https://github.com/panva/jose/commit/ea03f83d607fcaee6fc0778c8a4d40a2bbd75c9e\"\u003eea03f83\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/panva/jose/blob/main/CHANGELOG.md\"\u003ejose's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/panva/jose/compare/v6.2.11...v6.2.12\"\u003e6.2.12\u003c/a\u003e (2026-09-05)\u003c/h2\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eclarify and shorten public API guidance (\u003ca href=\"https://github.com/panva/jose/commit/be62530328431519950a2b6a09ccd1c7de8a38f9\"\u003ebe62530\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003esimplify JWS and JWE operation cores (\u003ca href=\"https://github.com/panva/jose/commit/92e9640290085dd37c152aeb7c4d5b22e9df96ab\"\u003e92e9640\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eavoid copying AES-GCM output (\u003ca href=\"https://github.com/panva/jose/commit/6925d43e05c7d05b0c801fda9eb1835bb8d334ef\"\u003e6925d43\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ededuplicate pending jwks key imports (\u003ca href=\"https://github.com/panva/jose/commit/bf5138b12bf9f8b7dc18f4b26ad1b7395e7e5dd6\"\u003ebf5138b\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eencode single-signature JWS input once (\u003ca href=\"https://github.com/panva/jose/commit/7bc9a3380a7436197bb5d6b377ca232094541c5c\"\u003e7bc9a33\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enormalize General JWE shared headers once (\u003ca href=\"https://github.com/panva/jose/commit/78637bd28031869df8a01cbcd82273c115860e35\"\u003e78637bd\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003enormalize jwks selection metadata once (\u003ca href=\"https://github.com/panva/jose/commit/fd3ae3f06efd4760df2631f1b0a08eb4fc448efd\"\u003efd3ae3f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse native encoding for larger ASCII strings (\u003ca href=\"https://github.com/panva/jose/commit/b23a6f378b26e960900761c244a5f383af22dddc\"\u003eb23a6f3\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/panva/jose/compare/v6.2.10...v6.2.11\"\u003e6.2.11\u003c/a\u003e (2026-09-04)\u003c/h2\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003erender subpath indexes as tables (\u003ca href=\"https://github.com/panva/jose/commit/94589ee9efe6cf257a133765d753bbe8d55f6ed3\"\u003e94589ee\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eshorten API index descriptions (\u003ca href=\"https://github.com/panva/jose/commit/681482fcca7577c6a4b8df61c992f195f6e6ac1b\"\u003e681482f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRefactor\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003emodel JWE key management modes (\u003ca href=\"https://github.com/panva/jose/commit/e01dda65d5d272c8dd44710d0c70673c1530038e\"\u003ee01dda6\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etypes:\u003c/strong\u003e reduce declaration repetition (\u003ca href=\"https://github.com/panva/jose/commit/55b970fc08c9082041f40473470ee0fe0e8b0087\"\u003e55b970f\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/panva/jose/compare/v6.2.9...v6.2.10\"\u003e6.2.10\u003c/a\u003e (2026-08-21)\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ejose:\u003c/strong\u003e consume serialization members once (\u003ca href=\"https://github.com/panva/jose/commit/9bee285a6bc356b495c29ae0a5e70b24e723568e\"\u003e9bee285\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejose:\u003c/strong\u003e reject empty protected and JWE AAD members (\u003ca href=\"https://github.com/panva/jose/commit/8da41453dce79967c6e3f47a787039a7f94de8fe\"\u003e8da4145\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejose:\u003c/strong\u003e validate serialized header values (\u003ca href=\"https://github.com/panva/jose/commit/b711d8fe223e3e85520d6c822d7a417cd872b718\"\u003eb711d8f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwe:\u003c/strong\u003e conceal invalid decrypted CEK lengths (\u003ca href=\"https://github.com/panva/jose/commit/41fafe035a62d85f4b313e166100004dd09b111f\"\u003e41fafe0\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwe:\u003c/strong\u003e enforce AES-GCM tag boundaries (\u003ca href=\"https://github.com/panva/jose/commit/9a5b74454bf145a106312d519efe95b8a9b53a87\"\u003e9a5b744\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwe:\u003c/strong\u003e validate explicit encryption parameters (\u003ca href=\"https://github.com/panva/jose/commit/7a02697126e40757ed9e02ae786ec9a2b180aa5c\"\u003e7a02697\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwk:\u003c/strong\u003e accept empty octet-sequence keys (\u003ca href=\"https://github.com/panva/jose/commit/3f871e7859c1ce51d1afcbfeff92c354b8e96dd9\"\u003e3f871e7\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwk:\u003c/strong\u003e normalize key resolution inputs (\u003ca href=\"https://github.com/panva/jose/commit/f54ee7bad8e21c975606bc5e47b352921ac0d890\"\u003ef54ee7b\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwks:\u003c/strong\u003e enforce verification key metadata (\u003ca href=\"https://github.com/panva/jose/commit/f9ba5101383154147780da7acf1aabc705f75aaf\"\u003ef9ba510\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwks:\u003c/strong\u003e order overlapping remote reloads (\u003ca href=\"https://github.com/panva/jose/commit/9a1a913983aa44d065a423692a92148b2a6a36c3\"\u003e9a1a913\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwks:\u003c/strong\u003e reject invalid remote duration values (\u003ca href=\"https://github.com/panva/jose/commit/7bdb9e56e6a74b833af582532c6fff5bc727ec1c\"\u003e7bdb9e5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwk:\u003c/strong\u003e validate ext and key_ops parameters (\u003ca href=\"https://github.com/panva/jose/commit/4d91c37fdd36241785cb172774fa017bb8854458\"\u003e4d91c37\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejws:\u003c/strong\u003e reject mixed payload encoding modes (\u003ca href=\"https://github.com/panva/jose/commit/dc69713081a55a3d6955dd1d8c2cf184905febad\"\u003edc69713\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejws:\u003c/strong\u003e validate unencoded payload strings (\u003ca href=\"https://github.com/panva/jose/commit/541f28234442c5cbfc5f843a95ccd18a721f3697\"\u003e541f282\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ejwt:\u003c/strong\u003e enforce explicit verification policies (\u003ca href=\"https://github.com/panva/jose/commit/b3471826b02589656eaf71843671922644cc60e2\"\u003eb347182\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/505a55b8f73536082367b2614cb77e927ba96ec1\"\u003e\u003ccode\u003e505a55b\u003c/code\u003e\u003c/a\u003e chore(release): 6.2.12\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/7bc9a3380a7436197bb5d6b377ca232094541c5c\"\u003e\u003ccode\u003e7bc9a33\u003c/code\u003e\u003c/a\u003e perf: encode single-signature JWS input once\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/78637bd28031869df8a01cbcd82273c115860e35\"\u003e\u003ccode\u003e78637bd\u003c/code\u003e\u003c/a\u003e perf: normalize General JWE shared headers once\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/bf5138b12bf9f8b7dc18f4b26ad1b7395e7e5dd6\"\u003e\u003ccode\u003ebf5138b\u003c/code\u003e\u003c/a\u003e perf: deduplicate pending jwks key imports\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/b23a6f378b26e960900761c244a5f383af22dddc\"\u003e\u003ccode\u003eb23a6f3\u003c/code\u003e\u003c/a\u003e perf: use native encoding for larger ASCII strings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/fd3ae3f06efd4760df2631f1b0a08eb4fc448efd\"\u003e\u003ccode\u003efd3ae3f\u003c/code\u003e\u003c/a\u003e perf: normalize jwks selection metadata once\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/6925d43e05c7d05b0c801fda9eb1835bb8d334ef\"\u003e\u003ccode\u003e6925d43\u003c/code\u003e\u003c/a\u003e perf: avoid copying AES-GCM output\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/be62530328431519950a2b6a09ccd1c7de8a38f9\"\u003e\u003ccode\u003ebe62530\u003c/code\u003e\u003c/a\u003e docs: clarify and shorten public API guidance\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/1b413121c71eed953852ac82a288f8a6b37f1343\"\u003e\u003ccode\u003e1b41312\u003c/code\u003e\u003c/a\u003e build: preserve README when generation fails\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/panva/jose/commit/0b518296d441aa95e45268eee178b3ad22a78d49\"\u003e\u003ccode\u003e0b51829\u003c/code\u003e\u003c/a\u003e build: check tree-shaking for every public binding\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/panva/jose/compare/v6.2.9...v6.2.12\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `lucide-react` from 1.31.0 to 1.43.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lucide-icons/lucide/releases\"\u003elucide-react's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 1.43.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003etic-tac-toe\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4772\"\u003elucide-icons/lucide#4772\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): changed \u003ccode\u003eid-card\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4820\"\u003elucide-icons/lucide#4820\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): changed \u003ccode\u003eid-card-lanyard\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4819\"\u003elucide-icons/lucide#4819\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): delegate \u003ccode\u003ecarton\u003c/code\u003e/\u003ccode\u003ecarton-off\u003c/code\u003e from lab by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4818\"\u003elucide-icons/lucide#4818\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/lucide-icons/lucide/compare/1.42.0...1.43.0\"\u003ehttps://github.com/lucide-icons/lucide/compare/1.42.0...1.43.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 1.42.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(docs): added better contribution guide by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4746\"\u003elucide-icons/lucide#4746\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(site): fix HomeHeroIconsCard.data.ts by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4805\"\u003elucide-icons/lucide#4805\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): deprecated swiss franc icons by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4799\"\u003elucide-icons/lucide#4799\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): add gap-horizontal and gap-vertical by \u003ca href=\"https://github.com/samuelalake\"\u003e\u003ccode\u003e@​samuelalake\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4544\"\u003elucide-icons/lucide#4544\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003etrash-off\u003c/code\u003e icon by \u003ca href=\"https://github.com/lx3133584\"\u003e\u003ccode\u003e@​lx3133584\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4788\"\u003elucide-icons/lucide#4788\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003ecircle-dashed-check\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4796\"\u003elucide-icons/lucide#4796\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003eequal-approximately-not\u003c/code\u003e icon by \u003ca href=\"https://github.com/ryck\"\u003e\u003ccode\u003e@​ryck\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4802\"\u003elucide-icons/lucide#4802\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added dome icons by \u003ca href=\"https://github.com/swastik7805\"\u003e\u003ccode\u003e@​swastik7805\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4261\"\u003elucide-icons/lucide#4261\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(lucide-react): Add Lucide React integration tests by \u003ca href=\"https://github.com/ericfennis\"\u003e\u003ccode\u003e@​ericfennis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4804\"\u003elucide-icons/lucide#4804\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(packages): extract icon build logic into \u003ccode\u003e@lucide/shared\u003c/code\u003e by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4409\"\u003elucide-icons/lucide#4409\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): changed \u003ccode\u003ecomputer\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4607\"\u003elucide-icons/lucide#4607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(dependencies): Update dependencies by \u003ca href=\"https://github.com/ericfennis\"\u003e\u003ccode\u003e@​ericfennis\u003c/code\u003e\u003c/a\u003e with \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4806\"\u003elucide-icons/lucide#4806\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): changed \u003ccode\u003etable-2\u003c/code\u003e icon by \u003ca href=\"https://github.com/jguddas\"\u003e\u003ccode\u003e@​jguddas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4810\"\u003elucide-icons/lucide#4810\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003euser-group\u003c/code\u003e icons by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4782\"\u003elucide-icons/lucide#4782\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lx3133584\"\u003e\u003ccode\u003e@​lx3133584\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4788\"\u003elucide-icons/lucide#4788\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ryck\"\u003e\u003ccode\u003e@​ryck\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4802\"\u003elucide-icons/lucide#4802\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/lucide-icons/lucide/compare/1.41.0...1.42.0\"\u003ehttps://github.com/lucide-icons/lucide/compare/1.41.0...1.42.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 1.41.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(icons): Add new icons \u003ccode\u003egerm\u003c/code\u003e and \u003ccode\u003egerm-off\u003c/code\u003e by \u003ca href=\"https://github.com/rrod497\"\u003e\u003ccode\u003e@​rrod497\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4056\"\u003elucide-icons/lucide#4056\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003edoor-stairwell\u003c/code\u003e icon \u0026amp; updated \u003ccode\u003edoor-*\u003c/code\u003e icons by \u003ca href=\"https://github.com/jguddas\"\u003e\u003ccode\u003e@​jguddas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/3554\"\u003elucide-icons/lucide#3554\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003ecredit-card-reader\u003c/code\u003e icon by \u003ca href=\"https://github.com/jguddas\"\u003e\u003ccode\u003e@​jguddas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4616\"\u003elucide-icons/lucide#4616\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added 'engine' icon by \u003ca href=\"https://github.com/benhaube\"\u003e\u003ccode\u003e@​benhaube\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4598\"\u003elucide-icons/lucide#4598\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): fixed \u003ccode\u003egerm\u003c/code\u003e \u0026amp; \u003ccode\u003egerm-off\u003c/code\u003e by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4789\"\u003elucide-icons/lucide#4789\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump the vue-deps group with 2 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4771\"\u003elucide-icons/lucide#4771\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003evirus\u003c/code\u003e/\u003ccode\u003evirus-off\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4765\"\u003elucide-icons/lucide#4765\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(copilot-reviews): Improve use-cases description. by \u003ca href=\"https://github.com/ericfennis\"\u003e\u003ccode\u003e@​ericfennis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4558\"\u003elucide-icons/lucide#4558\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): add \u003ccode\u003ecan-soda\u003c/code\u003e icon by \u003ca href=\"https://github.com/jaynewey\"\u003e\u003ccode\u003e@​jaynewey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4718\"\u003elucide-icons/lucide#4718\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): added \u003ccode\u003esquare-alert\u003c/code\u003e Icon by \u003ca href=\"https://github.com/viralcodex\"\u003e\u003ccode\u003e@​viralcodex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/3687\"\u003elucide-icons/lucide#3687\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(lab): Add label for lab icons by \u003ca href=\"https://github.com/ericfennis\"\u003e\u003ccode\u003e@​ericfennis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4793\"\u003elucide-icons/lucide#4793\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): changed \u003ccode\u003elab/bottle-toothbrush-comb\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4756\"\u003elucide-icons/lucide#4756\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(\u003ccode\u003e@​lucide/lab\u003c/code\u003e): Create automatic release flow for \u003ccode\u003e@lucide/lab\u003c/code\u003e by \u003ca href=\"https://github.com/ericfennis\"\u003e\u003ccode\u003e@​ericfennis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4792\"\u003elucide-icons/lucide#4792\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(icons): removed \u003ccode\u003etrash\u003c/code\u003e icon in favour of \u003ccode\u003etrash-2\u003c/code\u003e by \u003ca href=\"https://github.com/jguddas\"\u003e\u003ccode\u003e@​jguddas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/3141\"\u003elucide-icons/lucide#3141\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(icons): changed \u003ccode\u003eleaf\u003c/code\u003e icon by \u003ca href=\"https://github.com/karsa-mistmere\"\u003e\u003ccode\u003e@​karsa-mistmere\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/lucide-icons/lucide/pull/4801\"\u003elucide-icons/lucide#4801\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lucide-icons/lucide/commit/94e4cb9d9db5907053ebf3636a97c45529cf776b\"\u003e\u003ccode\u003e94e4cb9\u003c/code\u003e\u003c/a\u003e chore(dependencies): Update dependencies (\u003ca href=\"https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4806\"\u003e#4806\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lucide-icons/lucide/commit/99d25bdee231922e73e19525f57a585d1682fab2\"\u003e\u003ccode\u003e99d25bd\u003c/code\u003e\u003c/a\u003e feat(packages): extract icon build logic into \u003ccode\u003e@lucide/shared\u003c/code\u003e (\u003ca href=\"https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4409\"\u003e#4409\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lucide-icons/lucide/commit/75b55160aa9edd7095dfed1a6e3d88e66fb2b153\"\u003e\u003ccode\u003e75b5516\u003c/code\u003e\u003c/a\u003e chore(dev): upgrade ESLint to latest compatible stack (v10) (\u003ca href=\"https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4378\"\u003e#4378\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/lucide-icons/lucide/commits/1.43.0/packages/lucide-react\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `mermaid` from 11.16.1 to 11.17.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mermaid-js/mermaid/releases\"\u003emermaid's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003emermaid@11.17.2\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/8125\"\u003e#8125\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/178d7c79fcbafcf0662b822ec34ed989372ee5c2\"\u003e\u003ccode\u003e178d7c7\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/knsv-bot\"\u003e\u003ccode\u003e@​knsv-bot\u003c/code\u003e\u003c/a\u003e! - fix: restore the \u003ccode\u003eedgePaths\u003c/code\u003e class on the edge group in rendered SVG, and point the flowchart, block and user journey stylesheets at it\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003emermaid@11.17.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/8092\"\u003e#8092\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/31ce60a596746c76dc932ab540d910a6c7fff8be\"\u003e\u003ccode\u003e31ce60a\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/pbrolin47\"\u003e\u003ccode\u003e@​pbrolin47\u003c/code\u003e\u003c/a\u003e! - fix(c4): wrap element labels to \u003ccode\u003ec4.width\u003c/code\u003e again\u003c/p\u003e\n\u003cp\u003eC4 element labels (\u003ccode\u003eSystem\u003c/code\u003e, \u003ccode\u003eContainer\u003c/code\u003e, \u003ccode\u003eComponent\u003c/code\u003e, \u003ccode\u003ePerson\u003c/code\u003e and their \u003ccode\u003e_Ext\u003c/code\u003e variants) stopped wrapping in 11.17.0, so long descriptions rendered on one unbroken line and the shape grew sideways well past the configured \u003ccode\u003ec4.width\u003c/code\u003e. The unified-shapes label helper gated wrapping on the root-level \u003ccode\u003ewrap\u003c/code\u003e option, which has no schema default and is therefore \u003ccode\u003eundefined\u003c/code\u003e; it now gates on \u003ccode\u003ec4.wrap\u003c/code\u003e (default \u003ccode\u003etrue\u003c/code\u003e), which is what the legacy renderer used.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/8088\"\u003e#8088\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/c66200bc2302006c908f77819c584109f50c06e7\"\u003e\u003ccode\u003ec66200b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ashishjain0512\"\u003e\u003ccode\u003e@​ashishjain0512\u003c/code\u003e\u003c/a\u003e! - fix: neo-look arrowheads and crow's-foot markers no longer fall back to default theme colours/stroke widths on the first render with \u003ccode\u003elayout: elk\u003c/code\u003e. State diagram arrowheads stayed dark on dark themes, and ER / requirement markers were drawn at the default stroke width, because markers were created from the layout package's own bundled copy of mermaid, whose config had not been initialized yet.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/8079\"\u003e#8079\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/281cd7b0705a7cdf4295bfd5e3171647dc809dfb\"\u003e\u003ccode\u003e281cd7b\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/ashishjain0512\"\u003e\u003ccode\u003e@​ashishjain0512\u003c/code\u003e\u003c/a\u003e! - fix(class): class diagram relation markers (composition, aggregation, extension, dependency, lollipop) no longer scale with the edge stroke width, so they stay outside the class box boundary in themes that set \u003ccode\u003estrokeWidth: 2\u003c/code\u003e (\u003ccode\u003eredux\u003c/code\u003e, \u003ccode\u003eredux-dark\u003c/code\u003e, \u003ccode\u003eredux-color\u003c/code\u003e, \u003ccode\u003eredux-dark-color\u003c/code\u003e, \u003ccode\u003eneo\u003c/code\u003e, \u003ccode\u003eneo-dark\u003c/code\u003e) with the default \u003ccode\u003eclassic\u003c/code\u003e look.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003emermaid@11.17.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/7842\"\u003e#7842\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/3670b4e2d99b27945240dd3fe71da9175fddcaec\"\u003e\u003ccode\u003e3670b4e\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/filipsajdak\"\u003e\u003ccode\u003e@​filipsajdak\u003c/code\u003e\u003c/a\u003e! - feat(c4): render C4 elements through the unified shape system, using the new person shape\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/7812\"\u003e#7812\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/cdfc0ea65f47bc8f9605a2a646ed87c25a692216\"\u003e\u003ccode\u003ecdfc0ea\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/knsv-bot\"\u003e\u003ccode\u003e@​knsv-bot\u003c/code\u003e\u003c/a\u003e! - feat(class): route \u003ccode\u003eclassDiagram\u003c/code\u003e to the unified (v2) renderer by default\u003c/p\u003e\n\u003cp\u003eSet \u003ccode\u003eclass: { defaultRenderer: 'dagre-d3' }\u003c/code\u003e in the config to restore the legacy renderer.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/7785\"\u003e#7785\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/c45cde9582ede4add658f62b771ba2a7efadde83\"\u003e\u003ccode\u003ec45cde9\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/knsv-bot\"\u003e\u003ccode\u003e@​knsv-bot\u003c/code\u003e\u003c/a\u003e! - feat(flowchart): add collapsible flowchart subgraphs via \u003ccode\u003esubgraphId@{ view: collapsed }\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/7828\"\u003e#7828\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/8eb3afc08c64e0f5d2b2447daac417250a202c13\"\u003e\u003ccode\u003e8eb3afc\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/knsv-bot\"\u003e\u003ccode\u003e@​knsv-bot\u003c/code\u003e\u003c/a\u003e! - feat(elk): add \u003ccode\u003eelk.keepEntryNodeOnTop\u003c/code\u003e config option to keep a recursive flow's entry node on top\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/7803\"\u003e#7803\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/74e44ebf86d293cee1f2314c8b8a163284ea3911\"\u003e\u003ccode\u003e74e44eb\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/knsv-bot\"\u003e\u003ccode\u003e@​knsv-bot\u003c/code\u003e\u003c/a\u003e! - feat(elk): add \u003ccode\u003eelk.nodePlacementAlignment\u003c/code\u003e config option\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/7792\"\u003e#7792\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/ea55b31bcfb36cfdfbc31a531058ee8c4ee53a4f\"\u003e\u003ccode\u003eea55b31\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/RodrigojndSantos\"\u003e\u003ccode\u003e@​RodrigojndSantos\u003c/code\u003e\u003c/a\u003e! - feat(er): add subgraph support to ER diagrams.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/7970\"\u003e#7970\u003c/a\u003e \u003ca href=\"https://github.com/mermaid-js/mermaid/commit/a2c0fb6cdf8073b8feb10595ea3cccff0237049b\"\u003e\u003ccode\u003ea2c0fb6\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/filipsajdak\"\u003e\u003ccode\u003e@​filipsajdak\u003c/code\u003e\u003c/a\u003e! - feat(flowchart): add \u003ccode\u003efolder\u003c/code\u003e, \u003ccode\u003ebucket\u003c/code\u003e, \u003ccode\u003econsole\u003c/code\u003e (terminal window) and \u003ccode\u003ebrowser\u003c/code\u003e shapes\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/mermaid-js/mermaid/pull/7842\"\u003e#7842\u003c/a\u003e \u003ca href=\"htt...\n\n_Description has been truncated_","html_url":"https://github.com/openclaw/clawhub/pull/3686","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/openclaw%2Fclawhub/issues/3686","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/3686/packages"}},{"old_version":"8.10.0","new_version":"8.10.2","update_type":"patch","path":"the safe-updates group","pr_created_at":"2026-09-11T14:40:22.000Z","version_change":"8.10.0 → 8.10.2","issue":{"uuid":"5425590721","node_id":"PR_kwDOSI3MHs8AAAABDKHtvw","number":1197,"state":"open","title":"build(deps): Bump undici from 8.10.0 to 8.10.2 in the safe-updates group","user":"dependabot[bot]","labels":["documentation","dependencies","size/S"],"assignees":[],"locked":false,"comments_count":12,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T14:40:22.000Z","updated_at":"2026-09-11T14:45:33.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): Bump","packages":[{"name":"undici","old_version":"8.10.0","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"}],"path":"the safe-updates group","ecosystem":"npm"},"body":"Bumps the safe-updates group with 1 update: [undici](https://github.com/nodejs/undici).\n\nUpdates `undici` from 8.10.0 to 8.10.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm\"\u003eGHSA-vp8m-p9jh-q5pm\u003c/a\u003e: cache and deduplication interceptors could use caller-controlled request metadata instead of the authoritative dispatcher origin, enabling cross-origin cache poisoning and data disclosure. Undici now derives interceptor identities from the dispatcher origin and bypasses origin-dependent interceptors when no authoritative origin exists. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/caf6194d3dae989b731ed87ab85f182befe5eb80\"\u003ecaf6194d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e8f5868fb\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e66e12816\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6\"\u003e4411a238\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/662d0ea671fe64139e79533c913fce412765e1d7\"\u003e662d0ea6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003ecb75bbb3\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e7aac7f12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003ee905b5b8\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e2be07bf9\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e6d583124\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e0160a719\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps-dev): bump undici from 6.27.0 to 6.28.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5653\"\u003enodejs/undici#5653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump jest from 30.4.2 to 30.5.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5750\"\u003enodejs/undici#5750\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/analyze from 4.37.3 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5752\"\u003enodejs/undici#5752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5754\"\u003enodejs/undici#5754\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(h2): cover stream reset with NGHTTP2_INTERNAL_ERROR by \u003ca href=\"https://github.com/zeexzeex\"\u003e\u003ccode\u003e@​zeexzeex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5725\"\u003enodejs/undici#5725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): reject invalid resumed responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5724\"\u003enodejs/undici#5724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: make stale-while-revalidate cache update test deterministic by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5722\"\u003enodejs/undici#5722\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid unbounded recursion in Set-Cookie attribute parser by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5757\"\u003enodejs/undici#5757\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: honor SOCKS5 connection timeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5733\"\u003enodejs/undici#5733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(eventsource): validate Last-Event-ID on reconnect by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5746\"\u003enodejs/undici#5746\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid duplicate release attempts by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5745\"\u003enodejs/undici#5745\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(cache): refetch when 304 adds vary fields by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5732\"\u003enodejs/undici#5732\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etypes: expose PendingInterceptor and PendingInterceptorsFormatter on the MockAgent namespace by \u003ca href=\"https://github.com/RaphaelFakhri\"\u003e\u003ccode\u003e@​RaphaelFakhri\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5721\"\u003enodejs/undici#5721\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(codeql): align CodeQL action versions to v4.37.9 by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5759\"\u003enodejs/undici#5759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5760\"\u003enodejs/undici#5760\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(proxy-agent): guard Proxy-Authorization in iterable header containers by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5758\"\u003enodejs/undici#5758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: name the parameters these two blocks describe by \u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): fail the connection on a non-200 h2 extended CONNECT response by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(node-fetch): re-enable the set-cookie header combining test by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5730\"\u003enodejs/undici#5730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward rawHeaders writes through RetryController by \u003ca href=\"https://github.com/official-burak\"\u003e\u003ccode\u003e@​official-burak\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5727\"\u003enodejs/undici#5727\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5738\"\u003enodejs/undici#5738\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/5e541e0b9df7563e5766bbd469fbfe383d9ae6ca\"\u003e\u003ccode\u003e5e541e0\u003c/code\u003e\u003c/a\u003e Bumped v8.10.2 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5771\"\u003e#5771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/eb04cc39954e63e9b46bdf824e6efad9fff2e7b5\"\u003e\u003ccode\u003eeb04cc3\u003c/code\u003e\u003c/a\u003e fix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5738\"\u003e#5738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003e\u003ccode\u003ee905b5b\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e\u003ccode\u003e0160a71\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e\u003ccode\u003e66e1281\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e\u003ccode\u003e7aac7f1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003e\u003ccode\u003ecb75bbb\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e\u003ccode\u003e6d58312\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e\u003ccode\u003e8f5868f\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e\u003ccode\u003e2be07bf\u003c/code\u003e\u003c/a\u003e fix(cache): reject unsafe method response caching\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v8.10.0...v8.10.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=8.10.0\u0026new-version=8.10.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e\n\n\u003c!-- This is an auto-generated description by cubic. --\u003e\n---\n## Summary by cubic\nBumps `undici` from 8.10.0 to 8.10.2 in `dependencies` and `overrides` to address multiple security advisories, and updates the CVE remediation report accordingly. Patch-level update with no expected behavior changes.\n\n\u003csup\u003eWritten for commit 351ea311ed468890814931406e418f68c21b0729. Summary will update on new commits.\u003c/sup\u003e\n\n\u003ca href=\"https://cubic.dev/pr/Trancendos/Tranc3/pull/1197?utm_source=github\" target=\"_blank\" rel=\"noopener noreferrer\" data-no-image-dialog=\"true\"\u003e\u003cpicture\u003e\u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-light.svg\"\u003e\u003cimg alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003c/picture\u003e\u003c/a\u003e\n\n\u003c!-- End of auto-generated description by cubic. --\u003e\n\n","html_url":"https://github.com/Trancendos/Tranc3/pull/1197","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Trancendos%2FTranc3/issues/1197","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1197/packages"}},{"old_version":"7.28.0","new_version":"7.29.1","update_type":"minor","path":null,"pr_created_at":"2026-09-11T13:43:02.000Z","version_change":"7.28.0 → 7.29.1","issue":{"uuid":"5425007069","node_id":"PR_kwDOQELycM8AAAABDJpvbg","number":199,"state":"open","title":"chore(deps): bump the npm_and_yarn group across 1 directory with 20 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T13:43:02.000Z","updated_at":"2026-09-11T13:44:47.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"npm_and_yarn","update_count":20,"packages":[{"name":"next","old_version":"16.2.12","new_version":"16.3.3","repository_url":"https://github.com/vercel/next.js"},{"name":"sanitize-html","old_version":"2.17.0","new_version":"2.17.7","repository_url":"https://github.com/apostrophecms/apostrophe"},{"name":"fast-xml-parser","old_version":"5.9.3","new_version":"5.11.1","repository_url":"https://github.com/NaturalIntelligence/fast-xml-parser"},{"name":"@humanfs/node","old_version":"0.16.7","new_version":"0.16.8","repository_url":"https://github.com/humanwhocodes/humanfs"},{"name":"brace-expansion","old_version":"1.1.14","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"@tiptap/core","old_version":"3.13.0","new_version":"3.31.3","repository_url":"https://github.com/ueberdosis/tiptap"},{"name":"adm-zip","old_version":"0.5.17","new_version":"0.6.1","repository_url":"https://github.com/cthackers/adm-zip"},{"name":"baseline-browser-mapping","old_version":"2.10.43","new_version":"2.11.22","repository_url":"https://github.com/web-platform-dx/baseline-browser-mapping"},{"name":"browserslist","old_version":"4.28.1","new_version":"4.28.9","repository_url":"https://github.com/browserslist/browserslist"},{"name":"dompurify","old_version":"3.4.12","new_version":"3.4.15","repository_url":"https://github.com/cure53/DOMPurify"},{"name":"fast-uri","old_version":"3.1.3","new_version":"3.1.7","repository_url":"https://github.com/fastify/fast-uri"},{"name":"hono","old_version":"4.12.30","new_version":"4.13.7","repository_url":"https://github.com/honojs/hono"},{"name":"ip-address","old_version":"10.2.0","new_version":"10.7.0","repository_url":"https://github.com/beaugunderson/ip-address"},{"name":"js-yaml","old_version":"5.2.1","new_version":"5.4.1","repository_url":"https://github.com/nodeca/js-yaml"},{"name":"qs","old_version":"6.15.3","new_version":"6.16.0","repository_url":"https://github.com/ljharb/qs"},{"name":"smol-toml","old_version":"1.7.0","new_version":"1.8.0","repository_url":"https://github.com/squirrelchat/smol-toml"},{"name":"undici","old_version":"7.28.0","new_version":"7.29.1","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 17 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [next](https://github.com/vercel/next.js) | `16.2.12` | `16.3.3` |\n| [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html) | `2.17.0` | `2.17.7` |\n| [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) | `5.9.3` | `5.11.1` |\n| [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node) | `0.16.7` | `0.16.8` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.14` | `1.1.18` |\n| [@tiptap/core](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core) | `3.13.0` | `3.31.3` |\n| [adm-zip](https://github.com/cthackers/adm-zip) | `0.5.17` | `0.6.1` |\n| [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) | `2.10.43` | `2.11.22` |\n| [browserslist](https://github.com/browserslist/browserslist) | `4.28.1` | `4.28.9` |\n| [dompurify](https://github.com/cure53/DOMPurify) | `3.4.12` | `3.4.15` |\n| [fast-uri](https://github.com/fastify/fast-uri) | `3.1.3` | `3.1.7` |\n| [hono](https://github.com/honojs/hono) | `4.12.30` | `4.13.7` |\n| [ip-address](https://github.com/beaugunderson/ip-address) | `10.2.0` | `10.7.0` |\n| [js-yaml](https://github.com/nodeca/js-yaml) | `5.2.1` | `5.4.1` |\n| [qs](https://github.com/ljharb/qs) | `6.15.3` | `6.16.0` |\n| [smol-toml](https://github.com/squirrelchat/smol-toml) | `1.7.0` | `1.8.0` |\n| [undici](https://github.com/nodejs/undici) | `7.28.0` | `7.29.1` |\n\n\nUpdates `next` from 16.2.12 to 16.3.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003enext's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.3\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eCritical:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36\"\u003eUnauthenticated Remote Code Execution on windows-hosted servers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4\"\u003eUnauthenticated Remote Code Execution in Image Optimization API when AVIF files are used\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.2\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Scope app-entry export validation to files inside the app directory (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97357\"\u003e#97357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[backport] Fix catch-all index page being served for every other slug (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97416\"\u003e#97416\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: don't trace embedded WASM loader helpers (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97353\"\u003e#97353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97463\"\u003e#97463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: retain conditions when replacing resolve request keys (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97453\"\u003e#97453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Fix Turbopack worker chunk loading with asset prefix (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97419\"\u003e#97419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97603\"\u003e#97603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/lubieowoce\"\u003e\u003ccode\u003e@​lubieowoce\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[16.x] Turbopack: don't strip async-module runtime from shared runtime chunks by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96653\"\u003evercel/next.js#96653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] [turbopack] Add \u003ccode\u003eturbopack_ecmascript\u003c/code\u003e and \u003ccode\u003eturbopack_wasm\u003c/code\u003e's embeded FS to \u003ccode\u003einternal_assets_conditions\u003c/code\u003e by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96655\"\u003evercel/next.js#96655\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] [turbopack] Collapse nested promises in the analyzer by \u003ca href=\"https://github.com/sampoder\"\u003e\u003ccode\u003e@​sampoder\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96675\"\u003evercel/next.js#96675\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] fix(next/image): preserve image response after optimization by \u003ca href=\"https://github.com/styfle\"\u003e\u003ccode\u003e@​styfle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96733\"\u003evercel/next.js#96733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.3.x] Default deploy e2e tests to the repo next version by \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96900\"\u003evercel/next.js#96900\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Bump \u003ccode\u003e@​swc/helpers\u003c/code\u003e by \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96885\"\u003evercel/next.js#96885\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [turbopack] Raise registration calls in hoisted modules to the top by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97308\"\u003evercel/next.js#97308\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Fix missing styled-jsx styles in Pages Router SSR on adapter builds by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97302\"\u003evercel/next.js#97302\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [turbopack] Fix HMR for dynamic imports evaluated from layouts by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97317\"\u003evercel/next.js#97317\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Restore the live \u003ccode\u003eheaders()\u003c/code\u003e view of the incoming request by \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97311\"\u003evercel/next.js#97311\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Allow literal exports in \u003ccode\u003e'use cache'\u003c/code\u003e files by \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97312\"\u003evercel/next.js#97312\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Keep the dev validation worker alive across HMR updates by \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97315\"\u003evercel/next.js#97315\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Discard only cache entries that predate a tag revalidation, and reuse completed entries by \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97314\"\u003evercel/next.js#97314\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Encode the cache item name built by \u003ccode\u003eunstable_cache\u003c/code\u003e by \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97313\"\u003evercel/next.js#97313\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.3] [ci] Use OIDC tokens to read private preview builds by \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97258\"\u003evercel/next.js#97258\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [test] Compile the middleware redirect routes up front in dev by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97328\"\u003evercel/next.js#97328\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Fix Nav Inspector request loop on repeat captures by \u003ca href=\"https://github.com/acdlite\"\u003e\u003ccode\u003e@​acdlite\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97326\"\u003evercel/next.js#97326\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Fix: Optimistic routing bugs leading to repeated prefetch loops by \u003ca href=\"https://github.com/acdlite\"\u003e\u003ccode\u003e@​acdlite\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97325\"\u003evercel/next.js#97325\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Retain fewer stale cache versions and use a TTL, plus the mtime fallback by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97304\"\u003evercel/next.js#97304\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Revert i18n localization change for dynamic Pages API routes (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/94905\"\u003e#94905\u003c/a\u003e) by \u003ca href=\"https://github.com/gaojude\"\u003e\u003ccode\u003e@​gaojude\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97330\"\u003evercel/next.js#97330\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/vercel/next.js/compare/v16.3.0...v16.3.1\"\u003ehttps://github.com/vercel/next.js/compare/v16.3.0...v16.3.1\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/a9a1cb7859f178f830ad3773b303130c21b19586\"\u003e\u003ccode\u003ea9a1cb7\u003c/code\u003e\u003c/a\u003e v16.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/968b9fcb26bdeb8e0a861a9df05361474666d51b\"\u003e\u003ccode\u003e968b9fc\u003c/code\u003e\u003c/a\u003e [16.3.x] Fix ISR misses with backslashes in segments when deployed on Windows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/3a15b4ac6ac8e70b1a9b18ecc18e8434462899b3\"\u003e\u003ccode\u003e3a15b4a\u003c/code\u003e\u003c/a\u003e [16.3.x] [next/image]: disable avif image optimization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/7378b51ea05a6745d3676bee00cb4c63aac3dd16\"\u003e\u003ccode\u003e7378b51\u003c/code\u003e\u003c/a\u003e Backport/docs fixes 16.3 (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97649\"\u003e#97649\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/528c1cdfc36bdf8051992febdafe45f17f042010\"\u003e\u003ccode\u003e528c1cd\u003c/code\u003e\u003c/a\u003e [16.3.x] Stop generating error codes (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97780\"\u003e#97780\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/d0ac8828c2fe6026dd7d700488bfd8289711fde6\"\u003e\u003ccode\u003ed0ac882\u003c/code\u003e\u003c/a\u003e v16.3.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/81deb92859e26f8435cc0f37e244573c6638a955\"\u003e\u003ccode\u003e81deb92\u003c/code\u003e\u003c/a\u003e [16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/cd714d9fceae7aec9d467598792b0c844f710607\"\u003e\u003ccode\u003ecd714d9\u003c/code\u003e\u003c/a\u003e [16.3.x] Fix Turbopack worker chunk loading with asset prefix (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97419\"\u003e#97419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/5ac2327e62784eacdf6ab7db8629fd05c5f5fcdf\"\u003e\u003ccode\u003e5ac2327\u003c/code\u003e\u003c/a\u003e [16.3] Turbopack: retain conditions when replacing resolve request keys (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97453\"\u003e#97453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/0ccb3e7f5d6b55c5c9e215248b264a428aee7dcb\"\u003e\u003ccode\u003e0ccb3e7\u003c/code\u003e\u003c/a\u003e [16.3] Turbopack: don't trace embedded WASM loader helpers (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97353\"\u003e#97353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97463\"\u003e#97463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/compare/v16.2.12...v16.3.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `sanitize-html` from 2.17.0 to 2.17.7\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apostrophecms/apostrophe/blob/main/packages/sanitize-html/CHANGELOG.md\"\u003esanitize-html's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.17.7 (2026-08-13)\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an XSS / URL scheme policy bypass affecting configurations that allow the SVG animation elements (\u003ccode\u003eanimate\u003c/code\u003e, \u003ccode\u003eanimateColor\u003c/code\u003e, \u003ccode\u003eanimateMotion\u003c/code\u003e, \u003ccode\u003eanimateTransform\u003c/code\u003e or \u003ccode\u003eset\u003c/code\u003e) together with \u003ccode\u003eattributeName\u003c/code\u003e and one of the animation value attributes. The default configuration was not affected, as these elements are not in the default \u003ccode\u003eallowedTags\u003c/code\u003e. \u003ccode\u003eapostrophecms\u003c/code\u003e was not affected. Thanks to \u003ca href=\"https://github.com/koyokr\"\u003ekoyokr\u003c/a\u003e for responsibly disclosing the vulnerability (GHSA-g8qq-57p8-ggw5).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.17.6 (2026-07-10)\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAllow transformTags to emit text when textFilter is set, even if the tag is initially empty. This is consistent with the documentation. Thanks to \u003ca href=\"https://github.com/spokodev\"\u003espokodev\u003c/a\u003e for the fix.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an XSS/allowlist bypass in which the contents of a raw-text element (\u003ccode\u003etextarea\u003c/code\u003e or \u003ccode\u003exmp\u003c/code\u003e) nested inside an \u003ccode\u003esvg\u003c/code\u003e or \u003ccode\u003emath\u003c/code\u003e root were re-emitted without HTML-escaping. \u003ccode\u003esanitize-html\u003c/code\u003e treated that content as inert raw text because \u003ccode\u003ehtmlparser2\u003c/code\u003e 10.x classified raw-text elements by tag name and ignored the namespace, but a real HTML5 parser treats \u003ccode\u003etextarea\u003c/code\u003e/\u003ccode\u003exmp\u003c/code\u003e as ordinary foreign elements inside SVG/MathML and re-parses their contents as live markup. As a result, markup and event-handler attributes that the allowlist never permitted (for example \u003ccode\u003e\u0026lt;svg\u0026gt;\u0026lt;textarea\u0026gt;\u0026lt;img src=x onerror=alert(1)\u0026gt;\u003c/code\u003e) could survive sanitization and execute in the browser. This is now fixed on two fronts: \u003ccode\u003ehtmlparser2\u003c/code\u003e was upgraded to 12.x, which is namespace-aware and parses \u003ccode\u003etextarea\u003c/code\u003e/\u003ccode\u003exmp\u003c/code\u003e inside SVG/MathML as ordinary elements, so their non-allowlisted children (such as the injected \u003ccode\u003eimg\u003c/code\u003e) are dropped by the allowlist instead of being preserved as raw text; and any raw-text content \u003ccode\u003esanitize-html\u003c/code\u003e still emits for these tags (at HTML integration points such as \u003ccode\u003eforeignObject\u003c/code\u003e/\u003ccode\u003emtext\u003c/code\u003e, or outside foreign content) is always HTML-escaped. The default configuration is not affected; the precondition is an \u003ccode\u003eallowedTags\u003c/code\u003e that includes \u003ccode\u003esvg\u003c/code\u003e or \u003ccode\u003emath\u003c/code\u003e together with \u003ccode\u003etextarea\u003c/code\u003e or \u003ccode\u003exmp\u003c/code\u003e. Thanks to \u003ca href=\"https://github.com/khoadb175\"\u003ekhoadb175\u003c/a\u003e for responsibly disclosing the vulnerability.\u003c/li\u003e\n\u003cli\u003eFixed a mutation-XSS / \u003ccode\u003eallowedTags\u003c/code\u003e bypass affecting configurations that allow the \u003ccode\u003etextarea\u003c/code\u003e or \u003ccode\u003exmp\u003c/code\u003e raw-text tags. \u003ccode\u003ehtmlparser2\u003c/code\u003e 10.x did not recognize an end tag with a trailing solidus (e.g. \u003ccode\u003e\u0026lt;/textarea/\u0026gt;\u003c/code\u003e) as closing the element, so it kept the following markup as raw text, but a spec-compliant browser treats \u003ccode\u003e\u0026lt;/textarea/\u0026gt;\u003c/code\u003e as a valid close and parses that markup as a live element. Because raw-text content was re-emitted without escaping, a payload such as \u003ccode\u003e\u0026lt;textarea\u0026gt;\u0026lt;/textarea/\u0026gt;\u0026lt;img src=x onerror=...\u0026gt;\u003c/code\u003e could smuggle non-allowlisted, executable markup through the sanitizer. The default configuration was not affected. This is now defended at two layers: \u003ccode\u003ehtmlparser2\u003c/code\u003e was upgraded to 12.x, whose tokenizer closes these end tags correctly, and the raw text sanitize-html emits for these tags is always escaped so no \u003ccode\u003e\u0026lt;\u003c/code\u003e can reopen a tag when the output is re-parsed (\u003ccode\u003etextarea\u003c/code\u003e, an RCDATA element whose entities \u003ccode\u003ehtmlparser2\u003c/code\u003e decodes, is escaped like normal text, while \u003ccode\u003exmp\u003c/code\u003e, a raw-text element, has only its angle brackets escaped to avoid double-encoding already-encoded entities). Because \u003ccode\u003ehtmlparser2\u003c/code\u003e is ESM-only from version 11 onward, \u003ccode\u003esanitize-html\u003c/code\u003e now requires Node.js \u003ccode\u003e\u0026gt;=22.12.0\u003c/code\u003e (the first 22.x release in which \u003ccode\u003erequire()\u003c/code\u003e of an ES module is available unflagged). Thanks to \u003ca href=\"https://github.com/bibu123456\"\u003ebibu123456\u003c/a\u003e for reporting the vulnerability and \u003ca href=\"https://github.com/Kayiz-PT\"\u003eKayiz-PT\u003c/a\u003e for coordinating the disclosure (GHSA-jxwj-j7wr-gfrw).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.17.5 (2026-06-10)\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded a number of new attributes to be protected against unsafe URLs, e.g. \u003ccode\u003ejavascript:\u003c/code\u003e and similar. None of these are used in the default configuration of \u003ccode\u003esanitize-html\u003c/code\u003e or \u003ccode\u003eapostrophe\u003c/code\u003e or likely to be used there, and some attributes, like an \u003ccode\u003eaction\u003c/code\u003e for a \u003ccode\u003eform\u003c/code\u003e, are inherently unsafe to allow if XSS protection is your goal. Nevertheless it makes sense to block certain URL types where they are not appropriate. Some attributes are not supported at all by modern browsers but are included for completeness. Thanks to \u003ca href=\"https://github.com/crattack\"\u003ecrattack\u003c/a\u003e for reporting the vulnerability.\u003c/li\u003e\n\u003cli\u003eAddress a potential vulnerability when nonTextTags is configured in a nonstandard way. While it is never a good idea to remove known non-text tags from the standard list e.g. script, styles, etc., this change ensures that doing so does not result in nested tags being passed through without sanitization when they are not expressly allowed. (ApostropheCMS would never trigger this situation.) Thanks to \u003ca href=\"https://github.com/Dipanshusinghh\"\u003eDipanshu singh\u003c/a\u003e for pointing out the issue and contributing the fix.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.17.4\u003c/h2\u003e\n\u003ch3\u003eChanges\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003esanitize-html\u003c/code\u003e and \u003ccode\u003elaunder\u003c/code\u003e now share a single implementation of \u003ccode\u003enaughtyHref\u003c/code\u003e, based on that which previously existed in \u003ccode\u003esanitize-html\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity vulnerability: the xmp tag could be used to pass forbidden markup through sanitize-html, even when xmp itself is not explicitly allowed All users of sanitize-html should update immediately. Thanks to \u003ca href=\"https://github.com/sushi-gif\"\u003eVincenzo Turturro\u003c/a\u003e for reporting the vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.17.3 (2026-04-15)\u003c/h2\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix vulnerability introduced in version 2.17.2 that allowed XSS attacks if the developer chose to permit \u003ccode\u003eoption\u003c/code\u003e tags. There was no vulnerability when not explicitly allowing \u003ccode\u003eoption\u003c/code\u003e tags.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.17.2 (2026-03-19)\u003c/h2\u003e\n\u003ch3\u003eChanges\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003ehtmlparser2\u003c/code\u003e from 8.x to 10.1.0. This improves security by correctly decoding zero-padded numeric character references (e.g., \u003ccode\u003e\u0026amp;[#0000001](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html/issues/0000001)\u003c/code\u003e) that previously bypassed \u003ccode\u003ejavascript:\u003c/code\u003e URL detection. Also fixes double-encoding of entities inside raw text elements like \u003ccode\u003etextarea\u003c/code\u003e and \u003ccode\u003eoption\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.17.1 (2026-02-18)\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apostrophecms/apostrophe/commit/72f4531e7b491738049eec423d0c1c2342828e5f\"\u003e\u003ccode\u003e72f4531\u003c/code\u003e\u003c/a\u003e Latest reconciliation q2 m3 2026 (\u003ca href=\"https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html/issues/5555\"\u003e#5555\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apostrophecms/apostrophe/commit/207846a3aec6b1914a2b9f4dc36d45daf6a4afb9\"\u003e\u003ccode\u003e207846a\u003c/code\u003e\u003c/a\u003e ready for 4.32.0 release (\u003ca href=\"https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html/issues/5513\"\u003e#5513\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apostrophecms/apostrophe/commit/f82003349abf4245babdb1afcb225255a9694979\"\u003e\u003ccode\u003ef820033\u003c/code\u003e\u003c/a\u003e Latest reconciliation q2 m2 (\u003ca href=\"https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html/issues/5511\"\u003e#5511\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apostrophecms/apostrophe/commit/24275081ab67f2060782e141dc3554721c1bae5a\"\u003e\u003ccode\u003e2427508\u003c/code\u003e\u003c/a\u003e release and changelog edits (\u003ca href=\"https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html/issues/5465\"\u003e#5465\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apostrophecms/apostrophe/commit/5a88e9630cbbdde33154ef8abe7557ddf7be418b\"\u003e\u003ccode\u003e5a88e96\u003c/code\u003e\u003c/a\u003e Latest security q2 (\u003ca href=\"https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html/issues/5464\"\u003e#5464\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apostrophecms/apostrophe/commit/958d16214ff4b94b9280fddd088060ff401ded0d\"\u003e\u003ccode\u003e958d162\u003c/code\u003e\u003c/a\u003e merge main to latest (\u003ca href=\"https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html/issues/5460\"\u003e#5460\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apostrophecms/apostrophe/commit/e9b0ab0849a5dfea0f75335fbdf99b5c6bf9e4b3\"\u003e\u003ccode\u003ee9b0ab0\u003c/code\u003e\u003c/a\u003e release only (changelogs formatted) (\u003ca href=\"https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html/issues/5408\"\u003e#5408\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apostrophecms/apostrophe/commit/f03fa5b7746132bf46244036ab961bba995b611d\"\u003e\u003ccode\u003ef03fa5b\u003c/code\u003e\u003c/a\u003e Latest security merge (\u003ca href=\"https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html/issues/5407\"\u003e#5407\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apostrophecms/apostrophe/commit/96cf174486e1387948e189786c2d574cf7c3f3d0\"\u003e\u003ccode\u003e96cf174\u003c/code\u003e\u003c/a\u003e For release only (\u003ca href=\"https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html/issues/5381\"\u003e#5381\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apostrophecms/apostrophe/commit/7ca2d16237c72718ef7e5c7ae0458e6027ac4f64\"\u003e\u003ccode\u003e7ca2d16\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apostrophecms/apostrophe/commits/sanitize-html@2.17.7/packages/sanitize-html\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-xml-parser` from 5.9.3 to 5.11.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/releases\"\u003efast-xml-parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.11.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump actions/checkout from 7.0.0 to 7.0.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/858\"\u003eNaturalIntelligence/fast-xml-parser#858\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump zizmorcore/zizmor-action from 0.5.7 to 0.6.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/856\"\u003eNaturalIntelligence/fast-xml-parser#856\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/setup-node from 6.4.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/854\"\u003eNaturalIntelligence/fast-xml-parser#854\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: fix two 404 documentation links by \u003ca href=\"https://github.com/rajanpanth\"\u003e\u003ccode\u003e@​rajanpanth\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/862\"\u003eNaturalIntelligence/fast-xml-parser#862\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rajanpanth\"\u003e\u003ccode\u003e@​rajanpanth\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/862\"\u003eNaturalIntelligence/fast-xml-parser#862\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.11.0...v5.11.1\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.11.0...v5.11.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.11.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eadd support for endIndex in node metadata (5.x edition) by \u003ca href=\"https://github.com/Wain-PC\"\u003e\u003ccode\u003e@​Wain-PC\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/850\"\u003eNaturalIntelligence/fast-xml-parser#850\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: don't crash on a closing tag with no matching opening tag by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/861\"\u003eNaturalIntelligence/fast-xml-parser#861\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Wain-PC\"\u003e\u003ccode\u003e@​Wain-PC\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/850\"\u003eNaturalIntelligence/fast-xml-parser#850\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/861\"\u003eNaturalIntelligence/fast-xml-parser#861\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.10.1...v5.11.0\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.10.1...v5.11.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.10.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.10.0...v5.10.1\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.10.0...v5.10.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.10.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump actions/checkout from 6.0.3 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/849\"\u003eNaturalIntelligence/fast-xml-parser#849\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump zizmorcore/zizmor-action from 0.5.6 to 0.5.7 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/848\"\u003eNaturalIntelligence/fast-xml-parser#848\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.3...v5.10.0\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.3...v5.10.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md\"\u003efast-xml-parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003eNote: If you find missing information about particular minor version, that version must have been changed without any functional change in this library.\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003cp\u003eNote: Due to some last quick changes on v4, detail of v4.5.3 \u0026amp; v4.5.4 are not updated here. v4.5.4x is the last tag of v4 in github repository. I'm extremely sorry for the confusion\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e5.11.1 / 2026-08-27\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efix: validator; Replace regex with a single-pass scanner for attribute tokens, eliminating quadratic behavior on long whitespace runs.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e5.11.0 / 2026-08-16\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efeat: support for endIndex in node metadata (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/850\"\u003e#850\u003c/a\u003e) [By \u003ca href=\"https://github.com/Wain-PC\"\u003ePavel Dranichnikov\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003efix: don't crash on a closing tag with no matching opening tag (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/861\"\u003e#861\u003c/a\u003e) [By \u003ca href=\"https://github.com/hdimer\"\u003eHaïm Dimer\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003efix: DOCTYPE to read SYSTEM/PUBLIC\u003c/li\u003e\n\u003cli\u003edeps: strnum v2.4.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e5.10.1 / 2026-07-17\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efix: multiple DOCTYPE declarations.\u003c/li\u003e\n\u003cli\u003edeps: \u003ccode\u003e@nodable/entities\u003c/code\u003e for treeshaking\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e5.10.0 / 2026-07-11\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eupgrade:\n\u003cul\u003e\n\u003cli\u003exml-naming v0.3.0: cache support\u003c/li\u003e\n\u003cli\u003ePEM v1.6.2: sibling bug fix\u003c/li\u003e\n\u003cli\u003eis-unsafe v2.0.0: tree shaking\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e*\u003cem\u003e5.9.3 / 2026-06-19\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eupdate strnum\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e*\u003cem\u003e5.9.2 / 2026-06-17\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003edummy release to test changes in github action\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e*\u003cem\u003e5.9.1 / 2026-06-17\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003edummy release to test release from github action\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e*\u003cem\u003e5.9.0 / 2026-06-15\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eupdate strnum to 2.3.0\n\u003cul\u003e\n\u003cli\u003eyou can set hex, binary, enotation, infinity, unicode\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003evalidate unsafe HTML or XML data in doctype entities unsing 'is-unsafe' library.\nUser can override rules by overriding EntityDecoder.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e*\u003cem\u003e5.8.0 / 2026-05-12\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eintegrate xml-naming to validate DOCTYPE entity name and notation name (using qname becaue of backward compatibility)\n\u003cul\u003e\n\u003cli\u003eThis will consider xml-version as well. '1.0' is default\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eupdate strnum to 2.3.0\n\u003cul\u003e\n\u003cli\u003eYou can set octal and binary parsing which is bydeault off\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eupdate fast-xml-builder to 1.2.0\n\u003cul\u003e\n\u003cli\u003ecan sanitize tag names if found invalid\u003c/li\u003e\n\u003cli\u003efix format output\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e5.7.3 / 2006-05-05\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efix: alwaysCreateTextNode should create text node when attributes are present for self closing node\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/3617550adfb280989f482d662b7e9ece55a32a34\"\u003e\u003ccode\u003e3617550\u003c/code\u003e\u003c/a\u003e 5.11.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/6021128c3251d4c1456d2c6cd8442a5005a1f39a\"\u003e\u003ccode\u003e6021128\u003c/code\u003e\u003c/a\u003e update for release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/6ddcb65f240005988457af6af6dd68fa0947acf5\"\u003e\u003ccode\u003e6ddcb65\u003c/code\u003e\u003c/a\u003e remove regex from validator\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/7d608151078d47040841e9804d490feb5c07dfe7\"\u003e\u003ccode\u003e7d60815\u003c/code\u003e\u003c/a\u003e docs: fix two 404 documentation links (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/862\"\u003e#862\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/4e3857b3ab78f0b8e37e70e5cd08f2bc1ac726a8\"\u003e\u003ccode\u003e4e3857b\u003c/code\u003e\u003c/a\u003e Bump actions/setup-node from 6.4.0 to 7.0.0 (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/854\"\u003e#854\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/fcc62fb8f6f620c95dd1c9ab7aac3061f0905592\"\u003e\u003ccode\u003efcc62fb\u003c/code\u003e\u003c/a\u003e Bump zizmorcore/zizmor-action from 0.5.7 to 0.6.1 (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/856\"\u003e#856\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/23a9019d1e481ad3d1b9aef5266194f4e366f14e\"\u003e\u003ccode\u003e23a9019\u003c/code\u003e\u003c/a\u003e Bump actions/checkout from 7.0.0 to 7.0.1 (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/858\"\u003e#858\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/f3c69ae2a9a1a1df4e4be9ca954ddcdf6563d16a\"\u003e\u003ccode\u003ef3c69ae\u003c/code\u003e\u003c/a\u003e 5.11.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/fdbd072e23fcc6ea1a4779aecdd7196620f432d7\"\u003e\u003ccode\u003efdbd072\u003c/code\u003e\u003c/a\u003e update for release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/c5fcb5b1f9178ed07a078b08f53382ee49268ba3\"\u003e\u003ccode\u003ec5fcb5b\u003c/code\u003e\u003c/a\u003e update lock files\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.3...v5.11.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.14 to 8.5.23\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eraws\u003c/code\u003e after rehydrating a JSON AST (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed putting parent-less node in \u003ccode\u003enodes\u003c/code\u003e of new node (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed computing \u003ccode\u003eoffset\u003c/code\u003e in \u003ccode\u003epositionBy()\u003c/code\u003e (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003erangeBy()\u003c/code\u003e on \u003ccode\u003eindex: 0\u003c/code\u003e (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed declaration parsing performance (by \u003ca href=\"https://github.com/homanp\"\u003e\u003ccode\u003e@​homanp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/eb9e1fe793740bb3280bdf5bf98147f857f011bd\"\u003e\u003ccode\u003eeb9e1fe\u003c/code\u003e\u003c/a\u003e Release 8.5.23 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/9d19c78ac91108b3f7d7130e55c6fa806c0efb84\"\u003e\u003ccode\u003e9d19c78\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8\"\u003e\u003ccode\u003e7beca13\u003c/code\u003e\u003c/a\u003e Does no load source map file without opts.from\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/decea51421682341401575b3740709fda0e12930\"\u003e\u003ccode\u003edecea51\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/c18e30d126395d42a0726aa00e03a8f1088985ae\"\u003e\u003ccode\u003ec18e30d\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/98a39ad73d163a90be924d5126c771262110f1fc\"\u003e\u003ccode\u003e98a39ad\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/a3e48c492ddec0e4879d513b8b995fee887af352\"\u003e\u003ccode\u003ea3e48c4\u003c/code\u003e\u003c/a\u003e Release 8.5.22 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f49d6911795f53b2cfe023bb686bf1144ec30618\"\u003e\u003ccode\u003ef49d691\u003c/code\u003e\u003c/a\u003e Fix custom property losing its semicolon before a comment (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2117\"\u003e#2117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/28e0daf8f2fe5ba9e19ea3f8c27c8fe176f9419e\"\u003e\u003ccode\u003e28e0daf\u003c/code\u003e\u003c/a\u003e Release 8.5.21 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3d2b4e43e38274f233b5609d09687cadad8215d9\"\u003e\u003ccode\u003e3d2b4e4\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.14...8.5.23\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nanoid` from 3.3.11 to 3.3.19\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/releases\"\u003enanoid's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed breaking Nano ID by requesting big ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/blob/main/CHANGELOG.md\"\u003enanoid's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID (by \u003ca href=\"https://github.com/geoffrey-diederichs\"\u003e\u003ccode\u003e@​geoffrey-diederichs\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed breaking Nano ID by requesting big ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/eb63bd6775188dc35d143bf24868be094f19b5ee\"\u003e\u003ccode\u003eeb63bd6\u003c/code\u003e\u003c/a\u003e Release 3.3.19 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9067e0361a643ab2c94ddd67606efbf275f6c0dd\"\u003e\u003ccode\u003e9067e03\u003c/code\u003e\u003c/a\u003e Sync CJS and ESM\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9ad98052b316c5e707f8098ace509d2ae165e54d\"\u003e\u003ccode\u003e9ad9805\u003c/code\u003e\u003c/a\u003e Release 3.3.18 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/55e50a0621ec084b4bb4000ea4e86e1191bd3da8\"\u003e\u003ccode\u003e55e50a0\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e10f8d40ce9d1ab47f66d65a16b48086432730d0\"\u003e\u003ccode\u003ee10f8d4\u003c/code\u003e\u003c/a\u003e Update index.native.js (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/606\"\u003e#606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/73d67168136b36fd3b644159b0cff149da4905d9\"\u003e\u003ccode\u003e73d6716\u003c/code\u003e\u003c/a\u003e Release 3.3.17 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/f9d13f150847d117877adee3460a46eceb0cf49b\"\u003e\u003ccode\u003ef9d13f1\u003c/code\u003e\u003c/a\u003e Sync 0 size behaviour with PostCSS 5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9760e112757cf7d46a79abd7a133bc4958757bb8\"\u003e\u003ccode\u003e9760e11\u003c/code\u003e\u003c/a\u003e Release 3.3.16 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66d\"\u003e\u003ccode\u003ee835c9b\u003c/code\u003e\u003c/a\u003e fix(non-secure): clamp negative size to prevent infinite loop (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/601\"\u003e#601\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/96dd086eb24396a275fa93ee78d73b2fece35809\"\u003e\u003ccode\u003e96dd086\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ai/nanoid/compare/3.3.11...3.3.19\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for nanoid since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@humanfs/node` from 0.16.7 to 0.16.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/humanwhocodes/humanfs/releases\"\u003e@​humanfs/node's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003enode: v0.16.8\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/compare/node-v0.16.7...node-v0.16.8\"\u003e0.16.8\u003c/a\u003e (2026-04-17)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eInclude type dependencies at runtime (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e956ce7a\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/humanwhocodes/humanfs/issues/145\"\u003e#145\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe following workspace dependencies were updated\n\u003cul\u003e\n\u003cli\u003edependencies\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​humanfs/core\u003c/code\u003e bumped from ^0.19.1 to ^0.19.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/humanwhocodes/humanfs/blob/main/packages/node/CHANGELOG.md\"\u003e@​humanfs/node's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/compare/node-v0.16.7...node-v0.16.8\"\u003e0.16.8\u003c/a\u003e (2026-04-17)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEnsure symlinks are copied as symlinks in \u003ccode\u003ecopy()\u003c/code\u003e and \u003ccode\u003ecopyAll()\u003c/code\u003e (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/22bbaa4487a3e6c1197ca619840de4615d0c3404\"\u003e22bbaa44\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eInclude type dependencies at runtime (\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e956ce7a\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/humanwhocodes/humanfs/issues/145\"\u003e#145\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe following workspace dependencies were updated\n\u003cul\u003e\n\u003cli\u003edependencies\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​humanfs/core\u003c/code\u003e bumped from ^0.19.1 to ^0.19.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/e96070e897f017ae8abd2b0676d98d14e49665cc\"\u003e\u003ccode\u003ee96070e\u003c/code\u003e\u003c/a\u003e chore: release main (\u003ca href=\"https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node/issues/146\"\u003e#146\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/22bbaa4487a3e6c1197ca619840de4615d0c3404\"\u003e\u003ccode\u003e22bbaa4\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/humanwhocodes/humanfs/commit/956ce7aac2a998d0af23b7cb08e7630b69693138\"\u003e\u003ccode\u003e956ce7a\u003c/code\u003e\u003c/a\u003e fix: Include type dependencies at runtime\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/humanwhocodes/humanfs/commits/node-v0.16.8/packages/node\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.14 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24\"\u003e\u003ccode\u003e2203f4f\u003c/code\u003e\u003c/a\u003e 1.1.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd\"\u003e\u003ccode\u003e0b09384\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@tiptap/core` from 3.13.0 to 3.31.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ueberdosis/tiptap/releases\"\u003e@​tiptap/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.31.3\u003c/h2\u003e\n\u003ch3\u003e\u003ccode\u003e@​tiptap/extension-collaboration-caret\u003c/code\u003e\u003c/h3\u003e\n\u003ch4\u003ePatch Changes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug which allowed potentially unsafe color values being sent by other clients. Those unsafe colors received from collaboration users are now ignored.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e\u003ccode\u003e@​tiptap/react\u003c/code\u003e\u003c/h3\u003e\n\u003ch4\u003ePatch Changes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eFix a TypeScript error (TS2694) in the shipped type declarations when \u003ccode\u003eskipLibCheck\u003c/code\u003e is turned off.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.31.2\u003c/h2\u003e\n\u003ch3\u003e\u003ccode\u003e@​tiptap/pm\u003c/code\u003e\u003c/h3\u003e\n\u003ch4\u003ePatch Changes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003eprosemirror-view\u003c/code\u003e to \u003ccode\u003e^1.42.3\u003c/code\u003e, which fixes an XSS vulnerability where pasting crafted HTML could run arbitrary JavaScript (GHSA-c8x8-7fp4-3x9w).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.31.1\u003c/h2\u003e\n\u003ch3\u003e\u003ccode\u003e@​tiptap/core\u003c/code\u003e\u003c/h3\u003e\n\u003ch4\u003ePatch Changes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eFix freezes in framework-based node views on iOS and Android\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.31.0\u003c/h2\u003e\n\u003ch3\u003e\u003ccode\u003e@​tiptap/react\u003c/code\u003e\u003c/h3\u003e\n\u003ch4\u003eMinor Changes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003ee7bf804: Align \u003ccode\u003eselected\u003c/code\u003e with ProseMirror node selections by default, expose text selections through \u003ccode\u003eselectionInside\u003c/code\u003e, and keep \u003ccode\u003eselectedOnTextSelection\u003c/code\u003e compatible.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev3.30.6\u003c/h2\u003e\n\u003ch3\u003e\u003ccode\u003e@​tiptap/core\u003c/code\u003e\u003c/h3\u003e\n\u003ch4\u003ePatch Changes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eNested lists exported to Markdown now keep their hierarchy when the file is read back by other Markdown tools.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e\u003ccode\u003e@​tiptap/extension-list\u003c/code\u003e\u003c/h3\u003e\n\u003ch4\u003ePatch Changes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eNested lists exported to Markdown now keep their hierarchy when the file is read back by other Markdown tools.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e\u003ccode\u003e@​tiptap/extension-youtube\u003c/code\u003e\u003c/h3\u003e\n\u003ch4\u003ePatch Changes\u003c/h4\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ueberdosis/tiptap/blob/v3.31.3/packages/core/CHANGELOG.md\"\u003e@​tiptap/core's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.31.3\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tiptap/pm\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.31.3\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.31.2\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dependencies [c56b4c9]\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tiptap/pm\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.31.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.31.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecd32a2f: Fix freezes in framework-based node views on iOS and Android\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tiptap/pm\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.31.1\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.31.0\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tiptap/pm\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.31.0\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.30.6\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e9f844ab: Nested lists exported to Markdown now keep their hierarchy when the file is read back by other Markdown tools.\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tiptap/pm\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.30.6\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.30.5\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ed0d499b: Fix a denial-of-service risk where crafted block or inline Markdown attributes could consume excessive CPU and block the browser or server event loop.\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tiptap/pm\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.30.5\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.30.4\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e01d7af8: Prevent untrusted HTML attributes from changing an object's prototype when merged with \u003ccode\u003emergeAttributes\u003c/code\u003e.\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@​tiptap/pm\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.30.4\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.30.3\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ueberdosis/tiptap/commit/35d2110ecb118a2d80f2b5823b7e4f629d948894\"\u003e\u003ccode\u003e35d2110\u003c/code\u003e\u003c/a\u003e chore(release): release new stable release (\u003ca href=\"https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core/issues/8311\"\u003e#8311\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ueberdosis/tiptap/commit/f38fec0a4cc520ff2181411360b83ca987808268\"\u003e\u003ccode\u003ef38fec0\u003c/code\u003e\u003c/a\u003e chore(release): release new stable release (\u003ca href=\"https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core/issues/8304\"\u003e#8304\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ueberdosis/tiptap/commit/bd35333232c9378302f9c3af83d7d1b6756ad6ee\"\u003e\u003ccode\u003ebd35333\u003c/code\u003e\u003c/a\u003e chore(release): release new stable release (\u003ca href=\"https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core/issues/8297\"\u003e#8297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ueberdosis/tiptap/commit/cd32a2fa058a32bfce9f2505f32e72fb9cbef8ee\"\u003e\u003ccode\u003ecd32a2f\u003c/code\u003e\u003c/a\u003e fix: ignore iOS chrome mutations outside contentDOM (\u003ca href=\"https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core/issues/8221\"\u003e#8221\u003c/a\u003e) (\u003ca href=\"https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core/issues/8296\"\u003e#8296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ueberdosis/tiptap/commit/0280f4a161d2fbf56e92d8b4e216c6792fde7146\"\u003e\u003ccode\u003e0280f4a\u003c/code\u003e\u003c/a\u003e chore(release): release new stable release (\u003ca href=\"https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core/issues/8292\"\u003e#8292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ueberdosis/tiptap/commit/e7bf804f8d37b4b69bcd8a410023a37f8a9818b7\"\u003e\u003ccode\u003ee7bf804\u003c/code\u003e\u003c/a\u003e fix: linting\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ueberdosis/tiptap/commit/5302fda4748a439b395e6be81bd1e825dbfcc08e\"\u003e\u003ccode\u003e5302fda\u003c/code\u003e\u003c/a\u003e chore(release): release new stable release (\u003ca href=\"https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core/issues/8264\"\u003e#8264\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ueberdosis/tiptap/commit/9f844ab7f3068ec3efee6f211343f0eae3c10699\"\u003e\u003ccode\u003e9f844ab\u003c/code\u003e\u003c/a\u003e fix(markdown): indent nested list content to the parent marker (\u003ca href=\"https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core/issues/8219\"\u003e#8219\u003c/a\u003e) (\u003ca href=\"https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core/issues/8274\"\u003e#8274\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ueberdosis/tiptap/commit/b0c188b1bc919b204beace074de36f5cb2a2d961\"\u003e\u003ccode\u003eb0c188b\u003c/code\u003e\u003c/a\u003e chore(release): release new stable release (\u003ca href=\"https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core/issues/8261\"\u003e#8261\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ueberdosis/tiptap/commit/d0d499be3cce633cf54ca9aa9f3d8a5a1f98bd74\"\u003e\u003ccode\u003ed0d499b\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ueberdosis/tiptap/commits/v3.31.3/packages/core\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​tiptap/core\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `adm-zip` from 0.5.17 to 0.6.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cthackers/adm-zip/releases\"\u003eadm-zip's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.6.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cthackers/adm-zip/compare/v0.6.0...v0.6.1\"\u003ehttps://github.com/cthackers/adm-zip/compare/v0.6.0...v0.6.1\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated dev dependencies\u003c/li\u003e\n\u003cli\u003eFixed uncaught crash in async decompression on malformed DEFLATE data\u003c/li\u003e\n\u003cli\u003eFixed addLocalFolder following symlinks out of the archived folder\u003c/li\u003e\n\u003cli\u003eStripped setuid/setgid/sticky bits from extracted file permissions\u003c/li\u003e\n\u003cli\u003eEnforced the decompression size cap on the async path and for size 0\u003c/li\u003e\n\u003cli\u003eRejected archives with duplicate entry names\u003c/li\u003e\n\u003cli\u003eBlocked extraction from writing through symlinks inside the target\u003c/li\u003e\n\u003cli\u003eRouted malformed-header parse errors through the async callback\u003c/li\u003e\n\u003cli\u003eRejected zip entries whose declared data extent runs past the buffer\u003c/li\u003e\n\u003cli\u003eFixed addLocalFolderPromise hanging on empty folders and swallowing errors\u003c/li\u003e\n\u003cli\u003eFixed addLocalFolderAsync2 mangling local paths on Windows\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.6.0\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cthackers/adm-zip/compare/v0.5.18...v0.6.0\"\u003ehttps://github.com/cthackers/adm-zip/compare/v0.5.18...v0.6.0\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eThis release fixes a security vulnerability (CVE-2026-39244), resolves several long-standing bugs, ships built-in TypeScript types, and includes two behavior changes worth reading before you upgrade.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eextractEntryTo(dirEntry, target, maintainEntryPath = false) now preserves subdirectories instead of flattening files into the target folder by basename (which also silently overwrote same-named files). (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/306\"\u003e#306\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eExtraction no longer fails when the modification time can't be set — utimes is now best-effort. (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/379\"\u003e#379\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMinimum Node.js is now 14 (the code already required it; engines was incorrectly \u0026gt;=12).\u003c/li\u003e\n\u003cli\u003eCVE-2026-39244 — a crafted archive declaring a huge uncompressed size could force an unbounded Buffer.alloc and OOM the process; allocation is now bounded by the data actually present. Reported by Daniel Púa (devploit), Anh Hong, and José Antonio Zamudio Amaya. (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/568\"\u003e#568\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHardened entry-name lookup against object injection (\u003cstrong\u003eproto\u003c/strong\u003e names). Prototype-less table.\u003c/li\u003e\n\u003cli\u003eData-descriptor regression rejecting valid archives (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/548\"\u003e#548\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/533\"\u003e#533\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/554\"\u003e#554\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDirectory permissions not restored on extract (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/530\"\u003e#530\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eInfinite recursion on symlink loops in addLocalFolder (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/541\"\u003e#541\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUncaught process crash in writeFileToAsync on write failure (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/470\"\u003e#470\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/459\"\u003e#459\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/402\"\u003e#402\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEmpty name on directory entries (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/466\"\u003e#466\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etest() always returned false for archives with files\u003c/li\u003e\n\u003cli\u003e~6× faster entry sorting for large archives\u003c/li\u003e\n\u003cli\u003eBuilt-in TypeScript definitions (types.d.ts) — you can drop \u003ccode\u003e@​types/adm-zip\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.5.18\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump js-yaml from 4.1.1 to 4.3.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/pull/566\"\u003ecthackers/adm-zip#566\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix corrupted zip when round-tripping entries with a data descriptor (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/555\"\u003e#555\u003c/a\u003e) by \u003ca href=\"https://github.com/JohnJunior\"\u003e\u003ccode\u003e@​JohnJunior\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/pull/564\"\u003ecthackers/adm-zip#564\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eprevent crashes when process.versions is an empty object by \u003ca href=\"https://github.com/matt-fidd\"\u003e\u003ccode\u003e@​matt-fidd\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/pull/551\"\u003ecthackers/adm-zip#551\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003esupport for writing zip64 by \u003ca href=\"https://github.com/mielverkerken\"\u003e\u003ccode\u003e@​mielverkerken\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/pull/562\"\u003ecthackers/adm-zip#562\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix Archive Utility failure on zips with empty directories (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/558\"\u003e#558\u003c/a\u003e) by \u003ca href=\"https://github.com/JohnJunior\"\u003e\u003ccode\u003e@​JohnJunior\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/pull/563\"\u003ecthackers/adm-zip#563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JohnJunior\"\u003e\u003ccode\u003e@​JohnJunior\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/pull/564\"\u003ecthackers/adm-zip#564\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/matt-fidd\"\u003e\u003ccode\u003e@​matt-fidd\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/pull/551\"\u003ecthackers/adm-zip#551\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mielverkerken\"\u003e\u003ccode\u003e@​mielverkerken\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/pull/562\"\u003ecthackers/adm-zip#562\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/cthackers/adm-zip/compare/v0.5.17...v0.5.18\"\u003ehttps://github.com/cthackers/adm-zip/compare/v0.5.17...v0.5.18\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cthackers/adm-zip/blob/master/history.md\"\u003eadm-zip's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e0.6.0 / 2026-07-10\u003c/h1\u003e\n\u003cp\u003eSecurity\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed CVE-2026-39244: a crafted archive declaring a huge uncompressed size could force an unbounded \u003ccode\u003eBuffer.alloc\u003c/code\u003e (memory exhaustion / DoS) before any validation. Allocation is now bounded by the data actually present — STORED output is sized from the real bytes, DEFLATED output is grown by the inflater and capped at the declared size (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/568\"\u003e#568\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHardened the internal entry-name lookup table against object injection: entry names come from untrusted archives, and a name such as \u003ccode\u003e__proto__\u003c/code\u003e previously resolved to \u003ccode\u003eObject.prototype\u003c/code\u003e, crashing \u003ccode\u003eaddFile\u003c/code\u003e and hiding the entry from \u003ccode\u003egetEntry\u003c/code\u003e/\u003ccode\u003ereadFile\u003c/code\u003e. The table is now prototype-less\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eBug fixes\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a regression (0.5.15) that rejected valid archives using a data descriptor (general-purpose bit 3). The payload is now validated against the authoritative central-directory CRC instead of requiring/parsing the trailing descriptor (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/548\"\u003e#548\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/533\"\u003e#533\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/554\"\u003e#554\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eextractAllTo\u003c/code\u003e/\u003ccode\u003eextractAllToAsync\u003c/code\u003e not restoring directory permissions with \u003ccode\u003ekeepOriginalPermission\u003c/code\u003e; directory modes are applied after their contents are written, deepest path first, and no longer lock the extractor out of a restrictive directory (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/530\"\u003e#530\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed infinite recursion in \u003ccode\u003eaddLocalFolder\u003c/code\u003e when a folder contains a symlink pointing back to an ancestor (e.g. workspace \u003ccode\u003enode_modules\u003c/code\u003e); the walk now tracks resolved real paths and skips already-visited directories (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/541\"\u003e#541\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed an uncaught exception (\u003ccode\u003eERR_INVALID_ARG_TYPE\u003c/code\u003e) that crashed the process when \u003ccode\u003ewriteFileToAsync\u003c/code\u003e could not open the target file (bad permissions, invalid filename, exhausted file descriptors); write failures are now reported through the callback and write errors are no longer silently swallowed (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/470\"\u003e#470\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/459\"\u003e#459\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/402\"\u003e#402\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed directory entries reporting an empty \u003ccode\u003ename\u003c/code\u003e (e.g. \u003ccode\u003ea/b/c/\u003c/code\u003e now returns \u003ccode\u003ec\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/466\"\u003e#466\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eextractEntryTo\u003c/code\u003e flattening subdirectories when \u003ccode\u003emaintainEntryPath\u003c/code\u003e is false; the structure below the extracted directory is now preserved instead of collapsing (and overwriting) files by basename (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/306\"\u003e#306\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a failed \u003ccode\u003eutimes\u003c/code\u003e aborting extraction; setting the modification time is now best-effort and never fails extraction of already-written content (\u003ca href=\"https://redirect.github.com/cthackers/adm-zip/issues/379\"\u003e#379\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003etest()\u003c/code\u003e always returning false for any archive containing a file (it indexed the entries array with an entry object instead of reading the entry); it now correctly verifies each entry's CRC\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003ePerformance\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFaster entry sorting when writing archives with many entries: names are decoded once instead of on every comparison (about 6× faster sort for large archives)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAdded\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eBundled TypeScript type definitions (\u003ccode\u003etypes.d.ts\u003c/code\u003e), so \u003ccode\u003e@types/adm-zip\u003c/code\u003e is no longer required\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNotes\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eBehavior change: \u003ccode\u003eextractEntryTo(dir, target, /* maintainEntryPath */ false)\u003c/code\u003e now preserves subdirectories beneath the extracted directory rather than flattening them\u003c/li\u003e\n\u003cli\u003eBehavior change: extraction no longer fails when the modification time cannot be set\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e0.5.4 / 2021-03-08\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eFixed relative paths\u003c/li\u003e\n\u003cli\u003eAdded zipcrypto encryption\u003c/li\u003e\n\u003cli\u003eLower verMade...\n\n_Description has been truncated_","html_url":"https://github.com/koreyba/EverFreeNote/pull/199","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/koreyba%2FEverFreeNote/issues/199","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/199/packages"}},{"old_version":"6.24.0","new_version":"6.28.0","update_type":"minor","path":null,"pr_created_at":"2026-09-11T12:29:42.000Z","version_change":"6.24.0 → 6.28.0","issue":{"uuid":"5424304200","node_id":"PR_kwDOLRRzl88AAAABDJFsRA","number":59,"state":"open","title":"build(deps): bump the npm_and_yarn group across 1 directory with 16 updates","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":4,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T12:29:42.000Z","updated_at":"2026-09-11T12:31:00.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"npm_and_yarn","update_count":16,"packages":[{"name":"undici","old_version":"6.24.0","new_version":"6.28.0","repository_url":"https://github.com/nodejs/undici"},{"name":"vite","old_version":"7.3.1","new_version":"7.3.5","repository_url":"https://github.com/vitejs/vite"},{"name":"@babel/core","old_version":"7.26.0","new_version":"7.29.7","repository_url":"https://github.com/babel/babel"},{"name":"@babel/plugin-transform-modules-systemjs","old_version":"7.25.9","new_version":"7.29.8","repository_url":"https://github.com/babel/babel"},{"name":"brace-expansion","old_version":"1.1.11","new_version":"1.1.18","repository_url":"https://github.com/juliangruber/brace-expansion"},{"name":"browserslist","old_version":"4.24.4","new_version":"4.28.9","repository_url":"https://github.com/browserslist/browserslist"},{"name":"follow-redirects","old_version":"1.15.6","new_version":"1.16.0","repository_url":"https://github.com/follow-redirects/follow-redirects"},{"name":"form-data","old_version":"4.0.5","new_version":"4.0.6","repository_url":"https://github.com/form-data/form-data"},{"name":"joi","old_version":"17.6.3","new_version":"17.13.7","repository_url":"https://github.com/hapijs/joi"},{"name":"lodash","old_version":"4.17.21","new_version":"4.18.1","repository_url":"https://github.com/lodash/lodash"},{"name":"nanoid","old_version":"3.3.11","new_version":"3.3.19","repository_url":"https://github.com/ai/nanoid"},{"name":"postcss","old_version":"8.5.6","new_version":"8.5.28","repository_url":"https://github.com/postcss/postcss"},{"name":"qs","old_version":"6.14.1","new_version":"6.16.0","repository_url":"https://github.com/ljharb/qs"},{"name":"seroval","old_version":"1.5.1","new_version":"1.5.6","repository_url":"https://github.com/lxsmnsyc/seroval"},{"name":"tmp","old_version":"0.2.5","new_version":"0.2.7","repository_url":"https://github.com/raszi/node-tmp"}],"path":null,"ecosystem":"npm"},"body":"Bumps the npm_and_yarn group with 15 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [undici](https://github.com/nodejs/undici) | `6.24.0` | `6.28.0` |\n| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `7.3.1` | `7.3.5` |\n| [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) | `7.26.0` | `7.29.7` |\n| [@babel/plugin-transform-modules-systemjs](https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs) | `7.25.9` | `7.29.8` |\n| [brace-expansion](https://github.com/juliangruber/brace-expansion) | `1.1.11` | `1.1.18` |\n| [browserslist](https://github.com/browserslist/browserslist) | `4.24.4` | `4.28.9` |\n| [follow-redirects](https://github.com/follow-redirects/follow-redirects) | `1.15.6` | `1.16.0` |\n| [form-data](https://github.com/form-data/form-data) | `4.0.5` | `4.0.6` |\n| [joi](https://github.com/hapijs/joi) | `17.6.3` | `17.13.7` |\n| [lodash](https://github.com/lodash/lodash) | `4.17.21` | `4.18.1` |\n| [nanoid](https://github.com/ai/nanoid) | `3.3.11` | `3.3.19` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.6` | `8.5.28` |\n| [qs](https://github.com/ljharb/qs) | `6.14.1` | `6.16.0` |\n| [seroval](https://github.com/lxsmnsyc/seroval) | `1.5.1` | `1.5.6` |\n| [tmp](https://github.com/raszi/node-tmp) | `0.2.5` | `0.2.7` |\n\n\nUpdates `undici` from 6.24.0 to 6.28.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.28.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e740a0b7c\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003ecba3a52a\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e4fd5a0c6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003eaf748404\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e and \u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e affect the cache interceptor in Undici v7 and v8; Undici v6 is not in their affected version ranges.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\"\u003ehttps://github.com/nodejs/undici/compare/v6.27.0...v6.28.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.27.0\u003c/h2\u003e\n\u003ch1\u003e⚠️ Security Release\u003c/h1\u003e\n\u003cp\u003eThis release line addresses \u003cstrong\u003e4 security advisories\u003c/strong\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eAction required:\u003c/strong\u003e Upgrade to \u003cstrong\u003eundici 6.27.0\u003c/strong\u003e or later.\u003c/p\u003e\n\u003cpre lang=\"sh\"\u003e\u003ccode\u003enpm install undici@^6.27.0\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eNote on patched version:\u003c/strong\u003e the v6 fixes shipped in \u003cstrong\u003ev6.27.0\u003c/strong\u003e, not \u003ccode\u003e6.26.0\u003c/code\u003e\n— \u003ccode\u003ev6.26.0\u003c/code\u003e contains only the chunked-EOF fix (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5308\"\u003e#5308\u003c/a\u003e) and the version bump, none\nof the security fixes below.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe v6 line is \u003cstrong\u003enot\u003c/strong\u003e affected by the SOCKS5 advisories (GHSA-vmh5-mc38-953g,\nGHSA-hm92-r4w5-c3mj), the shared-cache disclosure (GHSA-pr7r-676h-xcf6), or the\n8.x-only WebSocket regression (GHSA-38rv-x7px-6hhq).\u003c/p\u003e\n\u003ch2\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAdvisory\u003c/th\u003e\n\u003cth\u003eCVE\u003c/th\u003e\n\u003cth\u003eSeverity (CVSS)\u003c/th\u003e\n\u003cth\u003eFixed in\u003c/th\u003e\n\u003cth\u003eFix commit\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-12151\u003c/td\u003e\n\u003ctd\u003eHigh (7.5)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b7f252e7\"\u003e\u003ccode\u003eb7f252e7\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv\"\u003eGHSA-p88m-4jfj-68fv\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-9679\u003c/td\u003e\n\u003ctd\u003eModerate (5.9)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/25efa447\"\u003e\u003ccode\u003e25efa447\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-g8m3-5g58-fq7m\"\u003eGHSA-g8m3-5g58-fq7m\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-11525\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/25efa447\"\u003e\u003ccode\u003e25efa447\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52\"\u003eGHSA-35p6-xmwp-9g52\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003eCVE-2026-6733\u003c/td\u003e\n\u003ctd\u003eLow (3.7)\u003c/td\u003e\n\u003ctd\u003e6.27.0\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f4c31d60\"\u003e\u003ccode\u003ef4c31d60\u003c/code\u003e\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003chr /\u003e\n\u003ch2\u003eHigh severity\u003c/h2\u003e\n\u003ch3\u003eWebSocket DoS via fragment count bypass — CVE-2026-12151\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q\"\u003eGHSA-vxpw-j846-p89q\u003c/a\u003e\u003c/strong\u003e · CWE-400, CWE-770\n\u003cstrong\u003eFix:\u003c/strong\u003e \u003ca href=\"https://github.com/nodejs/undici/commit/b7f252e7\"\u003e\u003ccode\u003eb7f252e7\u003c/code\u003e\u003c/a\u003e \u003cem\u003eBackport WebSocket maxPayloadSize fixes\u003c/em\u003e (\u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5423\"\u003e#5423\u003c/a\u003e, backported to v6 in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5428\"\u003e#5428\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eA malicious WebSocket server can stream a large number of small or empty\ncontinuation frames. Undici enforced a limit on cumulative payload size but did\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/01a912e49a50c48009ed2639d2a457a6ec26752a\"\u003e\u003ccode\u003e01a912e\u003c/code\u003e\u003c/a\u003e Bumped v6.28.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5591\"\u003e#5591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/481ecfc3280292ab7eb0abbc4d0139219126f15e\"\u003e\u003ccode\u003e481ecfc\u003c/code\u003e\u003c/a\u003e Use Node 22 and npm 11 to release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/740a0b7c173cb4a83a5b693e96e8f3a116cfc400\"\u003e\u003ccode\u003e740a0b7\u003c/code\u003e\u003c/a\u003e fix: validate blob body content type\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2698e492ed22c9ec704b5df573d612bdd03f6ca0\"\u003e\u003ccode\u003e2698e49\u003c/code\u003e\u003c/a\u003e fix: validate coerced header values for CRLF (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5579\"\u003e#5579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420\"\u003e\u003ccode\u003e4fd5a0c\u003c/code\u003e\u003c/a\u003e test(retry): correct broken content-range fixtures in retry-handler.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e\"\u003e\u003ccode\u003ecba3a52\u003c/code\u003e\u003c/a\u003e fix(retry): reject partial content length mismatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235\"\u003e\u003ccode\u003eaf74840\u003c/code\u003e\u003c/a\u003e fix: harden cookie domain, path, and unparsed attribute validation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/551138cbc1742c92242a68216167761075e8a82c\"\u003e\u003ccode\u003e551138c\u003c/code\u003e\u003c/a\u003e Bumped v6.27.0 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5431\"\u003e#5431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b7f252e7c0841418fb9d95cd297bdd9fad9d2a53\"\u003e\u003ccode\u003eb7f252e\u003c/code\u003e\u003c/a\u003e Backport WebSocket maxPayloadSize fixes to v7.x (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5423\"\u003e#5423\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5428\"\u003e#5428\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/25efa447997f74d5881edd144525c3fd7db945a4\"\u003e\u003ccode\u003e25efa44\u003c/code\u003e\u003c/a\u003e fix(cookies): preserve values and parse SameSite strictly\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v6.24.0...v6.28.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `vite` from 7.3.1 to 7.3.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/releases\"\u003evite's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.3.5\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.5/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.3.3\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.3/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev7.3.2\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.2/packages/vite/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vitejs/vite/blob/v7.3.5/packages/vite/CHANGELOG.md\"\u003evite's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.3...v7.3.5\"\u003e7.3.5\u003c/a\u003e (2026-06-01)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ebackport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22572\"\u003e#22572\u003c/a\u003e, reject windows alternate paths (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22574\"\u003e#22574\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8c1855607b7c9884c4565d897ee98899a008a2d0\"\u003e8c18556\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e backport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22571\"\u003e#22571\u003c/a\u003e, reject UNC paths for launch-editor-middleware (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22573\"\u003e#22573\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/f20d64bef6e0ef1e4fa7a9783281c7bba0ce5292\"\u003ef20d64b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMiscellaneous Chores\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eskip v7.3.4 release (\u003ca href=\"https://github.com/vitejs/vite/commit/8a6a0c9fc734dbfe293ac33a4954506ee50430e1\"\u003e8a6a0c9\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.3...v7.3.4\"\u003e7.3.4\u003c/a\u003e (2026-06-01)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ebackport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22572\"\u003e#22572\u003c/a\u003e, reject windows alternate paths (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22574\"\u003e#22574\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/8c1855607b7c9884c4565d897ee98899a008a2d0\"\u003e8c18556\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edeps:\u003c/strong\u003e backport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22571\"\u003e#22571\u003c/a\u003e, reject UNC paths for launch-editor-middleware (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22573\"\u003e#22573\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/f20d64bef6e0ef1e4fa7a9783281c7bba0ce5292\"\u003ef20d64b\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.2...v7.3.3\"\u003e7.3.3\u003c/a\u003e (2026-05-07)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eavoid destructure lowering for newer safari (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22346\"\u003e#22346\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/5ab51c0f76f0896175e02ad797c1f5fe116d02f4\"\u003e5ab51c0\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/vitejs/vite/compare/v7.3.1...v7.3.2\"\u003e7.3.2\u003c/a\u003e (2026-04-06)\u003c!-- raw HTML omitted --\u003e\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eavoid path traversal with optimize deps sourcemap handler (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22161\"\u003e#22161\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/09d8c903bde12fee2710314d3b42bc789c686df7\"\u003e09d8c90\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ebackport \u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22159\"\u003e#22159\u003c/a\u003e, apply server.fs check to env transport (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22162\"\u003e#22162\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/19db0f29c3a3ac4e64cc95c270716c77fd223ad1\"\u003e19db0f2\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echeck \u003ccode\u003eserver.fs\u003c/code\u003e after stripping query as well (\u003ca href=\"https://redirect.github.com/vitejs/vite/issues/22160\"\u003e#22160\u003c/a\u003e) (\u003ca href=\"https://github.com/vitejs/vite/commit/f8103cc946f137a54e395fe3f5d08e8209231ed6\"\u003ef8103cc\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/077945cb60df372a52cf999b6e532ba70fac7423\"\u003e\u003ccode\u003e077945c\u003c/code\u003e\u003c/a\u003e release: v7.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/8a6a0c9fc734dbfe293ac33a4954506ee50430e1\"\u003e\u003ccode\u003e8a6a0c9\u003c/code\u003e\u003c/a\u003e chore: skip v7.3.4 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/8c1855607b7c9884c4565d897ee98899a008a2d0\"\u003e\u003ccode\u003e8c18556\u003c/code\u003e\u003c/a\u003e fix: backport \u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22572\"\u003e#22572\u003c/a\u003e, reject windows alternate paths (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22574\"\u003e#22574\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/f20d64bef6e0ef1e4fa7a9783281c7bba0ce5292\"\u003e\u003ccode\u003ef20d64b\u003c/code\u003e\u003c/a\u003e fix(deps): backport \u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22571\"\u003e#22571\u003c/a\u003e, reject UNC paths for launch-editor-middleware (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/2\"\u003e#2\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/ca31424cccb075c88131132b929a63527d0e2b69\"\u003e\u003ccode\u003eca31424\u003c/code\u003e\u003c/a\u003e release: v7.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/5ab51c0f76f0896175e02ad797c1f5fe116d02f4\"\u003e\u003ccode\u003e5ab51c0\u003c/code\u003e\u003c/a\u003e fix: avoid destructure lowering for newer safari (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22346\"\u003e#22346\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/cc383e07b66d4c5a9768fcb570e0af812cb8d999\"\u003e\u003ccode\u003ecc383e0\u003c/code\u003e\u003c/a\u003e release: v7.3.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/09d8c903bde12fee2710314d3b42bc789c686df7\"\u003e\u003ccode\u003e09d8c90\u003c/code\u003e\u003c/a\u003e fix: avoid path traversal with optimize deps sourcemap handler (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22161\"\u003e#22161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/f8103cc946f137a54e395fe3f5d08e8209231ed6\"\u003e\u003ccode\u003ef8103cc\u003c/code\u003e\u003c/a\u003e fix: check \u003ccode\u003eserver.fs\u003c/code\u003e after stripping query as well (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22160\"\u003e#22160\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vitejs/vite/commit/19db0f29c3a3ac4e64cc95c270716c77fd223ad1\"\u003e\u003ccode\u003e19db0f2\u003c/code\u003e\u003c/a\u003e fix: backport \u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22159\"\u003e#22159\u003c/a\u003e, apply server.fs check to env transport (\u003ca href=\"https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22162\"\u003e#22162\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/vitejs/vite/commits/v7.3.5/packages/vite\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@babel/core` from 7.26.0 to 7.29.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/babel/babel/releases\"\u003e@​babel/core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.7 (2026-05-25)\u003c/h2\u003e\n\u003cp\u003eRe-release all packages with npm provenance attestations\u003c/p\u003e\n\u003ch2\u003ev7.29.6 (2026-05-25)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18014\"\u003e#18014\u003c/a\u003e Catchup source map position in preserveFormat (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18001\"\u003e#18001\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e, \u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17998\"\u003e#17998\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 3\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMateusz Burzyński (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.5 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:house:  Internal\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@babel/*\u003c/code\u003e dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.4 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17974\"\u003e#17974\u003c/a\u003e [7.x backport]fix(systemjs): improve module string name support (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 1\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.3 (2026-04-30)\u003c/h2\u003e\n\u003ch4\u003e:eyeglasses: Spec Compliance\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17923\"\u003e#17923\u003c/a\u003e Support flow extends bound (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-helper-create-class-features-plugin\u003c/code\u003e, \u003ccode\u003ebabel-plugin-proposal-decorators\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17931\"\u003e#17931\u003c/a\u003e fix(decorators): replace super within all removed static elements (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-register\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17915\"\u003e#17915\u003c/a\u003e Fix thread synchronization issues in \u003ccode\u003e@babel/register\u003c/code\u003e (\u003ca href=\"https://github.com/liuxingbaoyu\"\u003e\u003ccode\u003e@​liuxingbaoyu\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-compat-data\u003c/code\u003e, \u003ccode\u003ebabel-plugin-bugfix-safari-rest-destructuring-rhs-array\u003c/code\u003e, \u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17788\"\u003e#17788\u003c/a\u003e Add bugfix plugin for Safari array rest destructuring bug (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:nail_care: Polish\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-parser\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/4fba7541180bf5f58256d8e358b544e3831ad090\"\u003e\u003ccode\u003e4fba754\u003c/code\u003e\u003c/a\u003e v7.29.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/04ea6b27fdac8f40c3481aec2080ac9678779509\"\u003e\u003ccode\u003e04ea6b2\u003c/code\u003e\u003c/a\u003e v7.29.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/99f498a9b9fa0b900d603fbe8f6601bb3b9e42bb\"\u003e\u003ccode\u003e99f498a\u003c/code\u003e\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/18001\"\u003e#18001\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/feba0a3654c596bd369d1ef1231f5d56666d56dc\"\u003e\u003ccode\u003efeba0a3\u003c/code\u003e\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17998\"\u003e#17998\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/aa8394e454337d118ac3d40bfa3ee1a3cb3f3ed2\"\u003e\u003ccode\u003eaa8394e\u003c/code\u003e\u003c/a\u003e v7.29.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/ad0d03f0c92404a60ec6b1c12f15febd38e2397a\"\u003e\u003ccode\u003ead0d03f\u003c/code\u003e\u003c/a\u003e [7.x backport] feat: Allow specifying startLine in code frame (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17739\"\u003e#17739\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/d7f400889567ae18ef9ac41b024b5120f6060e17\"\u003e\u003ccode\u003ed7f4008\u003c/code\u003e\u003c/a\u003e v7.28.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/e130225028e93e106135586f344cfa44c4aac847\"\u003e\u003ccode\u003ee130225\u003c/code\u003e\u003c/a\u003e Polish(standalone): improve message on invalid preset/plugin (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17606\"\u003e#17606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/99dcba5e71de3bd81ce14077cfa5b6df58e9b177\"\u003e\u003ccode\u003e99dcba5\u003c/code\u003e\u003c/a\u003e chore: enable some ts-eslint rules (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17592\"\u003e#17592\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/c92c4919771105140015167f25f7bacac77c90d9\"\u003e\u003ccode\u003ec92c491\u003c/code\u003e\u003c/a\u003e Improve Unicode handling in code-frame tokenizer (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-core/issues/17589\"\u003e#17589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/babel/babel/commits/v7.29.7/packages/babel-core\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​babel/core\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@babel/plugin-transform-modules-systemjs` from 7.25.9 to 7.29.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/babel/babel/releases\"\u003e@​babel/plugin-transform-modules-systemjs's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.8 (2026-07-31)\u003c/h2\u003e\n\u003ch4\u003e:eyeglasses: Spec Compliance\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e, \u003ccode\u003ebabel-parser\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-spread\u003c/code\u003e, \u003ccode\u003ebabel-traverse\u003c/code\u003e, \u003ccode\u003ebabel-types\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17871\"\u003e#17871\u003c/a\u003e Disallow super call after new (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18046\"\u003e#18046\u003c/a\u003e fix(generator): improve new callee parens check (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-node\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18044\"\u003e#18044\u003c/a\u003e fix(systemjs): support \u003ccode\u003e__proto__\u003c/code\u003e as an export name (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 2\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.7 (2026-05-25)\u003c/h2\u003e\n\u003cp\u003eRe-release all packages with npm provenance attestations\u003c/p\u003e\n\u003ch2\u003ev7.29.6 (2026-05-25)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18014\"\u003e#18014\u003c/a\u003e Catchup source map position in preserveFormat (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18001\"\u003e#18001\u003c/a\u003e [7.x packport]Improve input source map handling (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-core\u003c/code\u003e, \u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17998\"\u003e#17998\u003c/a\u003e Preserve original identifier names from input sourcemaps (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs/issues/17992\"\u003e#17992\u003c/a\u003e) (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 3\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMateusz Burzyński (\u003ca href=\"https://github.com/Andarist\"\u003e\u003ccode\u003e@​Andarist\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.5 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:house:  Internal\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-preset-env\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@babel/*\u003c/code\u003e dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.29.4 (2026-05-05)\u003c/h2\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17974\"\u003e#17974\u003c/a\u003e [7.x backport]fix(systemjs): improve module string name support (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 1\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/5de11ca9234379b78ef95df72aebbec93f28bf45\"\u003e\u003ccode\u003e5de11ca\u003c/code\u003e\u003c/a\u003e v7.29.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/f08d4342e1f189a56e7cee46e60a1817af96219e\"\u003e\u003ccode\u003ef08d434\u003c/code\u003e\u003c/a\u003e fix(systemjs): support \u003cstrong\u003eproto\u003c/strong\u003e as an export name (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs/issues/18044\"\u003e#18044\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/4fba7541180bf5f58256d8e358b544e3831ad090\"\u003e\u003ccode\u003e4fba754\u003c/code\u003e\u003c/a\u003e v7.29.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/a458f66074b97d54773db8159af673d23b26079b\"\u003e\u003ccode\u003ea458f66\u003c/code\u003e\u003c/a\u003e v7.29.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/32ebd5aaf2526ddd176fd6a3d1e3dc594abdc8d9\"\u003e\u003ccode\u003e32ebd5a\u003c/code\u003e\u003c/a\u003e [7.x backport]fix(systemjs): improve module string name support (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs/issues/17974\"\u003e#17974\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/aa8394e454337d118ac3d40bfa3ee1a3cb3f3ed2\"\u003e\u003ccode\u003eaa8394e\u003c/code\u003e\u003c/a\u003e v7.29.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/0053db620c05acf0036f593b5aaf4e372daa79d0\"\u003e\u003ccode\u003e0053db6\u003c/code\u003e\u003c/a\u003e Update polyfill packages (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs/issues/17727\"\u003e#17727\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/61647ae2397c82c3c71f077b5ab109106a5cac0f\"\u003e\u003ccode\u003e61647ae\u003c/code\u003e\u003c/a\u003e v7.28.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/a177d551adba99773f4ff00ea9bf46550def6132\"\u003e\u003ccode\u003ea177d55\u003c/code\u003e\u003c/a\u003e [Babel 8] Use \u003ccode\u003et.traverseFast\u003c/code\u003e to replace some \u003ccode\u003epath.traverse\u003c/code\u003e (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs/issues/17518\"\u003e#17518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/eebd3a06021c13d335b5b0bd79734df3abbea678\"\u003e\u003ccode\u003eeebd3a0\u003c/code\u003e\u003c/a\u003e v7.27.1\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/babel/babel/commits/v7.29.8/packages/babel-plugin-transform-modules-systemjs\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​babel/plugin-transform-modules-systemjs\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `brace-expansion` from 1.1.11 to 1.1.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/juliangruber/brace-expansion/releases\"\u003ebrace-expansion's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBackport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)  0b09384\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.14...v1.1.15\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.1.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003epkg: publish on tag 1.x  c460dbd\u003c/li\u003e\n\u003cli\u003efmt  ccb8ac6\u003c/li\u003e\n\u003cli\u003eFix potential ReDoS Vulnerability or Inefficient Regular Expression (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/65\"\u003e#65\u003c/a\u003e)  c3c73c8\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/v1.1.11...v1.1.12\"\u003ehttps://github.com/juliangruber/brace-expansion/compare/v1.1.11...v1.1.12\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/758fcd6d188a95c2342818519c77b8c06794552b\"\u003e\u003ccode\u003e758fcd6\u003c/code\u003e\u003c/a\u003e 1.1.18\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/27fbeed22b4fdf2c5f732f66bcf84d43f4a26c6e\"\u003e\u003ccode\u003e27fbeed\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/5c57cc2519dfb067e188b7cb0733fffbd02946bf\"\u003e\u003ccode\u003e5c57cc2\u003c/code\u003e\u003c/a\u003e 1.1.17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d757f1dde7808bcbcd7a4628ab913e5185ed3d57\"\u003e\u003ccode\u003ed757f1d\u003c/code\u003e\u003c/a\u003e npm ignore \u003ccode\u003e.claude\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031\"\u003e\u003ccode\u003ecb4b9e4\u003c/code\u003e\u003c/a\u003e fix: backport GHSA-mh99-v99m-4gvg (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/129\"\u003e#129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/447763a91a613cfa67ac73096cbc1de9a2304f97\"\u003e\u003ccode\u003e447763a\u003c/code\u003e\u003c/a\u003e 1.1.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95\"\u003e\u003ccode\u003ed74e630\u003c/code\u003e\u003c/a\u003e fix: v1 backport for CVE-2026-13149 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/122\"\u003e#122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/2203f4f4895eba16c4d408b4219ce1b8e5f6ff24\"\u003e\u003ccode\u003e2203f4f\u003c/code\u003e\u003c/a\u003e 1.1.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/0b0938410732370559704230724ca4a44d1b29fd\"\u003e\u003ccode\u003e0b09384\u003c/code\u003e\u003c/a\u003e Backport v5.0.6 change to v1 (\u003ca href=\"https://redirect.github.com/juliangruber/brace-expansion/issues/111\"\u003e#111\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juliangruber/brace-expansion/commit/10c05fcf3699b1a29ef5e611c011af3d3c97e6e3\"\u003e\u003ccode\u003e10c05fc\u003c/code\u003e\u003c/a\u003e 1.1.14\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/juliangruber/brace-expansion/compare/1.1.11...v1.1.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `browserslist` from 4.24.4 to 4.28.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/releases\"\u003ebrowserslist's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eincluding kaios\u003c/code\u003e in baseline queries (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved parsing performance.\u003c/li\u003e\n\u003cli\u003eFixed unbounded memory growth (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed prototype write issue (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Electron version queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003e\u0026gt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;=\u003c/code\u003e queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eSyntaxError\u003c/code\u003e regression of 4.28.3.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed baseline query case-insensitivity (by \u003ca href=\"https://github.com/swwind\"\u003e\u003ccode\u003e@​swwind\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix prototype pollution (by \u003ca href=\"https://github.com/chluo1997\"\u003e\u003ccode\u003e@​chluo1997\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved Baseline warning since we have it own warning.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.27.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003eBROWSERSLIST_TRACE_WARNING\u003c/code\u003e environment variable.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003ethrowOnMissing\u003c/code\u003e with \u003ccode\u003eextends\u003c/code\u003e query (by \u003ca href=\"https://github.com/alexander-akait\"\u003e\u003ccode\u003e@​alexander-akait\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003ebaseline-browser-mapping\u003c/code\u003e version requirement.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated Firefox ESR.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded Baseline queries (by \u003ca href=\"https://github.com/tonypconway\"\u003e\u003ccode\u003e@​tonypconway\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.25.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Windows support for custom stats (by \u003ca href=\"https://github.com/torgeilo\"\u003e\u003ccode\u003e@​torgeilo\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.25.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed ReDoS (by \u003ca href=\"https://github.com/ericcornelissen\"\u003e\u003ccode\u003e@​ericcornelissen\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md\"\u003ebrowserslist's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.28.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImprove \u003ccode\u003eor\u003c/code\u003e parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eincluding kaios\u003c/code\u003e in baseline queries (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved parsing performance.\u003c/li\u003e\n\u003cli\u003eFixed unbounded memory growth (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed prototype write issue (by \u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed Electron version queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003e\u0026gt;\u003c/code\u003e and \u003ccode\u003e\u0026gt;=\u003c/code\u003e queries (by \u003ca href=\"https://github.com/spokodev\"\u003e\u003ccode\u003e@​spokodev\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eSyntaxError\u003c/code\u003e regression of 4.28.3.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed baseline query case-insensitivity (by \u003ca href=\"https://github.com/swwind\"\u003e\u003ccode\u003e@​swwind\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix prototype pollution (by \u003ca href=\"https://github.com/chluo1997\"\u003e\u003ccode\u003e@​chluo1997\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.28.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved Baseline warning since we have it own warning.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.48.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003efirefox \u0026gt;= esr\u003c/code\u003e query support (by \u003ca href=\"https://github.com/SethFalco\"\u003e\u003ccode\u003e@​SethFalco\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/SethFalco\"\u003e\u003ccode\u003e@​SethFalco\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.27.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003eBROWSERSLIST_TRACE_WARNING\u003c/code\u003e environment variable.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.26.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003ethrowOnMissing\u003c/code\u003e with \u003ccode\u003eextends\u003c/code\u003e query (by \u003ca href=\"https://github.com/alexander-akait\"\u003e\u003ccode\u003e@​alexander-akait\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/12ed5252dabc14fee4e97b465894b2f90910ca62\"\u003e\u003ccode\u003e12ed525\u003c/code\u003e\u003c/a\u003e Release 4.28.9 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/b1d8cf9d7a7dc76f6585425a8360218289194297\"\u003e\u003ccode\u003eb1d8cf9\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/21517b651c915cdbbfb8c122268bc36f5cabb7ef\"\u003e\u003ccode\u003e21517b6\u003c/code\u003e\u003c/a\u003e Improve \u003ccode\u003eor\u003c/code\u003e parsing performance\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/f2f2e6cfb01bb4942941d328737546f4e2ae41ad\"\u003e\u003ccode\u003ef2f2e6c\u003c/code\u003e\u003c/a\u003e Release 4.28.8 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/d0787c88fa29ba895fea51cfe921232c7b5d1377\"\u003e\u003ccode\u003ed0787c8\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/fcf8fa9857b30ccdf801a548f5d09d3c4ff0d43f\"\u003e\u003ccode\u003efcf8fa9\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/browserslist/browserslist/issues/939\"\u003e#939\u003c/a\u003e from Jaybhade/fix/baseline-kaios-without-downstream\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/57ecd64454e9252afdd6a7e76926e13dda48a38c\"\u003e\u003ccode\u003e57ecd64\u003c/code\u003e\u003c/a\u003e fix: support \u0026quot;including kaios\u0026quot; without downstream\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/093a0f67bb0becda55235d767b134df3197c54a1\"\u003e\u003ccode\u003e093a0f6\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/b637868045806d2fba4c24eb0060e4cc8b1db276\"\u003e\u003ccode\u003eb637868\u003c/code\u003e\u003c/a\u003e Release 4.28.7 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/browserslist/browserslist/commit/313f4659b9f985ade89d1d6a54a860371c41cc46\"\u003e\u003ccode\u003e313f465\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/browserslist/browserslist/compare/4.24.4...4.28.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for browserslist since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `follow-redirects` from 1.15.6 to 1.16.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/follow-redirects/follow-redirects/commit/0c23a223067201c368035e82954c11eb2578a33b\"\u003e\u003ccode\u003e0c23a22\u003c/code\u003e\u003c/a\u003e Release version 1.16.0 of the npm package.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/follow-redirects/follow-redirects/commit/844c4d302ac963d29bdb5dc1754ec7df3d70d7f9\"\u003e\u003ccode\u003e844c4d3\u003c/code\u003e\u003c/a\u003e Add sensitiveHeaders option.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/follow-redirects/follow-redirects/commit/5e8b8d024e2c76f804a284258e585ecb49a575be\"\u003e\u003ccode\u003e5e8b8d0\u003c/code\u003e\u003c/a\u003e ci: add Node.js 24.x to the CI matrix\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/follow-redirects/follow-redirects/commit/7953e2255aa0b93602eed3804f3bc5e6923a03af\"\u003e\u003ccode\u003e7953e22\u003c/code\u003e\u003c/a\u003e ci: upgrade GitHub Actions to use setup-node@v6 and checkout@v6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/follow-redirects/follow-redirects/commit/86dc1f86e4b56bcd642c78384d51f10f123aea75\"\u003e\u003ccode\u003e86dc1f8\u003c/code\u003e\u003c/a\u003e Sanitizing input.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/follow-redirects/follow-redirects/commit/21ef28a544c5e57f4c34b8476d75f2144609a1eb\"\u003e\u003ccode\u003e21ef28a\u003c/code\u003e\u003c/a\u003e Release version 1.15.11 of the npm package.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/follow-redirects/follow-redirects/commit/7c88135da3bd0681a7e156ee66b16b2f6f98b480\"\u003e\u003ccode\u003e7c88135\u003c/code\u003e\u003c/a\u003e Roll back tree shaking.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/follow-redirects/follow-redirects/commit/6e389ba094beec211a8847788a146917a16c1bdb\"\u003e\u003ccode\u003e6e389ba\u003c/code\u003e\u003c/a\u003e Release version 1.15.10 of the npm package.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/follow-redirects/follow-redirects/commit/5bc496e0229abda823221e0c6267926a3f93f262\"\u003e\u003ccode\u003e5bc496e\u003c/code\u003e\u003c/a\u003e Shake me up before you go-go.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/follow-redirects/follow-redirects/commit/694d6b47a42bc8377e5ef1480394de451e16bd5b\"\u003e\u003ccode\u003e694d6b4\u003c/code\u003e\u003c/a\u003e Bump minimist from 1.2.5 to 1.2.8\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/follow-redirects/follow-redirects/compare/v1.15.6...v1.16.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `form-data` from 4.0.5 to 4.0.6\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/form-data/form-data/blob/master/CHANGELOG.md\"\u003eform-data's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/form-data/form-data/compare/v4.0.5...v4.0.6\"\u003ev4.0.6\u003c/a\u003e - 2026-06-12\u003c/h2\u003e\n\u003ch3\u003eCommits\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[Fix] escape CR, LF, and \u003ccode\u003e\u0026quot;\u003c/code\u003e in field names and filenames \u003ca href=\"https://github.com/form-data/form-data/commit/8dff42c6da654ed4e7ad4acb7f8ccd3831217c99\"\u003e\u003ccode\u003e8dff42c\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003etape\u003c/code\u003e \u003ca href=\"https://github.com/form-data/form-data/commit/f31d21ef10bf46e46344c3ee4f99acbef6be43e1\"\u003e\u003ccode\u003ef31d21e\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Deps] update \u003ccode\u003ehasown\u003c/code\u003e, \u003ccode\u003emime-types\u003c/code\u003e \u003ca href=\"https://github.com/form-data/form-data/commit/92ae0eb5da94d6f01925d5f4fcffb2a1e50ed7cd\"\u003e\u003ccode\u003e92ae0eb\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Dev Deps] update \u003ccode\u003ejs-randomness-predictor\u003c/code\u003e \u003ca href=\"https://github.com/form-data/form-data/commit/67b0f65c2e0b065a511d42227d35e4d367644e97\"\u003e\u003ccode\u003e67b0f65\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/form-data/form-data/commit/64190db548c0179e37206858e39f27cf513e9435\"\u003e\u003ccode\u003e64190db\u003c/code\u003e\u003c/a\u003e v4.0.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/form-data/form-data/commit/92ae0eb5da94d6f01925d5f4fcffb2a1e50ed7cd\"\u003e\u003ccode\u003e92ae0eb\u003c/code\u003e\u003c/a\u003e [Deps] update \u003ccode\u003ehasown\u003c/code\u003e, \u003ccode\u003emime-types\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/form-data/form-data/commit/f31d21ef10bf46e46344c3ee4f99acbef6be43e1\"\u003e\u003ccode\u003ef31d21e\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003e@ljharb/eslint-config\u003c/code\u003e, \u003ccode\u003eauto-changelog\u003c/code\u003e, \u003ccode\u003etape\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/form-data/form-data/commit/8dff42c6da654ed4e7ad4acb7f8ccd3831217c99\"\u003e\u003ccode\u003e8dff42c\u003c/code\u003e\u003c/a\u003e [Fix] escape CR, LF, and \u003ccode\u003e\u0026quot;\u003c/code\u003e in field names and filenames\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/form-data/form-data/commit/67b0f65c2e0b065a511d42227d35e4d367644e97\"\u003e\u003ccode\u003e67b0f65\u003c/code\u003e\u003c/a\u003e [Dev Deps] update \u003ccode\u003ejs-randomness-predictor\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/form-data/form-data/compare/v4.0.5...v4.0.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `joi` from 17.6.3 to 17.13.7\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/ed9d7cdd11ef5f7751fd46886f38dc605c9c3995\"\u003e\u003ccode\u003eed9d7cd\u003c/code\u003e\u003c/a\u003e 17.13.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/f2729f71839c57c94ac500b4be9e4b5b26d4e637\"\u003e\u003ccode\u003ef2729f7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hapijs/joi/issues/3145\"\u003e#3145\u003c/a\u003e from hapijs/backport/isodate-timeshift-v17\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/c43fc964799c9b5f0c6921bf788162b67066ae81\"\u003e\u003ccode\u003ec43fc96\u003c/code\u003e\u003c/a\u003e chore: add regression test for \u003ca href=\"https://redirect.github.com/hapijs/joi/issues/3143\"\u003e#3143\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/115e7b58d5eaaecc5e9b7093d41899ad6fb053ec\"\u003e\u003ccode\u003e115e7b5\u003c/code\u003e\u003c/a\u003e fix(isoDate): pad a bare-hour timeshift with a colon, not just zeros\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/850be1ee24be8d548bb09359bdb0cf9fe41635ff\"\u003e\u003ccode\u003e850be1e\u003c/code\u003e\u003c/a\u003e 17.13.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/9faeecc48b18ec40e3881467645ae9074f0dfa3c\"\u003e\u003ccode\u003e9faeecc\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hapijs/joi/issues/3139\"\u003e#3139\u003c/a\u003e from hapijs/chore/backport-messages-proto\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/8d0b808f3e874d28f9078f61b7742290989afb36\"\u003e\u003ccode\u003e8d0b808\u003c/code\u003e\u003c/a\u003e fix: prevent messages proto injection\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/566e73fa58e72f0a1dcbb3b110ee2f49f33aece3\"\u003e\u003ccode\u003e566e73f\u003c/code\u003e\u003c/a\u003e 17.13.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/3f3907cd944257e143b22f3bf3f05e71478fa1b1\"\u003e\u003ccode\u003e3f3907c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/hapijs/joi/issues/3135\"\u003e#3135\u003c/a\u003e from hapijs/chore/backport-rename-proto\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hapijs/joi/commit/172ececa192feda532b743d77bc9d3e523d19b01\"\u003e\u003ccode\u003e172ecec\u003c/code\u003e\u003c/a\u003e fix: prevent proto on renames\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hapijs/joi/compare/v17.6.3...v17.13.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `lodash` from 4.17.21 to 4.18.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/lodash/lodash/releases\"\u003elodash's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.18.1\u003c/h2\u003e\n\u003ch2\u003eBugs\u003c/h2\u003e\n\u003cp\u003eFixes a \u003ccode\u003eReferenceError\u003c/code\u003e issue in \u003ccode\u003elodash\u003c/code\u003e \u003ccode\u003elodash-es\u003c/code\u003e \u003ccode\u003elodash-amd\u003c/code\u003e and \u003ccode\u003elodash.template\u003c/code\u003e when using the \u003ccode\u003etemplate\u003c/code\u003e and \u003ccode\u003efromPairs\u003c/code\u003e functions from the modular builds. See \u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6167#issuecomment-4165269769\"\u003elodash/lodash#6167\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eThese defects were related to how lodash distributions are built from the main branch using \u003ca href=\"https://github.com/lodash-archive/lodash-cli\"\u003ehttps://github.com/lodash-archive/lodash-cli\u003c/a\u003e. When internal dependencies change inside lodash functions, equivalent updates need to be made to a mapping in the lodash-cli. (hey, it was ahead of its time once upon a time!). We know this, but we missed it in the last release. It's the kind of thing that passes in CI, but fails bc the build is not the same thing you tested.\u003c/p\u003e\n\u003cp\u003eThere is no diff on main for this, but you can see the diffs for each of the npm packages on their respective branches:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elodash\u003c/code\u003e: \u003ca href=\"https://github.com/lodash/lodash/compare/4.18.0-npm...4.18.1-npm\"\u003ehttps://github.com/lodash/lodash/compare/4.18.0-npm...4.18.1-npm\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elodash-es\u003c/code\u003e: \u003ca href=\"https://github.com/lodash/lodash/compare/4.18.0-es...4.18.1-es\"\u003ehttps://github.com/lodash/lodash/compare/4.18.0-es...4.18.1-es\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elodash-amd\u003c/code\u003e: \u003ca href=\"https://github.com/lodash/lodash/compare/4.18.0-amd...4.18.1-amd\"\u003ehttps://github.com/lodash/lodash/compare/4.18.0-amd...4.18.1-amd\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elodash.template\u003c/code\u003e\u003ca href=\"https://github.com/lodash/lodash/compare/4.18.0-npm-packages...4.18.1-npm-packages\"\u003ehttps://github.com/lodash/lodash/compare/4.18.0-npm-packages...4.18.1-npm-packages\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.18.0\u003c/h2\u003e\n\u003ch2\u003ev4.18.0\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/lodash/lodash/compare/4.17.23...4.18.0\"\u003ehttps://github.com/lodash/lodash/compare/4.17.23...4.18.0\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ccode\u003e_.unset\u003c/code\u003e / \u003ccode\u003e_.omit\u003c/code\u003e\u003c/strong\u003e: Fixed prototype pollution via \u003ccode\u003econstructor\u003c/code\u003e/\u003ccode\u003eprototype\u003c/code\u003e path traversal (\u003ca href=\"https://github.com/lodash/lodash/security/advisories/GHSA-f23m-r3pf-42rh\"\u003eGHSA-f23m-r3pf-42rh\u003c/a\u003e, \u003ca href=\"https://github.com/lodash/lodash/commit/fe8d32eda854377349a4f922ab7655c8e5df9a0b\"\u003efe8d32e\u003c/a\u003e). Previously, array-wrapped path segments and primitive roots could bypass the existing guards, allowing deletion of properties from built-in prototypes. Now \u003ccode\u003econstructor\u003c/code\u003e and \u003ccode\u003eprototype\u003c/code\u003e are blocked unconditionally as non-terminal path keys, matching \u003ccode\u003ebaseSet\u003c/code\u003e. Calls that previously returned \u003ccode\u003etrue\u003c/code\u003e and deleted the property now return \u003ccode\u003efalse\u003c/code\u003e and leave the target untouched.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ccode\u003e_.template\u003c/code\u003e\u003c/strong\u003e: Fixed code injection via \u003ccode\u003eimports\u003c/code\u003e keys (\u003ca href=\"https://github.com/lodash/lodash/security/advisories/GHSA-r5fr-rjxr-66jc\"\u003eGHSA-r5fr-rjxr-66jc\u003c/a\u003e, CVE-2026-4800, \u003ca href=\"https://github.com/lodash/lodash/commit/879aaa93132d78c2f8d20c60279da9f8b21576d6\"\u003e879aaa9\u003c/a\u003e). Fixes an incomplete patch for CVE-2021-23337. The \u003ccode\u003evariable\u003c/code\u003e option was validated against \u003ccode\u003ereForbiddenIdentifierChars\u003c/code\u003e but \u003ccode\u003eimportsKeys\u003c/code\u003e was left unguarded, allowing code injection via the same \u003ccode\u003eFunction()\u003c/code\u003e constructor sink. \u003ccode\u003eimports\u003c/code\u003e keys containing forbidden identifier characters now throw \u003ccode\u003e\u0026quot;Invalid imports option passed into _.template\u0026quot;\u003c/code\u003e.\u003c/p\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd security notice for \u003ccode\u003e_.template\u003c/code\u003e in threat model and API docs (\u003ca href=\"https://redirect.github.com/lodash/lodash/pull/6099\"\u003e#6099\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDocument \u003ccode\u003elower \u0026gt; upper\u003c/code\u003e behavior in \u003ccode\u003e_.random\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/lodash/lodash/pull/6115\"\u003e#6115\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix quotes in \u003ccode\u003e_.compact\u003c/code\u003e jsdoc (\u003ca href=\"https://redirect.github.com/lodash/lodash/pull/6090\"\u003e#6090\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e\u003ccode\u003elodash.*\u003c/code\u003e modular packages\u003c/h3\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/lodash/lodash/pull/6157\"\u003eDiff\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eWe have also regenerated and published a select number of the \u003ccode\u003elodash.*\u003c/code\u003e modular packages.\u003c/p\u003e\n\u003cp\u003eThese modular packages had fallen out of sync significantly from the minor/patch updates to lodash. Specifically, we have brought the following packages up to parity w/ the latest lodash release because they have had CVEs on them in the past:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.orderby\"\u003elodash.orderby\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.tonumber\"\u003elodash.tonumber\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.trim\"\u003elodash.trim\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.trimend\"\u003elodash.trimend\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.sortedindexby\"\u003elodash.sortedindexby\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.zipobjectdeep\"\u003elodash.zipobjectdeep\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.unset\"\u003elodash.unset\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.omit\"\u003elodash.omit\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.npmjs.com/package/lodash.template\"\u003elodash.template\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/cb0b9b9212521c08e3eafe7c8cb0af1b42b6649e\"\u003e\u003ccode\u003ecb0b9b9\u003c/code\u003e\u003c/a\u003e release(patch): bump main to 4.18.1 (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6177\"\u003e#6177\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/75535f57883b7225adb96de1cfc1cd4169cfcb51\"\u003e\u003ccode\u003e75535f5\u003c/code\u003e\u003c/a\u003e chore: prune stale advisory refs (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6170\"\u003e#6170\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/62e91bc6a39c98d85b9ada8c44d40593deaf82a4\"\u003e\u003ccode\u003e62e91bc\u003c/code\u003e\u003c/a\u003e docs: remove n_ Node.js \u0026lt; 6 REPL note from README (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6165\"\u003e#6165\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/59be2de61f8aa9461c7856533b51d31b7d8babc4\"\u003e\u003ccode\u003e59be2de\u003c/code\u003e\u003c/a\u003e release(minor): bump to 4.18.0 (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6161\"\u003e#6161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/af634573030f979194871da7c68f79420992f53d\"\u003e\u003ccode\u003eaf63457\u003c/code\u003e\u003c/a\u003e fix: broken tests for _.template 879aaa9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/1073a7693e1727e0cf3641e5f71f75ddcf8de7c0\"\u003e\u003ccode\u003e1073a76\u003c/code\u003e\u003c/a\u003e fix: linting issues\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/879aaa93132d78c2f8d20c60279da9f8b21576d6\"\u003e\u003ccode\u003e879aaa9\u003c/code\u003e\u003c/a\u003e fix: validate imports keys in _.template\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/fe8d32eda854377349a4f922ab7655c8e5df9a0b\"\u003e\u003ccode\u003efe8d32e\u003c/code\u003e\u003c/a\u003e fix: block prototype pollution in baseUnset via constructor/prototype traversal\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/18ba0a32f42fd02117f096b032f89c984173462d\"\u003e\u003ccode\u003e18ba0a3\u003c/code\u003e\u003c/a\u003e refactor(fromPairs): use baseAssignValue for consistent assignment (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6153\"\u003e#6153\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lodash/lodash/commit/b8190803d48d60b8c80ad45d39125f32fa618cb2\"\u003e\u003ccode\u003eb819080\u003c/code\u003e\u003c/a\u003e ci: add dist sync validation workflow (\u003ca href=\"https://redirect.github.com/lodash/lodash/issues/6137\"\u003e#6137\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/lodash/lodash/compare/4.17.21...4.18.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nanoid` from 3.3.11 to 3.3.19\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/releases\"\u003enanoid's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed breaking Nano ID by requesting big ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ai/nanoid/blob/main/CHANGELOG.md\"\u003enanoid's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed killing the app by setting huge user ID (by \u003ca href=\"https://github.com/geoffrey-diederichs\"\u003e\u003ccode\u003e@​geoffrey-diederichs\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on async for React Native (by \u003ca href=\"https://github.com/OvergrowthBeards-JB\"\u003e\u003ccode\u003e@​OvergrowthBeards-JB\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on zero size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed infinite loop on negative size (by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.15\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed npm provenance error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.14\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed random pool corruption on big ID sizes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced npm package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.3.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed breaking Nano ID by requesting big ID.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/eb63bd6775188dc35d143bf24868be094f19b5ee\"\u003e\u003ccode\u003eeb63bd6\u003c/code\u003e\u003c/a\u003e Release 3.3.19 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9067e0361a643ab2c94ddd67606efbf275f6c0dd\"\u003e\u003ccode\u003e9067e03\u003c/code\u003e\u003c/a\u003e Sync CJS and ESM\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9ad98052b316c5e707f8098ace509d2ae165e54d\"\u003e\u003ccode\u003e9ad9805\u003c/code\u003e\u003c/a\u003e Release 3.3.18 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/55e50a0621ec084b4bb4000ea4e86e1191bd3da8\"\u003e\u003ccode\u003e55e50a0\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e10f8d40ce9d1ab47f66d65a16b48086432730d0\"\u003e\u003ccode\u003ee10f8d4\u003c/code\u003e\u003c/a\u003e Update index.native.js (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/606\"\u003e#606\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/73d67168136b36fd3b644159b0cff149da4905d9\"\u003e\u003ccode\u003e73d6716\u003c/code\u003e\u003c/a\u003e Release 3.3.17 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/f9d13f150847d117877adee3460a46eceb0cf49b\"\u003e\u003ccode\u003ef9d13f1\u003c/code\u003e\u003c/a\u003e Sync 0 size behaviour with PostCSS 5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/9760e112757cf7d46a79abd7a133bc4958757bb8\"\u003e\u003ccode\u003e9760e11\u003c/code\u003e\u003c/a\u003e Release 3.3.16 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66d\"\u003e\u003ccode\u003ee835c9b\u003c/code\u003e\u003c/a\u003e fix(non-secure): clamp negative size to prevent infinite loop (\u003ca href=\"https://redirect.github.com/ai/nanoid/issues/601\"\u003e#601\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ai/nanoid/commit/96dd086eb24396a275fa93ee78d73b2fece35809\"\u003e\u003ccode\u003e96dd086\u003c/code\u003e\u003c/a\u003e Update CI action\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ai/nanoid/compare/3.3.11...3.3.19\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for nanoid since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `postcss` from 8.5.6 to 8.5.28\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/releases\"\u003epostcss's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.28\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes types regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed removing any comments starting with \u003ccode\u003e/*#\u003c/code\u003e (by \u003ca href=\"https://github.com/dylanpulver\"\u003e\u003ccode\u003e@​dylanpulver\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e*\u003c/code\u003e hack before a comment in Custom Properties (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed empty values in the middle of \u003ccode\u003elist.comma()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed whitespace-only values in \u003ccode\u003elist.space()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed rule’s end position on space before semicolon (by \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/romainmenke\"\u003e\u003ccode\u003e@​romainmenke\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed Chinese text in deprecation warning (by \u003ca href=\"https://github.com/Jesse205\"\u003e\u003ccode\u003e@​Jesse205\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestricted loading previous source maps file to the \u003ccode\u003eopts.from\u003c/code\u003e folder for security reasons (use \u003ccode\u003eunsafeMap: true\u003c/code\u003e to disable the check).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.17\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eMaximum call stack size exceeded\u003c/code\u003e error.\u003c/li\u003e\n\u003cli\u003eFixed Prototype hijacking for \u003ccode\u003epostcss.fromJSON()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e for unmapped end position (by \u003ca href=\"https://github.com/chatman-media\"\u003e\u003ccode\u003e@​chatman-media\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.16\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eInput#origin()\u003c/code\u003e position (by \u003ca href=\"https://github.com/mizdra\"\u003e\u003ccode\u003e@​mizdra\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/postcss/blob/main/CHANGELOG.md\"\u003epostcss's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.5.28\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes types regression.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed removing any comments starting with \u003ccode\u003e/*#\u003c/code\u003e (by \u003ca href=\"https://github.com/dylanpulver\"\u003e\u003ccode\u003e@​dylanpulver\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003e*\u003c/code\u003e hack before a comment in Custom Properties (by \u003ca href=\"https://github.com/Jaybhade\"\u003e\u003ccode\u003e@​Jaybhade\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed empty values in the middle of \u003ccode\u003elist.comma()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed whitespace-only values in \u003ccode\u003elist.space()\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed rule’s end position on space before semicolon (by \u003ca href=\"https://github.com/maximilliangrand\"\u003e\u003ccode\u003e@​maximilliangrand\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed types (by \u003ca href=\"https://github.com/romainmenke\"\u003e\u003ccode\u003e@​romainmenke\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed Chinese text in deprecation warning (by \u003ca href=\"https://github.com/Jesse205\"\u003e\u003ccode\u003e@​Jesse205\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e regression (by \u003ca href=\"https://github.com/lazerg\"\u003e\u003ccode\u003e@​lazerg\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTrack symlinks in path protection in source map loading (by \u003ca href=\"https://github.com/drengir1\"\u003e\u003ccode\u003e@​drengir1\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed 8.5.17 visitor regression.\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003elist.split()\u003c/code\u003e for non-string values (by \u003ca href=\"https://github.com/amir-rezaei\"\u003e\u003ccode\u003e@​amir-rezaei\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve the BOM after the processing (by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDo not load source map without \u003ccode\u003eopts.from\u003c/code\u003e for security reasons.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed custom property losing semicolon before a comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.21\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed childless at-rule losing semicolon before comment (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed docs (by \u003ca href=\"https://github.com/isker\"\u003e\u003ccode\u003e@​isker\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed missing space if \u003ccode\u003eAtRule#params\u003c/code\u003e is set after (by \u003ca href=\"https://github.com/sarathfrancis90\"\u003e\u003ccode\u003e@​sarathfrancis90\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed mixing AST error on warnings (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e8.5.19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed cleaning \u003ccode\u003ebefore\u003c/code\u003e for new nodes inserted to \u003ccode\u003eRoot\u003c/code\u003e (by \u003ca href=\"https://github.com/MahinAnowar\"\u003e\u003ccode\u003e@​MahinAnowar\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/e544bffc4f4b3966d8ec69c41744b3ed65afc64a\"\u003e\u003ccode\u003ee544bff\u003c/code\u003e\u003c/a\u003e Release 8.5.28 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/f8fc2525717a6a7216659f7be43c525f60c6a15a\"\u003e\u003ccode\u003ef8fc252\u003c/code\u003e\u003c/a\u003e Typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/5039fd78962d285abea5d7b3aebef32f053781ce\"\u003e\u003ccode\u003e5039fd7\u003c/code\u003e\u003c/a\u003e Add missed release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/ae40ca499cf6a9afdbb264c0ec09e71fe934e2af\"\u003e\u003ccode\u003eae40ca4\u003c/code\u003e\u003c/a\u003e Release 8.5.27 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/62b1626bb7fbb28eda616d002cbd525d239b18ba\"\u003e\u003ccode\u003e62b1626\u003c/code\u003e\u003c/a\u003e Fix linter\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/1dba9384515a2dbc64517697c2f738b6d5c3f9a4\"\u003e\u003ccode\u003e1dba938\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/3e82edc9f037faa41647342dceceba9b841f9881\"\u003e\u003ccode\u003e3e82edc\u003c/code\u003e\u003c/a\u003e Keep non-annotation comments when the processor has no plugins (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2150\"\u003e#2150\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/6d23bc362203118478bc8051b81f2910907ebe6e\"\u003e\u003ccode\u003e6d23bc3\u003c/code\u003e\u003c/a\u003e Fix link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/508e9976be81536292e7666741e1c35e876b9a6a\"\u003e\u003ccode\u003e508e997\u003c/code\u003e\u003c/a\u003e Add GitHub Sponsors link\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/postcss/commit/e993739dc49b6055f7dfc59b161d75702f0b2b8b\"\u003e\u003ccode\u003ee993739\u003c/code\u003e\u003c/a\u003e Add CodeRabbit sponsor (\u003ca href=\"https://redirect.github.com/postcss/postcss/issues/2145\"\u003e#2145\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/postcss/compare/8.5.6...8.5.28\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for postcss since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `qs` from 6.14.1 to 6.16.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com...\n\n_Description has been truncated_","html_url":"https://github.com/hashim21223445/Andoka-now-44/pull/59","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/hashim21223445%2FAndoka-now-44/issues/59","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/59/packages"}},{"old_version":"7.28.0","new_version":"7.29.1","update_type":"minor","path":"/apps/frontend","pr_created_at":"2026-09-11T12:14:16.000Z","version_change":"7.28.0 → 7.29.1","issue":{"uuid":"5424162332","node_id":"PR_kwDORtkDrM8AAAABDI-fgA","number":172,"state":"closed","title":"build(deps): bump undici from 7.28.0 to 7.29.1 in /apps/frontend","user":"dependabot[bot]","labels":["dependencies","javascript","released"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-11T12:15:40.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-11T12:14:16.000Z","updated_at":"2026-09-11T14:54:09.000Z","time_to_close":84,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps)","packages":[{"name":"undici","old_version":"7.28.0","new_version":"7.29.1","repository_url":"https://github.com/nodejs/undici"}],"path":"/apps/frontend","ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 7.28.0 to 7.29.1.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.1\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/f690157d728508652fef14673630c71515123e96\"\u003ef690157d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6615e0175e9b635bcd2e3e87a47daa82f6f5b728\"\u003e6615e017\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/63cf698b611fecc6ee0a17b185b930051e4b982f\"\u003e63cf698b\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1858656ebb1e919311c1f31613dfd581b7214349\"\u003e1858656e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/b6c5a00252c37da9dd2db9bead053bb843e1f988\"\u003eb6c5a002\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2c7d7e1227043c644c4c32cfd1e276f4fd4fcb11\"\u003e2c7d7e12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3c6726599cea8646384dde846c97d630da472a74\"\u003e3c672659\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/b61d9432bac7caac51273ad209862e4c0bf935ae\"\u003eb61d9432\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/21693f406f0142f3504192e9f9b022dcf84782ae\"\u003e21693f40\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cd8af90b38ae33c2838d54a2d629774122effe95\"\u003ecd8af90b\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[v7.x] drop: remove Node.js 26 from shared-builtin CI build by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5592\"\u003enodejs/undici#5592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): honour headersTimeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5604\"\u003enodejs/undici#5604\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): keep the connection ref'd while requests are outstanding by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5605\"\u003enodejs/undici#5605\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: increase Windows workflow timeout on v7.x by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5621\"\u003enodejs/undici#5621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): retire the request that completed, not the head of the queue by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5618\"\u003enodejs/undici#5618\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): settle a request whose stream is cancelled by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5607\"\u003enodejs/undici#5607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: reduce EventSourceStream parser allocations (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5032\"\u003e#5032\u003c/a\u003e) by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5646\"\u003enodejs/undici#5646\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): handle GOAWAY for CONNECT streams by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5640\"\u003enodejs/undici#5640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v7.x] perf(h1): drop idle-socket timer floor with a ref'd setImmediate (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5707\"\u003e#5707\u003c/a\u003e) by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5769\"\u003enodejs/undici#5769\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.29.0...v7.29.1\"\u003ehttps://github.com/nodejs/undici/compare/v7.29.0...v7.29.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d39a83e7b0d631590c3b85b5cc0dbeab66c3a1d8\"\u003e\u003ccode\u003ed39a83e\u003c/code\u003e\u003c/a\u003e Bumped v7.29.1 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5772\"\u003e#5772\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0d88464876d02bdb9cf27015d9d66500a8aaa782\"\u003e\u003ccode\u003e0d88464\u003c/code\u003e\u003c/a\u003e fix(test): remove unused EventEmitter import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f57411b894d45b89964252971497507500c32bc1\"\u003e\u003ccode\u003ef57411b\u003c/code\u003e\u003c/a\u003e perf(h1): drop idle-socket timer floor with a ref'd setImmediate (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5707\"\u003e#5707\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5769\"\u003e#5769\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3c6726599cea8646384dde846c97d630da472a74\"\u003e\u003ccode\u003e3c67265\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cd8af90b38ae33c2838d54a2d629774122effe95\"\u003e\u003ccode\u003ecd8af90\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6615e0175e9b635bcd2e3e87a47daa82f6f5b728\"\u003e\u003ccode\u003e6615e01\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2c7d7e1227043c644c4c32cfd1e276f4fd4fcb11\"\u003e\u003ccode\u003e2c7d7e1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b6c5a00252c37da9dd2db9bead053bb843e1f988\"\u003e\u003ccode\u003eb6c5a00\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/21693f406f0142f3504192e9f9b022dcf84782ae\"\u003e\u003ccode\u003e21693f4\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f690157d728508652fef14673630c71515123e96\"\u003e\u003ccode\u003ef690157\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.28.0...v7.29.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=7.28.0\u0026new-version=7.29.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/venkatesh-singamsetty/cricscore/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/venkatesh-singamsetty/cricscore/pull/172","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/venkatesh-singamsetty%2Fcricscore/issues/172","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/172/packages"}},{"old_version":"7.25.0","new_version":"7.29.1","update_type":"minor","path":null,"pr_created_at":"2026-09-11T11:59:40.000Z","version_change":"7.25.0 → 7.29.1","issue":{"uuid":"5424035437","node_id":"PR_kwDOR_3Bw88AAAABDI3_hg","number":59,"state":"closed","title":"build(deps): bump undici from 7.25.0 to 7.29.1","user":"dependabot[bot]","labels":["dependencies","javascript"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-11T12:11:51.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-11T11:59:40.000Z","updated_at":"2026-09-11T12:11:53.000Z","time_to_close":731,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps)","packages":[{"name":"undici","old_version":"7.25.0","new_version":"7.29.1","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 7.25.0 to 7.29.1.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.1\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/f690157d728508652fef14673630c71515123e96\"\u003ef690157d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6615e0175e9b635bcd2e3e87a47daa82f6f5b728\"\u003e6615e017\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/63cf698b611fecc6ee0a17b185b930051e4b982f\"\u003e63cf698b\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1858656ebb1e919311c1f31613dfd581b7214349\"\u003e1858656e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/b6c5a00252c37da9dd2db9bead053bb843e1f988\"\u003eb6c5a002\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2c7d7e1227043c644c4c32cfd1e276f4fd4fcb11\"\u003e2c7d7e12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3c6726599cea8646384dde846c97d630da472a74\"\u003e3c672659\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/b61d9432bac7caac51273ad209862e4c0bf935ae\"\u003eb61d9432\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/21693f406f0142f3504192e9f9b022dcf84782ae\"\u003e21693f40\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cd8af90b38ae33c2838d54a2d629774122effe95\"\u003ecd8af90b\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[v7.x] drop: remove Node.js 26 from shared-builtin CI build by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5592\"\u003enodejs/undici#5592\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): honour headersTimeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5604\"\u003enodejs/undici#5604\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): keep the connection ref'd while requests are outstanding by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5605\"\u003enodejs/undici#5605\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: increase Windows workflow timeout on v7.x by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5621\"\u003enodejs/undici#5621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): retire the request that completed, not the head of the queue by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5618\"\u003enodejs/undici#5618\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): settle a request whose stream is cancelled by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5607\"\u003enodejs/undici#5607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: reduce EventSourceStream parser allocations (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5032\"\u003e#5032\u003c/a\u003e) by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5646\"\u003enodejs/undici#5646\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(h2): handle GOAWAY for CONNECT streams by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5640\"\u003enodejs/undici#5640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v7.x] perf(h1): drop idle-socket timer floor with a ref'd setImmediate (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5707\"\u003e#5707\u003c/a\u003e) by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5769\"\u003enodejs/undici#5769\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nodejs/undici/compare/v7.29.0...v7.29.1\"\u003ehttps://github.com/nodejs/undici/compare/v7.29.0...v7.29.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev7.29.0\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-4cwx-7wf7-3272\"\u003eGHSA-4cwx-7wf7-3272\u003c/a\u003e: malformed qualified \u003ccode\u003eprivate\u003c/code\u003e Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/9f10f1e9bfcc68b5c8b53d0459cb6d9562008fcd\"\u003e9f10f1e9\u003c/a\u003e, with regression coverage in \u003ca href=\"https://github.com/nodejs/undici/commit/466e99d123b452c9ac56dea8b03ec4dcd0d98ad5\"\u003e466e99d1\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-m8rv-5g2x-5cg5\"\u003eGHSA-m8rv-5g2x-5cg5\u003c/a\u003e: a malicious \u003ccode\u003etype\u003c/code\u003e property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated \u003ccode\u003econtent-type\u003c/code\u003e header. Undici now coerces and validates the value before adding it to the request. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/33928bc24f742ea8422ed90d17f2e0cc83e4d09d\"\u003e33928bc2\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-jr45-8vmc-qm54\"\u003eGHSA-jr45-8vmc-qm54\u003c/a\u003e: optional whitespace around \u003ccode\u003e=\u003c/code\u003e in qualified \u003ccode\u003eno-cache\u003c/code\u003e and \u003ccode\u003eprivate\u003c/code\u003e directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/98011a862a248bb43c1bc5a2edcf4ee787948e95\"\u003e98011a86\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524\"\u003eGHSA-8xcm-r25x-g524\u003c/a\u003e: the retry interceptor could expose a stale \u003ccode\u003eContent-Length\u003c/code\u003e after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose \u003ccode\u003eContent-Length\u003c/code\u003e is inconsistent with \u003ccode\u003eContent-Range\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c\"\u003e1b5a5312\u003c/a\u003e, with corrected fixtures in \u003ca href=\"https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7\"\u003e4a9dafb1\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm\"\u003eGHSA-v3r7-h72x-cjcm\u003c/a\u003e: unsanitized \u003ccode\u003edomain\u003c/code\u003e and \u003ccode\u003eunparsed\u003c/code\u003e values passed to \u003ccode\u003esetCookie()\u003c/code\u003e could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef\"\u003e3bf91ddb\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/d39a83e7b0d631590c3b85b5cc0dbeab66c3a1d8\"\u003e\u003ccode\u003ed39a83e\u003c/code\u003e\u003c/a\u003e Bumped v7.29.1 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5772\"\u003e#5772\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0d88464876d02bdb9cf27015d9d66500a8aaa782\"\u003e\u003ccode\u003e0d88464\u003c/code\u003e\u003c/a\u003e fix(test): remove unused EventEmitter import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f57411b894d45b89964252971497507500c32bc1\"\u003e\u003ccode\u003ef57411b\u003c/code\u003e\u003c/a\u003e perf(h1): drop idle-socket timer floor with a ref'd setImmediate (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5707\"\u003e#5707\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5769\"\u003e#5769\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/3c6726599cea8646384dde846c97d630da472a74\"\u003e\u003ccode\u003e3c67265\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cd8af90b38ae33c2838d54a2d629774122effe95\"\u003e\u003ccode\u003ecd8af90\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6615e0175e9b635bcd2e3e87a47daa82f6f5b728\"\u003e\u003ccode\u003e6615e01\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2c7d7e1227043c644c4c32cfd1e276f4fd4fcb11\"\u003e\u003ccode\u003e2c7d7e1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/b6c5a00252c37da9dd2db9bead053bb843e1f988\"\u003e\u003ccode\u003eb6c5a00\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/21693f406f0142f3504192e9f9b022dcf84782ae\"\u003e\u003ccode\u003e21693f4\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/f690157d728508652fef14673630c71515123e96\"\u003e\u003ccode\u003ef690157\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v7.25.0...v7.29.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=7.25.0\u0026new-version=7.29.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/trashmans/hello-fresh-trash-app/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/trashmans/hello-fresh-trash-app/pull/59","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/trashmans%2Fhello-fresh-trash-app/issues/59","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/59/packages"}},{"old_version":"8.9.0","new_version":"8.10.2","update_type":"minor","path":null,"pr_created_at":"2026-09-11T11:58:07.000Z","version_change":"8.9.0 → 8.10.2","issue":{"uuid":"5424022568","node_id":"PR_kwDOIU25788AAAABDI3Vbw","number":259,"state":"open","title":"deps(deps): bump the other-dependencies group across 1 directory with 47 updates","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T11:58:07.000Z","updated_at":"2026-09-11T11:59:39.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"deps(deps): bump","group_name":"other-dependencies","update_count":47,"packages":[{"name":"@types/node","old_version":"26.4.1","new_version":"26.5.0","repository_url":"https://github.com/DefinitelyTyped/DefinitelyTyped"},{"name":"@asamuzakjp/css-color","old_version":"6.0.5","new_version":"6.0.7","repository_url":"https://github.com/asamuzaK/cssColor"},{"name":"@asamuzakjp/dom-selector","old_version":"8.3.0","new_version":"8.3.2","repository_url":"https://github.com/asamuzaK/domSelector"},{"name":"@babel/types","old_version":"7.29.7","new_version":"7.29.8","repository_url":"https://github.com/babel/babel"},{"name":"@babel/parser","old_version":"7.29.7","new_version":"7.29.8","repository_url":"https://github.com/babel/babel"},{"name":"@csstools/color-helpers","old_version":"6.1.0","new_version":"6.1.1","repository_url":"https://github.com/csstools/postcss-plugins"},{"name":"@csstools/css-color-parser","old_version":"4.1.10","new_version":"4.2.2","repository_url":"https://github.com/csstools/postcss-plugins"},{"name":"@csstools/css-syntax-patches-for-csstree","old_version":"1.1.7","new_version":"1.1.13","repository_url":"https://github.com/csstools/postcss-plugins"},{"name":"@inquirer/ansi","old_version":"2.0.7","new_version":"2.0.8","repository_url":"https://github.com/SBoudrias/Inquirer.js"},{"name":"@inquirer/checkbox","old_version":"5.2.1","new_version":"5.2.5","repository_url":"https://github.com/SBoudrias/Inquirer.js"},{"name":"@inquirer/editor","old_version":"5.2.2","new_version":"5.3.3","repository_url":"https://github.com/SBoudrias/Inquirer.js"},{"name":"@inquirer/expand","old_version":"5.1.1","new_version":"5.1.5","repository_url":"https://github.com/SBoudrias/Inquirer.js"},{"name":"@inquirer/input","old_version":"5.1.2","new_version":"5.1.6","repository_url":"https://github.com/SBoudrias/Inquirer.js"},{"name":"@inquirer/number","old_version":"4.1.1","new_version":"4.2.3","repository_url":"https://github.com/SBoudrias/Inquirer.js"},{"name":"@inquirer/password","old_version":"5.1.1","new_version":"5.2.2","repository_url":"https://github.com/SBoudrias/Inquirer.js"},{"name":"@inquirer/rawlist","old_version":"5.3.1","new_version":"5.3.5","repository_url":"https://github.com/SBoudrias/Inquirer.js"},{"name":"@inquirer/search","old_version":"4.2.1","new_version":"4.3.3","repository_url":"https://github.com/SBoudrias/Inquirer.js"},{"name":"@inquirer/select","old_version":"5.2.1","new_version":"5.2.5","repository_url":"https://github.com/SBoudrias/Inquirer.js"},{"name":"@jridgewell/sourcemap-codec","old_version":"1.5.5","new_version":"1.6.0","repository_url":"https://github.com/jridgewell/sourcemaps"},{"name":"@napi-rs/wasm-runtime","old_version":"1.2.2","new_version":"1.2.4","repository_url":"https://github.com/napi-rs/napi-rs"},{"name":"ansi-regex","old_version":"6.2.2","new_version":"6.3.0","repository_url":"https://github.com/chalk/ansi-regex"},{"name":"ast-v8-to-istanbul","old_version":"1.0.5","new_version":"1.0.6","repository_url":"https://github.com/AriPerkkio/ast-v8-to-istanbul"},{"name":"axios","old_version":"1.19.0","new_version":"1.20.0","repository_url":"https://github.com/axios/axios"},{"name":"baseline-browser-mapping","old_version":"2.11.8","new_version":"2.11.22","repository_url":"https://github.com/web-platform-dx/baseline-browser-mapping"},{"name":"bidi-js","old_version":"1.0.3","new_version":"1.1.0","repository_url":"https://github.com/lojjic/bidi-js"},{"name":"browserslist","old_version":"4.28.7","new_version":"4.28.9","repository_url":"https://github.com/browserslist/browserslist"},{"name":"chromedriver","old_version":"152.0.2","new_version":"153.0.0","repository_url":"https://github.com/giggio/node-chromedriver"},{"name":"express-rate-limit","old_version":"8.6.2","new_version":"8.7.0","repository_url":"https://github.com/express-rate-limit/express-rate-limit"},{"name":"hono","old_version":"4.13.5","new_version":"4.13.7","repository_url":"https://github.com/honojs/hono"},{"name":"ip-address","old_version":"10.4.0","new_version":"10.7.0","repository_url":"https://github.com/beaugunderson/ip-address"},{"name":"jose","old_version":"6.2.10","new_version":"6.2.12","repository_url":"https://github.com/panva/jose"},{"name":"postcss","old_version":"8.5.25","new_version":"8.5.28","repository_url":"https://github.com/postcss/postcss"},{"name":"postcss-safe-parser","old_version":"7.0.1","new_version":"7.1.0","repository_url":"https://github.com/postcss/postcss-safe-parser"},{"name":"readdirp","old_version":"5.0.0","new_version":"5.1.1","repository_url":"https://github.com/paulmillr/readdirp"},{"name":"socks","old_version":"2.8.9","new_version":"2.8.10","repository_url":"https://github.com/JoshGlazebrook/socks"},{"name":"tldts","old_version":"7.4.10","new_version":"7.4.12","repository_url":"https://github.com/remusao/tldts"},{"name":"undici","old_version":"8.9.0","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"},{"name":"ws","old_version":"8.21.1","new_version":"8.21.3","repository_url":"https://github.com/websockets/ws"}],"path":null,"ecosystem":"npm"},"body":"Bumps the other-dependencies group with 38 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.4.1` | `26.5.0` |\n| [@asamuzakjp/css-color](https://github.com/asamuzaK/cssColor) | `6.0.5` | `6.0.7` |\n| [@asamuzakjp/dom-selector](https://github.com/asamuzaK/domSelector) | `8.3.0` | `8.3.2` |\n| [@babel/types](https://github.com/babel/babel/tree/HEAD/packages/babel-types) | `7.29.7` | `7.29.8` |\n| [@babel/parser](https://github.com/babel/babel/tree/HEAD/packages/babel-parser) | `7.29.7` | `7.29.8` |\n| [@csstools/color-helpers](https://github.com/csstools/postcss-plugins/tree/HEAD/packages/color-helpers) | `6.1.0` | `6.1.1` |\n| [@csstools/css-color-parser](https://github.com/csstools/postcss-plugins/tree/HEAD/packages/css-color-parser) | `4.1.10` | `4.2.2` |\n| [@csstools/css-syntax-patches-for-csstree](https://github.com/csstools/postcss-plugins/tree/HEAD/packages/css-syntax-patches-for-csstree) | `1.1.7` | `1.1.13` |\n| [@inquirer/ansi](https://github.com/SBoudrias/Inquirer.js) | `2.0.7` | `2.0.8` |\n| [@inquirer/checkbox](https://github.com/SBoudrias/Inquirer.js) | `5.2.1` | `5.2.5` |\n| [@inquirer/editor](https://github.com/SBoudrias/Inquirer.js) | `5.2.2` | `5.3.3` |\n| [@inquirer/expand](https://github.com/SBoudrias/Inquirer.js) | `5.1.1` | `5.1.5` |\n| [@inquirer/input](https://github.com/SBoudrias/Inquirer.js) | `5.1.2` | `5.1.6` |\n| [@inquirer/number](https://github.com/SBoudrias/Inquirer.js) | `4.1.1` | `4.2.3` |\n| [@inquirer/password](https://github.com/SBoudrias/Inquirer.js) | `5.1.1` | `5.2.2` |\n| [@inquirer/rawlist](https://github.com/SBoudrias/Inquirer.js) | `5.3.1` | `5.3.5` |\n| [@inquirer/search](https://github.com/SBoudrias/Inquirer.js) | `4.2.1` | `4.3.3` |\n| [@inquirer/select](https://github.com/SBoudrias/Inquirer.js) | `5.2.1` | `5.2.5` |\n| [@jridgewell/sourcemap-codec](https://github.com/jridgewell/sourcemaps/tree/HEAD/packages/sourcemap-codec) | `1.5.5` | `1.6.0` |\n| [@napi-rs/wasm-runtime](https://github.com/napi-rs/napi-rs/tree/HEAD/wasm-runtime) | `1.2.2` | `1.2.4` |\n| [ansi-regex](https://github.com/chalk/ansi-regex) | `6.2.2` | `6.3.0` |\n| [ast-v8-to-istanbul](https://github.com/AriPerkkio/ast-v8-to-istanbul) | `1.0.5` | `1.0.6` |\n| [axios](https://github.com/axios/axios) | `1.19.0` | `1.20.0` |\n| [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) | `2.11.8` | `2.11.22` |\n| [bidi-js](https://github.com/lojjic/bidi-js) | `1.0.3` | `1.1.0` |\n| [browserslist](https://github.com/browserslist/browserslist) | `4.28.7` | `4.28.9` |\n| [chromedriver](https://github.com/giggio/node-chromedriver) | `152.0.2` | `153.0.0` |\n| [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) | `8.6.2` | `8.7.0` |\n| [hono](https://github.com/honojs/hono) | `4.13.5` | `4.13.7` |\n| [ip-address](https://github.com/beaugunderson/ip-address) | `10.4.0` | `10.7.0` |\n| [jose](https://github.com/panva/jose) | `6.2.10` | `6.2.12` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.25` | `8.5.28` |\n| [postcss-safe-parser](https://github.com/postcss/postcss-safe-parser) | `7.0.1` | `7.1.0` |\n| [readdirp](https://github.com/paulmillr/readdirp) | `5.0.0` | `5.1.1` |\n| [socks](https://github.com/JoshGlazebrook/socks) | `2.8.9` | `2.8.10` |\n| [tldts](https://github.com/remusao/tldts) | `7.4.10` | `7.4.12` |\n| [undici](https://github.com/nodejs/undici) | `8.9.0` | `8.10.2` |\n| [ws](https://github.com/websockets/ws) | `8.21.1` | `8.21.3` |\n\n\nUpdates `@types/node` from 26.4.1 to 26.5.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@asamuzakjp/css-color` from 6.0.5 to 6.0.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/asamuzaK/cssColor/releases\"\u003e@​asamuzakjp/css-color's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.0.7\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd sortMathFnTerms function by \u003ca href=\"https://github.com/asamuzaK\"\u003e\u003ccode\u003e@​asamuzaK\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/asamuzaK/cssColor/pull/118\"\u003easamuzaK/cssColor#118\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/asamuzaK/cssColor/compare/v6.0.6...v6.0.7\"\u003ehttps://github.com/asamuzaK/cssColor/compare/v6.0.6...v6.0.7\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev6.0.6\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix min/max functions in calc expressions by \u003ca href=\"https://github.com/asamuzaK\"\u003e\u003ccode\u003e@​asamuzaK\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/asamuzaK/cssColor/pull/116\"\u003easamuzaK/cssColor#116\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix math() functions and sort calc() args by \u003ca href=\"https://github.com/asamuzaK\"\u003e\u003ccode\u003e@​asamuzaK\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/asamuzaK/cssColor/pull/117\"\u003easamuzaK/cssColor#117\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/asamuzaK/cssColor/compare/v6.0.5...v6.0.6\"\u003ehttps://github.com/asamuzaK/cssColor/compare/v6.0.5...v6.0.6\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/cssColor/commit/e637b110301d5d8c869b5d2ad15bc31d8fe8103c\"\u003e\u003ccode\u003ee637b11\u003c/code\u003e\u003c/a\u003e v6.0.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/cssColor/commit/4d849a149334fad12fe88214f2de3d2e72e42c4d\"\u003e\u003ccode\u003e4d849a1\u003c/code\u003e\u003c/a\u003e Add sortMathFnTerms function (\u003ca href=\"https://redirect.github.com/asamuzaK/cssColor/issues/118\"\u003e#118\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/cssColor/commit/87ce8ae21ab081611427752e0e7e2c18c6f3b778\"\u003e\u003ccode\u003e87ce8ae\u003c/code\u003e\u003c/a\u003e v6.0.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/cssColor/commit/45df517257c3a4f6b36f1a0e83c395b8b85843f1\"\u003e\u003ccode\u003e45df517\u003c/code\u003e\u003c/a\u003e Fix math-function detection\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/cssColor/commit/0d521956ec0225435e9a53b0507b1b942b31e1a3\"\u003e\u003ccode\u003e0d52195\u003c/code\u003e\u003c/a\u003e Fix math() functions and sort calc() args (\u003ca href=\"https://redirect.github.com/asamuzaK/cssColor/issues/117\"\u003e#117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/cssColor/commit/5df35737f31d337f2433663cab54299c366c69d9\"\u003e\u003ccode\u003e5df3573\u003c/code\u003e\u003c/a\u003e Fix min/max functions in calc expressions (\u003ca href=\"https://redirect.github.com/asamuzaK/cssColor/issues/116\"\u003e#116\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/cssColor/commit/d1e11135df8e5f15d19375b1503611a705361544\"\u003e\u003ccode\u003ed1e1113\u003c/code\u003e\u003c/a\u003e Update dependencies and devDependencies\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/asamuzaK/cssColor/compare/v6.0.5...v6.0.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@asamuzakjp/dom-selector` from 8.3.0 to 8.3.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/asamuzaK/domSelector/releases\"\u003e@​asamuzakjp/dom-selector's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.3.2\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/asamuzaK/domSelector/compare/v8.3.1...v8.3.2\"\u003ehttps://github.com/asamuzaK/domSelector/compare/v8.3.1...v8.3.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev8.3.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/asamuzaK/domSelector/compare/v8.3.0...v8.3.1\"\u003ehttps://github.com/asamuzaK/domSelector/compare/v8.3.0...v8.3.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/domSelector/commit/3a8c5e0ecb2ac69c6ed600da73f819fd3a367902\"\u003e\u003ccode\u003e3a8c5e0\u003c/code\u003e\u003c/a\u003e v8.3.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/domSelector/commit/2780b0a0f3399351f4ddd2789f99b5337f454645\"\u003e\u003ccode\u003e2780b0a\u003c/code\u003e\u003c/a\u003e Match common attribute selectors in validation (\u003ca href=\"https://redirect.github.com/asamuzaK/domSelector/issues/301\"\u003e#301\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/domSelector/commit/3288d3b16ca54cdb9fa3d14c529a9657f9714ac5\"\u003e\u003ccode\u003e3288d3b\u003c/code\u003e\u003c/a\u003e v8.3.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/asamuzaK/domSelector/commit/a52bf29317b180913225e0cba23ad57dbcb81b6d\"\u003e\u003ccode\u003ea52bf29\u003c/code\u003e\u003c/a\u003e Fix attribute selectors case-insensitivity (\u003ca href=\"https://redirect.github.com/asamuzaK/domSelector/issues/300\"\u003e#300\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/asamuzaK/domSelector/compare/v8.3.0...v8.3.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@babel/types` from 7.29.7 to 7.29.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/babel/babel/releases\"\u003e@​babel/types's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.8 (2026-07-31)\u003c/h2\u003e\n\u003ch4\u003e:eyeglasses: Spec Compliance\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e, \u003ccode\u003ebabel-parser\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-spread\u003c/code\u003e, \u003ccode\u003ebabel-traverse\u003c/code\u003e, \u003ccode\u003ebabel-types\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17871\"\u003e#17871\u003c/a\u003e Disallow super call after new (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18046\"\u003e#18046\u003c/a\u003e fix(generator): improve new callee parens check (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-node\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18044\"\u003e#18044\u003c/a\u003e fix(systemjs): support \u003ccode\u003e__proto__\u003c/code\u003e as an export name (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 2\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/5de11ca9234379b78ef95df72aebbec93f28bf45\"\u003e\u003ccode\u003e5de11ca\u003c/code\u003e\u003c/a\u003e v7.29.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/64c37e53529ba4a24ba1f074fdce3d439c6b29ba\"\u003e\u003ccode\u003e64c37e5\u003c/code\u003e\u003c/a\u003e Disallow super call after new (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-types/issues/17871\"\u003e#17871\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/babel/babel/commits/v7.29.8/packages/babel-types\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@babel/parser` from 7.29.7 to 7.29.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/babel/babel/releases\"\u003e@​babel/parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.29.8 (2026-07-31)\u003c/h2\u003e\n\u003ch4\u003e:eyeglasses: Spec Compliance\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e, \u003ccode\u003ebabel-parser\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-spread\u003c/code\u003e, \u003ccode\u003ebabel-traverse\u003c/code\u003e, \u003ccode\u003ebabel-types\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/17871\"\u003e#17871\u003c/a\u003e Disallow super call after new (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003e:bug: Bug Fix\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebabel-generator\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18046\"\u003e#18046\u003c/a\u003e fix(generator): improve new callee parens check (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebabel-node\u003c/code\u003e, \u003ccode\u003ebabel-plugin-transform-modules-systemjs\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/babel/babel/pull/18044\"\u003e#18044\u003c/a\u003e fix(systemjs): support \u003ccode\u003e__proto__\u003c/code\u003e as an export name (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eCommitters: 2\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHuáng Jùnliàng (\u003ca href=\"https://github.com/JLHwung\"\u003e\u003ccode\u003e@​JLHwung\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNicolò Ribaudo (\u003ca href=\"https://github.com/nicolo-ribaudo\"\u003e\u003ccode\u003e@​nicolo-ribaudo\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/5de11ca9234379b78ef95df72aebbec93f28bf45\"\u003e\u003ccode\u003e5de11ca\u003c/code\u003e\u003c/a\u003e v7.29.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/babel/babel/commit/64c37e53529ba4a24ba1f074fdce3d439c6b29ba\"\u003e\u003ccode\u003e64c37e5\u003c/code\u003e\u003c/a\u003e Disallow super call after new (\u003ca href=\"https://github.com/babel/babel/tree/HEAD/packages/babel-parser/issues/17871\"\u003e#17871\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/babel/babel/commits/v7.29.8/packages/babel-parser\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@csstools/color-helpers` from 6.1.0 to 6.1.1\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/csstools/postcss-plugins/blob/main/packages/color-helpers/CHANGELOG.md\"\u003e@​csstools/color-helpers's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch3\u003e6.1.1\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eAugust 15, 2026\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated: gamut mapping algorithm\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/csstools/postcss-plugins/commits/HEAD/packages/color-helpers\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@csstools/css-color-parser` from 4.1.10 to 4.2.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/csstools/postcss-plugins/blob/main/packages/css-color-parser/CHANGELOG.md\"\u003e@​csstools/css-color-parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch3\u003e4.2.2\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eAugust 30, 2026\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eNormalize hue in \u003ccode\u003ecomputedValue()\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e4.2.1\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eAugust 25, 2026\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve powerless hue in \u003ccode\u003ecolor-mix()\u003c/code\u003e when the input color space equals the interpolation color space, matching relative color syntax.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e4.2.0\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eAugust 15, 2026\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003ecomputedValue()\u003c/code\u003e serialization function for color data.\u003c/li\u003e\n\u003cli\u003eMandatory \u003ccode\u003ealpha\u003c/code\u003e in the relative \u003ccode\u003ealpha()\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eUpdated \u003ca href=\"https://github.com/csstools/postcss-plugins/tree/main/packages/color-helpers\"\u003e\u003ccode\u003e@csstools/color-helpers\u003c/code\u003e\u003c/a\u003e to \u003ca href=\"https://github.com/csstools/postcss-plugins/tree/main/packages/color-helpers/CHANGELOG.md#611\"\u003e\u003ccode\u003e6.1.1\u003c/code\u003e\u003c/a\u003e (patch)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/csstools/postcss-plugins/commits/HEAD/packages/css-color-parser\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@csstools/css-syntax-patches-for-csstree` from 1.1.7 to 1.1.13\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/csstools/postcss-plugins/blob/main/packages/css-syntax-patches-for-csstree/CHANGELOG.md\"\u003e@​csstools/css-syntax-patches-for-csstree's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch3\u003e1.1.13\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eSeptember 10, 2026\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@webref/css\u003c/code\u003e to \u003ca href=\"https://github.com/w3c/webref/releases/tag/%40webref%2Fcss%408.7.4\"\u003e\u003ccode\u003ev8.7.4\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e1.1.12\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eAugust 31, 2026\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003e@import\u003c/code\u003e prelude syntax definition\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e1.1.11\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eAugust 31, 2026\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd at-rule preludes\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e1.1.10\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eAugust 30, 2026\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@webref/css\u003c/code\u003e to \u003ca href=\"https://github.com/w3c/webref/releases/tag/%40webref%2Fcss%408.7.3\"\u003e\u003ccode\u003ev8.7.3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e1.1.9\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eAugust 25, 2026\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@webref/css\u003c/code\u003e to \u003ca href=\"https://github.com/w3c/webref/releases/tag/%40webref%2Fcss%408.7.2\"\u003e\u003ccode\u003ev8.7.2\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e1.1.8\u003c/h3\u003e\n\u003cp\u003e\u003cem\u003eAugust 15, 2026\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@webref/css\u003c/code\u003e to \u003ca href=\"https://github.com/w3c/webref/releases/tag/%40webref%2Fcss%408.7.1\"\u003e\u003ccode\u003ev8.7.1\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/csstools/postcss-plugins/commits/HEAD/packages/css-syntax-patches-for-csstree\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/ansi` from 2.0.7 to 2.0.8\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/ansi's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/figures\u003c/code\u003e\u003ca href=\"https://github.com/2\"\u003e\u003ccode\u003e@​2\u003c/code\u003e\u003c/a\u003e.0.8\u003c/h2\u003e\n\u003cp\u003eNo source changes. Bumped to keep in lockstep with the \u003ccode\u003e@inquirer/*\u003c/code\u003e release train.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/5748bd9966b5e175ddf5995ee4cdce6f60c4272e\"\u003e\u003ccode\u003e5748bd9\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/269ae73ca9dd7ac738cd35f7d0222b3522021ad9\"\u003e\u003ccode\u003e269ae73\u003c/code\u003e\u003c/a\u003e fix: pin \u003ccode\u003e@​inquirer/type\u003c/code\u003e exactly in published manifests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/927d6dda59aacf8c4088d43df68da5062757cd6d\"\u003e\u003ccode\u003e927d6dd\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/testing\u003c/code\u003e): keep keypress simulation working under TERM=dumb\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2d813b145b9ce2a531d7ba6eafb8f7451594b004\"\u003e\u003ccode\u003e2d813b1\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.6 to 0.16.8 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2245\"\u003e#2245\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7affbc9bef22adcb059325c7e8450e3da64bd6fa\"\u003e\u003ccode\u003e7affbc9\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump turbo from 2.10.9 to 2.10.11 in the build group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2243\"\u003e#2243\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/56db98993c3c5c55864e5b1b7f458b1bb9c59e65\"\u003e\u003ccode\u003e56db989\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2242\"\u003e#2242\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8e6bc3cec6b88bbd08ff49b0f01fc5dabc5f6bb2\"\u003e\u003ccode\u003e8e6bc3c\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 2 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2241\"\u003e#2241\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/427b7a1f55d1947dd6876ce026706ae2369db313\"\u003e\u003ccode\u003e427b7a1\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the testing group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2240\"\u003e#2240\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/51ac389603405e8f9f315ce49416153d95c5fefe\"\u003e\u003ccode\u003e51ac389\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0f1718e9db1a129ad07c61a0d530f00dc4362740\"\u003e\u003ccode\u003e0f1718e\u003c/code\u003e\u003c/a\u003e feat(\u003ccode\u003e@​inquirer/password\u003c/code\u003e): add ctrl+t toggle to reveal password\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/ansi@2.0.7...@inquirer/ansi@2.0.8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/ansi\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/checkbox` from 5.2.1 to 5.2.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/checkbox's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/checkbox\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.2.3\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.1\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/type\u003c/code\u003e bumped to \u003ccode\u003e^4.1.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/checkbox\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.2.2\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.0\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/figures\u003c/code\u003e bumped to \u003ccode\u003e^2.0.8\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/cbdb34bfc6c245941d80ef88493c50b3d6dbfce6\"\u003e\u003ccode\u003ecbdb34b\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8340d2dd764d4b11d4e200412b614f9964ae0691\"\u003e\u003ccode\u003e8340d2d\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): clear hook effects before settling prompts\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2475e07186d824d52504095c71c2272d9e7338fe\"\u003e\u003ccode\u003e2475e07\u003c/code\u003e\u003c/a\u003e test(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): cover hook cleanup error semantics\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/15cd8d3b53bfc270633072073c24d6be6ce3d83b\"\u003e\u003ccode\u003e15cd8d3\u003c/code\u003e\u003c/a\u003e fix(confirm): ignore surrounding whitespace in answers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/9cb0da6c187346c955ab0b788fa1a88c897f16da\"\u003e\u003ccode\u003e9cb0da6\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/1c750bc55ab4fac310d70db84a7a6ada76c0e854\"\u003e\u003ccode\u003e1c750bc\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the build group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2251\"\u003e#2251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/81f1525110990603e9796d48eecde0f8c2d2fc98\"\u003e\u003ccode\u003e81f1525\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump \u003ccode\u003e@​types/node\u003c/code\u003e in the types group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2252\"\u003e#2252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7c27f26606a16b6e8f55b51e4431c72658c674c5\"\u003e\u003ccode\u003e7c27f26\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2249\"\u003e#2249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/6119088a4e07ec59460c3cd44d06817de97bfdac\"\u003e\u003ccode\u003e6119088\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2250\"\u003e#2250\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0d167c0aface3f5cf95132ada9bfec7946dd5b74\"\u003e\u003ccode\u003e0d167c0\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 4 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2248\"\u003e#2248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/checkbox@5.2.1...@inquirer/checkbox@5.2.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/checkbox\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/editor` from 5.2.2 to 5.3.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/editor's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/editor\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.3.1\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.1\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/type\u003c/code\u003e bumped to \u003ccode\u003e^4.1.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/editor\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.3.0\u003c/h2\u003e\n\u003ch3\u003eWhat's fixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAccept explicit \u003ccode\u003eundefined\u003c/code\u003e as the default value (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/pull/2182\"\u003e#2182\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.0\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/external-editor\u003c/code\u003e bumped to \u003ccode\u003e^3.0.4\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/cbdb34bfc6c245941d80ef88493c50b3d6dbfce6\"\u003e\u003ccode\u003ecbdb34b\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8340d2dd764d4b11d4e200412b614f9964ae0691\"\u003e\u003ccode\u003e8340d2d\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): clear hook effects before settling prompts\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2475e07186d824d52504095c71c2272d9e7338fe\"\u003e\u003ccode\u003e2475e07\u003c/code\u003e\u003c/a\u003e test(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): cover hook cleanup error semantics\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/15cd8d3b53bfc270633072073c24d6be6ce3d83b\"\u003e\u003ccode\u003e15cd8d3\u003c/code\u003e\u003c/a\u003e fix(confirm): ignore surrounding whitespace in answers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/9cb0da6c187346c955ab0b788fa1a88c897f16da\"\u003e\u003ccode\u003e9cb0da6\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/1c750bc55ab4fac310d70db84a7a6ada76c0e854\"\u003e\u003ccode\u003e1c750bc\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the build group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2251\"\u003e#2251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/81f1525110990603e9796d48eecde0f8c2d2fc98\"\u003e\u003ccode\u003e81f1525\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump \u003ccode\u003e@​types/node\u003c/code\u003e in the types group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2252\"\u003e#2252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7c27f26606a16b6e8f55b51e4431c72658c674c5\"\u003e\u003ccode\u003e7c27f26\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2249\"\u003e#2249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/6119088a4e07ec59460c3cd44d06817de97bfdac\"\u003e\u003ccode\u003e6119088\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2250\"\u003e#2250\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0d167c0aface3f5cf95132ada9bfec7946dd5b74\"\u003e\u003ccode\u003e0d167c0\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 4 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2248\"\u003e#2248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/editor@5.2.2...@inquirer/editor@5.3.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/editor\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/expand` from 5.1.1 to 5.1.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/expand's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/expand\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.1.3\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.1\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/type\u003c/code\u003e bumped to \u003ccode\u003e^4.1.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/expand\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.1.2\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/cbdb34bfc6c245941d80ef88493c50b3d6dbfce6\"\u003e\u003ccode\u003ecbdb34b\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8340d2dd764d4b11d4e200412b614f9964ae0691\"\u003e\u003ccode\u003e8340d2d\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): clear hook effects before settling prompts\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2475e07186d824d52504095c71c2272d9e7338fe\"\u003e\u003ccode\u003e2475e07\u003c/code\u003e\u003c/a\u003e test(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): cover hook cleanup error semantics\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/15cd8d3b53bfc270633072073c24d6be6ce3d83b\"\u003e\u003ccode\u003e15cd8d3\u003c/code\u003e\u003c/a\u003e fix(confirm): ignore surrounding whitespace in answers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/9cb0da6c187346c955ab0b788fa1a88c897f16da\"\u003e\u003ccode\u003e9cb0da6\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/1c750bc55ab4fac310d70db84a7a6ada76c0e854\"\u003e\u003ccode\u003e1c750bc\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the build group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2251\"\u003e#2251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/81f1525110990603e9796d48eecde0f8c2d2fc98\"\u003e\u003ccode\u003e81f1525\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump \u003ccode\u003e@​types/node\u003c/code\u003e in the types group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2252\"\u003e#2252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7c27f26606a16b6e8f55b51e4431c72658c674c5\"\u003e\u003ccode\u003e7c27f26\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2249\"\u003e#2249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/6119088a4e07ec59460c3cd44d06817de97bfdac\"\u003e\u003ccode\u003e6119088\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2250\"\u003e#2250\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0d167c0aface3f5cf95132ada9bfec7946dd5b74\"\u003e\u003ccode\u003e0d167c0\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 4 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2248\"\u003e#2248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/expand@5.1.1...@inquirer/expand@5.1.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/expand\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/external-editor` from 3.0.3 to 3.0.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/external-editor's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/external-editor\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.0.4\u003c/h2\u003e\n\u003cp\u003eNo source changes. Bumped to keep in lockstep with the \u003ccode\u003e@inquirer/*\u003c/code\u003e release train.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/5748bd9966b5e175ddf5995ee4cdce6f60c4272e\"\u003e\u003ccode\u003e5748bd9\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/269ae73ca9dd7ac738cd35f7d0222b3522021ad9\"\u003e\u003ccode\u003e269ae73\u003c/code\u003e\u003c/a\u003e fix: pin \u003ccode\u003e@​inquirer/type\u003c/code\u003e exactly in published manifests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/927d6dda59aacf8c4088d43df68da5062757cd6d\"\u003e\u003ccode\u003e927d6dd\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/testing\u003c/code\u003e): keep keypress simulation working under TERM=dumb\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2d813b145b9ce2a531d7ba6eafb8f7451594b004\"\u003e\u003ccode\u003e2d813b1\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.6 to 0.16.8 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2245\"\u003e#2245\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7affbc9bef22adcb059325c7e8450e3da64bd6fa\"\u003e\u003ccode\u003e7affbc9\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump turbo from 2.10.9 to 2.10.11 in the build group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2243\"\u003e#2243\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/56db98993c3c5c55864e5b1b7f458b1bb9c59e65\"\u003e\u003ccode\u003e56db989\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2242\"\u003e#2242\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8e6bc3cec6b88bbd08ff49b0f01fc5dabc5f6bb2\"\u003e\u003ccode\u003e8e6bc3c\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 2 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2241\"\u003e#2241\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/427b7a1f55d1947dd6876ce026706ae2369db313\"\u003e\u003ccode\u003e427b7a1\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the testing group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2240\"\u003e#2240\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/51ac389603405e8f9f315ce49416153d95c5fefe\"\u003e\u003ccode\u003e51ac389\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0f1718e9db1a129ad07c61a0d530f00dc4362740\"\u003e\u003ccode\u003e0f1718e\u003c/code\u003e\u003c/a\u003e feat(\u003ccode\u003e@​inquirer/password\u003c/code\u003e): add ctrl+t toggle to reveal password\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/external-editor@3.0.3...@inquirer/external-editor@3.0.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/external-editor\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/figures` from 2.0.7 to 2.0.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/figures's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/figures\u003c/code\u003e\u003ca href=\"https://github.com/2\"\u003e\u003ccode\u003e@​2\u003c/code\u003e\u003c/a\u003e.0.8\u003c/h2\u003e\n\u003cp\u003eNo source changes. Bumped to keep in lockstep with the \u003ccode\u003e@inquirer/*\u003c/code\u003e release train.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/5748bd9966b5e175ddf5995ee4cdce6f60c4272e\"\u003e\u003ccode\u003e5748bd9\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/269ae73ca9dd7ac738cd35f7d0222b3522021ad9\"\u003e\u003ccode\u003e269ae73\u003c/code\u003e\u003c/a\u003e fix: pin \u003ccode\u003e@​inquirer/type\u003c/code\u003e exactly in published manifests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/927d6dda59aacf8c4088d43df68da5062757cd6d\"\u003e\u003ccode\u003e927d6dd\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/testing\u003c/code\u003e): keep keypress simulation working under TERM=dumb\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2d813b145b9ce2a531d7ba6eafb8f7451594b004\"\u003e\u003ccode\u003e2d813b1\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.6 to 0.16.8 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2245\"\u003e#2245\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7affbc9bef22adcb059325c7e8450e3da64bd6fa\"\u003e\u003ccode\u003e7affbc9\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump turbo from 2.10.9 to 2.10.11 in the build group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2243\"\u003e#2243\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/56db98993c3c5c55864e5b1b7f458b1bb9c59e65\"\u003e\u003ccode\u003e56db989\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2242\"\u003e#2242\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8e6bc3cec6b88bbd08ff49b0f01fc5dabc5f6bb2\"\u003e\u003ccode\u003e8e6bc3c\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 2 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2241\"\u003e#2241\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/427b7a1f55d1947dd6876ce026706ae2369db313\"\u003e\u003ccode\u003e427b7a1\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the testing group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2240\"\u003e#2240\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/51ac389603405e8f9f315ce49416153d95c5fefe\"\u003e\u003ccode\u003e51ac389\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0f1718e9db1a129ad07c61a0d530f00dc4362740\"\u003e\u003ccode\u003e0f1718e\u003c/code\u003e\u003c/a\u003e feat(\u003ccode\u003e@​inquirer/password\u003c/code\u003e): add ctrl+t toggle to reveal password\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/figures@2.0.7...@inquirer/figures@2.0.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/figures\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/input` from 5.1.2 to 5.1.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/input's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/input\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.1.4\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.1\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/type\u003c/code\u003e bumped to \u003ccode\u003e^4.1.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/input\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.1.3\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/cbdb34bfc6c245941d80ef88493c50b3d6dbfce6\"\u003e\u003ccode\u003ecbdb34b\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8340d2dd764d4b11d4e200412b614f9964ae0691\"\u003e\u003ccode\u003e8340d2d\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): clear hook effects before settling prompts\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2475e07186d824d52504095c71c2272d9e7338fe\"\u003e\u003ccode\u003e2475e07\u003c/code\u003e\u003c/a\u003e test(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): cover hook cleanup error semantics\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/15cd8d3b53bfc270633072073c24d6be6ce3d83b\"\u003e\u003ccode\u003e15cd8d3\u003c/code\u003e\u003c/a\u003e fix(confirm): ignore surrounding whitespace in answers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/9cb0da6c187346c955ab0b788fa1a88c897f16da\"\u003e\u003ccode\u003e9cb0da6\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/1c750bc55ab4fac310d70db84a7a6ada76c0e854\"\u003e\u003ccode\u003e1c750bc\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the build group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2251\"\u003e#2251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/81f1525110990603e9796d48eecde0f8c2d2fc98\"\u003e\u003ccode\u003e81f1525\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump \u003ccode\u003e@​types/node\u003c/code\u003e in the types group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2252\"\u003e#2252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7c27f26606a16b6e8f55b51e4431c72658c674c5\"\u003e\u003ccode\u003e7c27f26\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2249\"\u003e#2249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/6119088a4e07ec59460c3cd44d06817de97bfdac\"\u003e\u003ccode\u003e6119088\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2250\"\u003e#2250\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0d167c0aface3f5cf95132ada9bfec7946dd5b74\"\u003e\u003ccode\u003e0d167c0\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 4 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2248\"\u003e#2248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/input@5.1.2...@inquirer/input@5.1.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/input\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/number` from 4.1.1 to 4.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/number's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/number\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.2.1\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.1\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/type\u003c/code\u003e bumped to \u003ccode\u003e^4.1.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/number\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.2.0\u003c/h2\u003e\n\u003ch3\u003eWhat's fixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid floating-point step errors by scaling value/step/min to exact decimal integers before the remainder check (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/pull/2166\"\u003e#2166\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAccept explicit \u003ccode\u003eundefined\u003c/code\u003e as the default value (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/pull/2182\"\u003e#2182\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/cbdb34bfc6c245941d80ef88493c50b3d6dbfce6\"\u003e\u003ccode\u003ecbdb34b\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8340d2dd764d4b11d4e200412b614f9964ae0691\"\u003e\u003ccode\u003e8340d2d\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): clear hook effects before settling prompts\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2475e07186d824d52504095c71c2272d9e7338fe\"\u003e\u003ccode\u003e2475e07\u003c/code\u003e\u003c/a\u003e test(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): cover hook cleanup error semantics\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/15cd8d3b53bfc270633072073c24d6be6ce3d83b\"\u003e\u003ccode\u003e15cd8d3\u003c/code\u003e\u003c/a\u003e fix(confirm): ignore surrounding whitespace in answers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/9cb0da6c187346c955ab0b788fa1a88c897f16da\"\u003e\u003ccode\u003e9cb0da6\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/1c750bc55ab4fac310d70db84a7a6ada76c0e854\"\u003e\u003ccode\u003e1c750bc\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the build group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2251\"\u003e#2251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/81f1525110990603e9796d48eecde0f8c2d2fc98\"\u003e\u003ccode\u003e81f1525\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump \u003ccode\u003e@​types/node\u003c/code\u003e in the types group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2252\"\u003e#2252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7c27f26606a16b6e8f55b51e4431c72658c674c5\"\u003e\u003ccode\u003e7c27f26\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2249\"\u003e#2249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/6119088a4e07ec59460c3cd44d06817de97bfdac\"\u003e\u003ccode\u003e6119088\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2250\"\u003e#2250\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0d167c0aface3f5cf95132ada9bfec7946dd5b74\"\u003e\u003ccode\u003e0d167c0\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 4 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2248\"\u003e#2248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/number@4.1.1...@inquirer/number@4.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/number\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/password` from 5.1.1 to 5.2.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/password's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/password\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.2.0\u003c/h2\u003e\n\u003ch3\u003eWhat's new\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded a \u003ccode\u003etoggleMask\u003c/code\u003e option to temporarily reveal the typed value with \u003ccode\u003ectrl+t\u003c/code\u003e, with a themed, i18n-able help tip for discoverability. Defaults to \u003ccode\u003etrue\u003c/code\u003e; set to \u003ccode\u003efalse\u003c/code\u003e to disable both the shortcut and its help line.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.1\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/type\u003c/code\u003e bumped to \u003ccode\u003e^4.1.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/password\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.1.2\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/cbdb34bfc6c245941d80ef88493c50b3d6dbfce6\"\u003e\u003ccode\u003ecbdb34b\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8340d2dd764d4b11d4e200412b614f9964ae0691\"\u003e\u003ccode\u003e8340d2d\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): clear hook effects before settling prompts\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2475e07186d824d52504095c71c2272d9e7338fe\"\u003e\u003ccode\u003e2475e07\u003c/code\u003e\u003c/a\u003e test(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): cover hook cleanup error semantics\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/15cd8d3b53bfc270633072073c24d6be6ce3d83b\"\u003e\u003ccode\u003e15cd8d3\u003c/code\u003e\u003c/a\u003e fix(confirm): ignore surrounding whitespace in answers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/9cb0da6c187346c955ab0b788fa1a88c897f16da\"\u003e\u003ccode\u003e9cb0da6\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/1c750bc55ab4fac310d70db84a7a6ada76c0e854\"\u003e\u003ccode\u003e1c750bc\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the build group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2251\"\u003e#2251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/81f1525110990603e9796d48eecde0f8c2d2fc98\"\u003e\u003ccode\u003e81f1525\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump \u003ccode\u003e@​types/node\u003c/code\u003e in the types group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2252\"\u003e#2252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7c27f26606a16b6e8f55b51e4431c72658c674c5\"\u003e\u003ccode\u003e7c27f26\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2249\"\u003e#2249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/6119088a4e07ec59460c3cd44d06817de97bfdac\"\u003e\u003ccode\u003e6119088\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2250\"\u003e#2250\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0d167c0aface3f5cf95132ada9bfec7946dd5b74\"\u003e\u003ccode\u003e0d167c0\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 4 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2248\"\u003e#2248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/password@5.1.1...@inquirer/password@5.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/password\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/rawlist` from 5.3.1 to 5.3.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/rawlist's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/rawlist\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.3.3\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.1\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/type\u003c/code\u003e bumped to \u003ccode\u003e^4.1.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/rawlist\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.3.2\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/cbdb34bfc6c245941d80ef88493c50b3d6dbfce6\"\u003e\u003ccode\u003ecbdb34b\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8340d2dd764d4b11d4e200412b614f9964ae0691\"\u003e\u003ccode\u003e8340d2d\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): clear hook effects before settling prompts\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2475e07186d824d52504095c71c2272d9e7338fe\"\u003e\u003ccode\u003e2475e07\u003c/code\u003e\u003c/a\u003e test(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): cover hook cleanup error semantics\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/15cd8d3b53bfc270633072073c24d6be6ce3d83b\"\u003e\u003ccode\u003e15cd8d3\u003c/code\u003e\u003c/a\u003e fix(confirm): ignore surrounding whitespace in answers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/9cb0da6c187346c955ab0b788fa1a88c897f16da\"\u003e\u003ccode\u003e9cb0da6\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/1c750bc55ab4fac310d70db84a7a6ada76c0e854\"\u003e\u003ccode\u003e1c750bc\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the build group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2251\"\u003e#2251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/81f1525110990603e9796d48eecde0f8c2d2fc98\"\u003e\u003ccode\u003e81f1525\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump \u003ccode\u003e@​types/node\u003c/code\u003e in the types group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2252\"\u003e#2252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7c27f26606a16b6e8f55b51e4431c72658c674c5\"\u003e\u003ccode\u003e7c27f26\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2249\"\u003e#2249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/6119088a4e07ec59460c3cd44d06817de97bfdac\"\u003e\u003ccode\u003e6119088\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2250\"\u003e#2250\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0d167c0aface3f5cf95132ada9bfec7946dd5b74\"\u003e\u003ccode\u003e0d167c0\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 4 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2248\"\u003e#2248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/rawlist@5.3.1...@inquirer/rawlist@5.3.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/rawlist\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/search` from 4.2.1 to 4.3.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/search's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/search\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.3.1\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.1\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/type\u003c/code\u003e bumped to \u003ccode\u003e^4.1.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/search\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.3.0\u003c/h2\u003e\n\u003ch3\u003eWhat's new\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eNew \u003ccode\u003einitialValue?: string\u003c/code\u003e option to pre-fill the search input (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/pull/2205\"\u003e#2205\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.0\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/figures\u003c/code\u003e bumped to \u003ccode\u003e^2.0.8\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/cbdb34bfc6c245941d80ef88493c50b3d6dbfce6\"\u003e\u003ccode\u003ecbdb34b\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8340d2dd764d4b11d4e200412b614f9964ae0691\"\u003e\u003ccode\u003e8340d2d\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): clear hook effects before settling prompts\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2475e07186d824d52504095c71c2272d9e7338fe\"\u003e\u003ccode\u003e2475e07\u003c/code\u003e\u003c/a\u003e test(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): cover hook cleanup error semantics\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/15cd8d3b53bfc270633072073c24d6be6ce3d83b\"\u003e\u003ccode\u003e15cd8d3\u003c/code\u003e\u003c/a\u003e fix(confirm): ignore surrounding whitespace in answers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/9cb0da6c187346c955ab0b788fa1a88c897f16da\"\u003e\u003ccode\u003e9cb0da6\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/1c750bc55ab4fac310d70db84a7a6ada76c0e854\"\u003e\u003ccode\u003e1c750bc\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the build group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2251\"\u003e#2251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/81f1525110990603e9796d48eecde0f8c2d2fc98\"\u003e\u003ccode\u003e81f1525\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump \u003ccode\u003e@​types/node\u003c/code\u003e in the types group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2252\"\u003e#2252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7c27f26606a16b6e8f55b51e4431c72658c674c5\"\u003e\u003ccode\u003e7c27f26\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2249\"\u003e#2249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/6119088a4e07ec59460c3cd44d06817de97bfdac\"\u003e\u003ccode\u003e6119088\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2250\"\u003e#2250\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0d167c0aface3f5cf95132ada9bfec7946dd5b74\"\u003e\u003ccode\u003e0d167c0\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 4 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2248\"\u003e#2248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/search@4.2.1...@inquirer/search@4.3.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/search\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/select` from 5.2.1 to 5.2.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/select's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/select\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.2.3\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.1\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/type\u003c/code\u003e bumped to \u003ccode\u003e^4.1.0\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/select\u003c/code\u003e\u003ca href=\"https://github.com/5\"\u003e\u003ccode\u003e@​5\u003c/code\u003e\u003c/a\u003e.2.2\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/core\u003c/code\u003e bumped to \u003ccode\u003e^12.0.0\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@inquirer/figures\u003c/code\u003e bumped to \u003ccode\u003e^2.0.8\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNo source changes.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/cbdb34bfc6c245941d80ef88493c50b3d6dbfce6\"\u003e\u003ccode\u003ecbdb34b\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8340d2dd764d4b11d4e200412b614f9964ae0691\"\u003e\u003ccode\u003e8340d2d\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): clear hook effects before settling prompts\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2475e07186d824d52504095c71c2272d9e7338fe\"\u003e\u003ccode\u003e2475e07\u003c/code\u003e\u003c/a\u003e test(\u003ccode\u003e@​inquirer/core\u003c/code\u003e): cover hook cleanup error semantics\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/15cd8d3b53bfc270633072073c24d6be6ce3d83b\"\u003e\u003ccode\u003e15cd8d3\u003c/code\u003e\u003c/a\u003e fix(confirm): ignore surrounding whitespace in answers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/9cb0da6c187346c955ab0b788fa1a88c897f16da\"\u003e\u003ccode\u003e9cb0da6\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/1c750bc55ab4fac310d70db84a7a6ada76c0e854\"\u003e\u003ccode\u003e1c750bc\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the build group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2251\"\u003e#2251\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/81f1525110990603e9796d48eecde0f8c2d2fc98\"\u003e\u003ccode\u003e81f1525\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump \u003ccode\u003e@​types/node\u003c/code\u003e in the types group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2252\"\u003e#2252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7c27f26606a16b6e8f55b51e4431c72658c674c5\"\u003e\u003ccode\u003e7c27f26\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2249\"\u003e#2249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/6119088a4e07ec59460c3cd44d06817de97bfdac\"\u003e\u003ccode\u003e6119088\u003c/code\u003e\u003c/a\u003e chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2250\"\u003e#2250\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0d167c0aface3f5cf95132ada9bfec7946dd5b74\"\u003e\u003ccode\u003e0d167c0\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 4 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2248\"\u003e#2248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/select@5.2.1...@inquirer/select@5.2.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/select\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@inquirer/type` from 4.0.7 to 4.1.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/releases\"\u003e@​inquirer/type's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​inquirer/type\u003c/code\u003e\u003ca href=\"https://github.com/4\"\u003e\u003ccode\u003e@​4\u003c/code\u003e\u003c/a\u003e.1.0\u003c/h2\u003e\n\u003ch3\u003eWhat's new\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ePrettify\u003c/code\u003e is now recursive, so \u003ccode\u003emakeTheme\u003c/code\u003e returns a fully flattened theme type (nested style intersections merged into one object) for better IDE display (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/pull/2239\"\u003e#2239\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/5748bd9966b5e175ddf5995ee4cdce6f60c4272e\"\u003e\u003ccode\u003e5748bd9\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/269ae73ca9dd7ac738cd35f7d0222b3522021ad9\"\u003e\u003ccode\u003e269ae73\u003c/code\u003e\u003c/a\u003e fix: pin \u003ccode\u003e@​inquirer/type\u003c/code\u003e exactly in published manifests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/927d6dda59aacf8c4088d43df68da5062757cd6d\"\u003e\u003ccode\u003e927d6dd\u003c/code\u003e\u003c/a\u003e fix(\u003ccode\u003e@​inquirer/testing\u003c/code\u003e): keep keypress simulation working under TERM=dumb\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/2d813b145b9ce2a531d7ba6eafb8f7451594b004\"\u003e\u003ccode\u003e2d813b1\u003c/code\u003e\u003c/a\u003e chore(deps): Bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.6 to 0.16.8 (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2245\"\u003e#2245\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/7affbc9bef22adcb059325c7e8450e3da64bd6fa\"\u003e\u003ccode\u003e7affbc9\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump turbo from 2.10.9 to 2.10.11 in the build group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2243\"\u003e#2243\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/56db98993c3c5c55864e5b1b7f458b1bb9c59e65\"\u003e\u003ccode\u003e56db989\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump oxfmt in the formatting group (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2242\"\u003e#2242\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/8e6bc3cec6b88bbd08ff49b0f01fc5dabc5f6bb2\"\u003e\u003ccode\u003e8e6bc3c\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the linting group with 2 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2241\"\u003e#2241\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/427b7a1f55d1947dd6876ce026706ae2369db313\"\u003e\u003ccode\u003e427b7a1\u003c/code\u003e\u003c/a\u003e chore(deps-dev): Bump the testing group with 3 updates (\u003ca href=\"https://redirect.github.com/SBoudrias/Inquirer.js/issues/2240\"\u003e#2240\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/51ac389603405e8f9f315ce49416153d95c5fefe\"\u003e\u003ccode\u003e51ac389\u003c/code\u003e\u003c/a\u003e chore: Publish new release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SBoudrias/Inquirer.js/commit/0f1718e9db1a129ad07c61a0d530f00dc4362740\"\u003e\u003ccode\u003e0f1718e\u003c/code\u003e\u003c/a\u003e feat(\u003ccode\u003e@​inquirer/password\u003c/code\u003e): add ctrl+t toggle to reveal password\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/type@4.0.7...@inquirer/type@4.1.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​inquirer/type\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@jridgewell/sourcemap-codec` from 1.5.5 to 1.6.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jridgewell/sourcemaps/blob/main/packages/sourcemap-codec/CHANGELOG.md\"\u003e@​jridgewell/sourcemap-codec's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e[1.6.0] - 2026-08-27\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Range Mapping support: \u003ca href=\"https://github.com/jridgewell/sourcemaps/tree/HEAD/packages/sourcemap-codec/issues/45\"\u003e#45\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003eincludes new \u003ccode\u003edecodeRangeMappings\u003c/code\u003e and \u003ccode\u003eencodeRangeMappings\u003c/code\u003e APIs\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/jridgewell/sourcemaps/compare/sourcemap-codec/1.5.5...sourcemap-codec/1.6.0\"\u003ehttps://github.com/jridgewell/sourcemaps/compare/sourcemap-codec/1.5.5...sourcemap-codec/1.6.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jridgewell/sourcemaps/commit/b7600158f4de012d246b7834a73c7c2190e75136\"\u003e\u003ccode\u003eb760015\u003c/code\u003e\u003c/a\u003e sourcemap-codec/1.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jridgewell/sourcemaps/commit/8aec72939113eff31a4fed37b7f78a19c81ddcd3\"\u003e\u003ccode\u003e8aec729\u003c/code\u003e\u003c/a\u003e Ignore map files during ripgrepping\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jridgewell/sourcemaps/commit/6566f0c3c8c0dcdbd93655e5b82e990d48c77606\"\u003e\u003ccode\u003e6566f0c\u003c/code\u003e\u003c/a\u003e Range mappings: update encoding to latest\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jridgewell/sourcemaps/commit/e5d58e6611a03a84ca64e2dd0de5667d7716b877\"\u003e\u003ccode\u003ee5d58e6\u003c/code\u003e\u003c/a\u003e Improve mocha setup\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jridgewell/sourcemaps/commit/f34bc275de9b6947c1d7e90e0f106d2440675104\"\u003e\u003ccode\u003ef34bc27\u003c/code\u003e\u003c/a\u003e Changelogs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jridgewell/sourcemaps/commit/01a4f69b2582826f9476d7045272a5eab67133e6\"\u003e\u003ccode\u003e01a4f69\u003c/code\u003e\u003c/a\u003e Small clenaup\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jridgewell/sourcemaps/commit/6cbfce2cc8318fdc2f917d7e64833d0d7154deec\"\u003e\u003ccode\u003e6cbfce2\u003c/code\u003e\u003c/a\u003e Add test:watch commands\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jridgewell/sourcemaps/commit/f3cb43e91f830c8f46d2223dff494dcd075ec087\"\u003e\u003ccode\u003ef3cb43e\u003c/code\u003e\u003c/a\u003e Separate signing from encoding/decoding integers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jridgewell/sourcemaps/commit/b319fc0af756b0079e7a6735afd586f0d52c7736\"\u003e\u003ccode\u003eb319fc0\u003c/code\u003e\u003c/a\u003e Range mappings: add initial decoding/encoding support\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jridgewell/sourcemaps/commit/59f4045d1319138c521604f30b9f1e38947eb776\"\u003e\u003ccode\u003e59f4045\u003c/code\u003e\u003c/a\u003e Add unsigned VLQ encode/decode options\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/jridgewell/sourcemaps/commits/sourcemap-codec/1.6.0/packages/sourcemap-codec\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@nap...\n\n_Description has been truncated_","html_url":"https://github.com/alderichoarau/alderichoarau.github.io/pull/259","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/alderichoarau%2Falderichoarau.github.io/issues/259","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/259/packages"}},{"old_version":"8.10.1","new_version":"8.10.2","update_type":"patch","path":null,"pr_created_at":"2026-09-11T08:14:58.000Z","version_change":"8.10.1 → 8.10.2","issue":{"uuid":"5422008605","node_id":"PR_kwDOUSOj0s8AAAABDHQosA","number":9,"state":"open","title":"Bump undici from 8.10.1 to 8.10.2","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T08:14:58.000Z","updated_at":"2026-09-11T08:15:04.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"undici","old_version":"8.10.1","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"}],"path":null,"ecosystem":"npm"},"body":"Bumps [undici](https://github.com/nodejs/undici) from 8.10.1 to 8.10.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nodejs/undici/releases\"\u003eundici's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.10.2\u003c/h2\u003e\n\u003ch2\u003e⚠️ Security fixes\u003c/h2\u003e\n\u003ch3\u003eHigh severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm\"\u003eGHSA-vp8m-p9jh-q5pm\u003c/a\u003e: cache and deduplication interceptors could use caller-controlled request metadata instead of the authoritative dispatcher origin, enabling cross-origin cache poisoning and data disclosure. Undici now derives interceptor identities from the dispatcher origin and bypasses origin-dependent interceptors when no authoritative origin exists. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/caf6194d3dae989b731ed87ab85f182befe5eb80\"\u003ecaf6194d\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3\"\u003eGHSA-w293-vg96-wgc3\u003c/a\u003e: \u003ccode\u003eBalancedPool\u003c/code\u003e could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves \u003ccode\u003econnect\u003c/code\u003e and legacy \u003ccode\u003etls\u003c/code\u003e options when creating upstreams. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e8f5868fb\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5\"\u003eGHSA-rfgv-xxqx-mfg5\u003c/a\u003e: a WebSocket server could select a subprotocol when none was requested, causing an uncaught \u003ccode\u003eTypeError\u003c/code\u003e that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e66e12816\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMedium severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v\"\u003eGHSA-3wwx-pv8p-q78v\u003c/a\u003e: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6\"\u003e4411a238\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq\"\u003eGHSA-rx4f-c7p8-82vq\u003c/a\u003e: an unclean \u003ccode\u003eWebSocketStream\u003c/code\u003e close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/662d0ea671fe64139e79533c913fce412765e1d7\"\u003e662d0ea6\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j\"\u003eGHSA-2jfj-6hjv-fm6j\u003c/a\u003e: shared caches could store and replay responses containing \u003ccode\u003eSet-Cookie\u003c/code\u003e, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003ecb75bbb3\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm\"\u003eGHSA-3xpg-4rpp-hhhm\u003c/a\u003e: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable \u003ccode\u003emaxSize\u003c/code\u003e. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e7aac7f12\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x\"\u003eGHSA-pmjh-fq2x-6v4x\u003c/a\u003e: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003ee905b5b8\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLow severity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv\"\u003eGHSA-8436-99hf-9mmv\u003c/a\u003e: cache interceptors could store and replay responses to unsafe HTTP methods such as \u003ccode\u003ePOST\u003c/code\u003e or \u003ccode\u003eDELETE\u003c/code\u003e. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e2be07bf9\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968\"\u003eGHSA-2gqq-gqf2-x968\u003c/a\u003e: the dump interceptor could treat an oversized chunked response as successfully truncated when no \u003ccode\u003eContent-Length\u003c/code\u003e was present. Undici now enforces \u003ccode\u003emaxSize\u003c/code\u003e against received bytes and aborts oversized responses. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e6d583124\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r\"\u003eGHSA-r53p-7pc4-xj5r\u003c/a\u003e: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates \u003ccode\u003eContent-Range\u003c/code\u003e against the original response framing before resuming. Fixed by \u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e0160a719\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps-dev): bump undici from 6.27.0 to 6.28.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5653\"\u003enodejs/undici#5653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump jest from 30.4.2 to 30.5.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5750\"\u003enodejs/undici#5750\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/analyze from 4.37.3 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5752\"\u003enodejs/undici#5752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.9 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5754\"\u003enodejs/undici#5754\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(h2): cover stream reset with NGHTTP2_INTERNAL_ERROR by \u003ca href=\"https://github.com/zeexzeex\"\u003e\u003ccode\u003e@​zeexzeex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5725\"\u003enodejs/undici#5725\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): reject invalid resumed responses by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5724\"\u003enodejs/undici#5724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: make stale-while-revalidate cache update test deterministic by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5722\"\u003enodejs/undici#5722\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid unbounded recursion in Set-Cookie attribute parser by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5757\"\u003enodejs/undici#5757\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: honor SOCKS5 connection timeout by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5733\"\u003enodejs/undici#5733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(eventsource): validate Last-Event-ID on reconnect by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5746\"\u003enodejs/undici#5746\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: avoid duplicate release attempts by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5745\"\u003enodejs/undici#5745\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(cache): refetch when 304 adds vary fields by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5732\"\u003enodejs/undici#5732\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etypes: expose PendingInterceptor and PendingInterceptorsFormatter on the MockAgent namespace by \u003ca href=\"https://github.com/RaphaelFakhri\"\u003e\u003ccode\u003e@​RaphaelFakhri\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5721\"\u003enodejs/undici#5721\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci(codeql): align CodeQL action versions to v4.37.9 by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5759\"\u003enodejs/undici#5759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump \u003ccode\u003e@​humanfs/node\u003c/code\u003e from 0.16.7 to 0.16.8 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5760\"\u003enodejs/undici#5760\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(proxy-agent): guard Proxy-Authorization in iterable header containers by \u003ca href=\"https://github.com/mcollina\"\u003e\u003ccode\u003e@​mcollina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5758\"\u003enodejs/undici#5758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: name the parameters these two blocks describe by \u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(websocket): fail the connection on a non-200 h2 extended CONNECT response by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(node-fetch): re-enable the set-cookie header combining test by \u003ca href=\"https://github.com/pacocartones\"\u003e\u003ccode\u003e@​pacocartones\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5730\"\u003enodejs/undici#5730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(retry): forward rawHeaders writes through RetryController by \u003ca href=\"https://github.com/official-burak\"\u003e\u003ccode\u003e@​official-burak\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5727\"\u003enodejs/undici#5727\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs by \u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5738\"\u003enodejs/undici#5738\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/darkdi\"\u003e\u003ccode\u003e@​darkdi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5735\"\u003enodejs/undici#5735\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjsik11\"\u003e\u003ccode\u003e@​kjsik11\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nodejs/undici/pull/5751\"\u003enodejs/undici#5751\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/5e541e0b9df7563e5766bbd469fbfe383d9ae6ca\"\u003e\u003ccode\u003e5e541e0\u003c/code\u003e\u003c/a\u003e Bumped v8.10.2 (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5771\"\u003e#5771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/eb04cc39954e63e9b46bdf824e6efad9fff2e7b5\"\u003e\u003ccode\u003eeb04cc3\u003c/code\u003e\u003c/a\u003e fix(fetch): only send Sec-Fetch-Mode to potentially trustworthy URLs (\u003ca href=\"https://redirect.github.com/nodejs/undici/issues/5738\"\u003e#5738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/e905b5b87e6953bcc542af90557b2fee5b7b5974\"\u003e\u003ccode\u003ee905b5b\u003c/code\u003e\u003c/a\u003e fix(retry): settle exposed body on terminal failure\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/0160a719063fb0a77f4fdf9500b9166b91e14329\"\u003e\u003ccode\u003e0160a71\u003c/code\u003e\u003c/a\u003e fix(retry): validate resumed response framing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad\"\u003e\u003ccode\u003e66e1281\u003c/code\u003e\u003c/a\u003e fix(websocket): reject unrequested subprotocols\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/7aac7f12f757844763c8b8f1ab6e305e80d55838\"\u003e\u003ccode\u003e7aac7f1\u003c/code\u003e\u003c/a\u003e fix(decompress): limit decompressed response size\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/cb75bbb34224a968b4ad80cab8b7aba5e0b3b28a\"\u003e\u003ccode\u003ecb75bbb\u003c/code\u003e\u003c/a\u003e fix(cache): do not cache Set-Cookie in shared caches\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584\"\u003e\u003ccode\u003e6d58312\u003c/code\u003e\u003c/a\u003e fix(interceptor/dump): abort oversized chunked responses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390\"\u003e\u003ccode\u003e8f5868f\u003c/code\u003e\u003c/a\u003e fix: preserve BalancedPool connection options\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3\"\u003e\u003ccode\u003e2be07bf\u003c/code\u003e\u003c/a\u003e fix(cache): reject unsafe method response caching\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nodejs/undici/compare/v8.10.1...v8.10.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici\u0026package-manager=npm_and_yarn\u0026previous-version=8.10.1\u0026new-version=8.10.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/xcawh/rsshub/pull/9","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/xcawh%2Frsshub/issues/9","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/9/packages"}},{"old_version":"8.6.0","new_version":"8.10.2","update_type":"minor","path":null,"pr_created_at":"2026-09-11T07:40:51.000Z","version_change":"8.6.0 → 8.10.2","issue":{"uuid":"5421718027","node_id":"PR_kwDOJUlaKM8AAAABDHB9pw","number":473,"state":"open","title":"chore(deps): bump the production-minor-patch group across 1 directory with 20 updates","user":"dependabot[bot]","labels":["dependencies","javascript","ai-fix-requested"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-11T07:40:51.000Z","updated_at":"2026-09-11T07:43:15.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"production-minor-patch","update_count":20,"packages":[{"name":"@fortedigital/nextjs-cache-handler","old_version":"3.2.0","new_version":"3.3.0","repository_url":"https://github.com/fortedigital/nextjs-cache-handler"},{"name":"@headlessui/react","old_version":"2.2.9","new_version":"2.2.10","repository_url":"https://github.com/tailwindlabs/headlessui"},{"name":"@sentry/nextjs","old_version":"10.32.0","new_version":"10.73.0","repository_url":"https://github.com/getsentry/sentry-javascript"},{"name":"@tailwindcss/forms","old_version":"0.5.10","new_version":"0.5.11","repository_url":"https://github.com/tailwindlabs/tailwindcss-forms"},{"name":"@tailwindcss/typography","old_version":"0.5.16","new_version":"0.5.20","repository_url":"https://github.com/tailwindlabs/tailwindcss-typography"},{"name":"autoprefixer","old_version":"10.4.21","new_version":"10.5.5","repository_url":"https://github.com/postcss/autoprefixer"},{"name":"date-fns","old_version":"4.1.0","new_version":"4.4.0","repository_url":"https://github.com/date-fns/date-fns"},{"name":"fast-xml-parser","old_version":"5.8.0","new_version":"5.11.1","repository_url":"https://github.com/NaturalIntelligence/fast-xml-parser"},{"name":"next","old_version":"16.2.6","new_version":"16.3.4","repository_url":"https://github.com/vercel/next.js"},{"name":"next-intl","old_version":"4.12.0","new_version":"4.14.2","repository_url":"https://github.com/amannn/next-intl"},{"name":"postcss","old_version":"8.5.16","new_version":"8.5.28","repository_url":"https://github.com/postcss/postcss"},{"name":"react","old_version":"19.2.4","new_version":"19.2.8","repository_url":"https://github.com/react/react"},{"name":"react-dom","old_version":"19.2.4","new_version":"19.2.8","repository_url":"https://github.com/react/react"},{"name":"react-select","old_version":"5.10.1","new_version":"5.10.2","repository_url":"https://github.com/JedWatson/react-select"},{"name":"react-share","old_version":"5.2.2","new_version":"5.3.0","repository_url":"https://github.com/nygardk/react-share"},{"name":"redis","old_version":"6.0.0","new_version":"6.2.1","repository_url":"https://github.com/redis/node-redis"},{"name":"sharp","old_version":"0.34.5","new_version":"0.35.4","repository_url":"https://github.com/lovell/sharp"},{"name":"swr","old_version":"2.3.4","new_version":"2.5.1","repository_url":"https://github.com/vercel/swr"},{"name":"undici","old_version":"8.6.0","new_version":"8.10.2","repository_url":"https://github.com/nodejs/undici"},{"name":"zod","old_version":"3.24.3","new_version":"3.25.76","repository_url":"https://github.com/colinhacks/zod"}],"path":null,"ecosystem":"npm"},"body":"Bumps the production-minor-patch group with 20 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [@fortedigital/nextjs-cache-handler](https://github.com/fortedigital/nextjs-cache-handler) | `3.2.0` | `3.3.0` |\n| [@headlessui/react](https://github.com/tailwindlabs/headlessui/tree/HEAD/packages/@headlessui-react) | `2.2.9` | `2.2.10` |\n| [@sentry/nextjs](https://github.com/getsentry/sentry-javascript) | `10.32.0` | `10.73.0` |\n| [@tailwindcss/forms](https://github.com/tailwindlabs/tailwindcss-forms) | `0.5.10` | `0.5.11` |\n| [@tailwindcss/typography](https://github.com/tailwindlabs/tailwindcss-typography) | `0.5.16` | `0.5.20` |\n| [autoprefixer](https://github.com/postcss/autoprefixer) | `10.4.21` | `10.5.5` |\n| [date-fns](https://github.com/date-fns/date-fns) | `4.1.0` | `4.4.0` |\n| [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) | `5.8.0` | `5.11.1` |\n| [next](https://github.com/vercel/next.js) | `16.2.6` | `16.3.4` |\n| [next-intl](https://github.com/amannn/next-intl) | `4.12.0` | `4.14.2` |\n| [postcss](https://github.com/postcss/postcss) | `8.5.16` | `8.5.28` |\n| [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.4` | `19.2.8` |\n| [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) | `19.2.4` | `19.2.8` |\n| [react-select](https://github.com/JedWatson/react-select) | `5.10.1` | `5.10.2` |\n| [react-share](https://github.com/nygardk/react-share) | `5.2.2` | `5.3.0` |\n| [redis](https://github.com/redis/node-redis) | `6.0.0` | `6.2.1` |\n| [sharp](https://github.com/lovell/sharp) | `0.34.5` | `0.35.4` |\n| [swr](https://github.com/vercel/swr) | `2.3.4` | `2.5.1` |\n| [undici](https://github.com/nodejs/undici) | `8.6.0` | `8.10.2` |\n| [zod](https://github.com/colinhacks/zod) | `3.24.3` | `3.25.76` |\n\n\nUpdates `@fortedigital/nextjs-cache-handler` from 3.2.0 to 3.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/releases\"\u003e@​fortedigital/nextjs-cache-handler's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(redis-strings): preserve native Redis abort handling by \u003ca href=\"https://github.com/Dwlad90\"\u003e\u003ccode\u003e@​Dwlad90\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/pull/236\"\u003efortedigital/nextjs-cache-handler#236\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the npm_and_yarn group across 1 directory with 2 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/pull/239\"\u003efortedigital/nextjs-cache-handler#239\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(instrumentation): load segmentData from disk in registerInitialCache by \u003ca href=\"https://github.com/gergokee\"\u003e\u003ccode\u003e@​gergokee\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/pull/237\"\u003efortedigital/nextjs-cache-handler#237\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!WARNING]\n\u003cstrong\u003eNext.js 16.3.0 breaking change:\u003c/strong\u003e Starting with Next.js 16.3.0, prefetch requests for the app router's route tree (\u003ccode\u003e/_tree\u003c/code\u003e) require per-segment RSC payloads (\u003ccode\u003esegmentData\u003c/code\u003e) to be present in the cache entry. Versions of this package prior to \u003cstrong\u003e3.3.0\u003c/strong\u003e did not populate \u003ccode\u003esegmentData\u003c/code\u003e when restoring the initial cache from disk (via \u003ccode\u003eregisterInitialCache\u003c/code\u003e), which caused the Next.js 16.3.0+ client to receive an unparseable response for \u003ccode\u003e/_tree\u003c/code\u003e prefetch requests and retry indefinitely.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/compare/3.2.2...3.3.0\"\u003ehttps://github.com/fortedigital/nextjs-cache-handler/compare/3.2.2...3.3.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.2.2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: use route cache revalidation by \u003ca href=\"https://github.com/tomatotomata\"\u003e\u003ccode\u003e@​tomatotomata\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/pull/232\"\u003efortedigital/nextjs-cache-handler#232\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tomatotomata\"\u003e\u003ccode\u003e@​tomatotomata\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/pull/232\"\u003efortedigital/nextjs-cache-handler#232\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/compare/3.2.1...3.2.2\"\u003ehttps://github.com/fortedigital/nextjs-cache-handler/compare/3.2.1...3.2.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.2.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix(cache-handler): persist implicit path tags for PAGES entries  by \u003ca href=\"https://github.com/KajSzy\"\u003e\u003ccode\u003e@​KajSzy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/pull/227\"\u003efortedigital/nextjs-cache-handler#227\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: packages upgraded\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/compare/3.2.0...3.2.1\"\u003ehttps://github.com/fortedigital/nextjs-cache-handler/compare/3.2.0...3.2.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/commit/702913d1cdc4f9966706df89513017c39ff4182a\"\u003e\u003ccode\u003e702913d\u003c/code\u003e\u003c/a\u003e 3.3.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/commit/48c1faf04af989651dde36b6dfc9776a73c98410\"\u003e\u003ccode\u003e48c1faf\u003c/code\u003e\u003c/a\u003e Added concurrency limit\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/commit/78b8cbd34551b471657646afc8246b5214a271d5\"\u003e\u003ccode\u003e78b8cbd\u003c/code\u003e\u003c/a\u003e Package bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/commit/8861a1256be64c962f12b680523bafd07bcc0cb5\"\u003e\u003ccode\u003e8861a12\u003c/code\u003e\u003c/a\u003e fix(instrumentation): load segmentData from disk in registerInitialCache (\u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/issues/237\"\u003e#237\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/commit/4ba9330b1b3bffa98419c7acba1004ba569d4c30\"\u003e\u003ccode\u003e4ba9330\u003c/code\u003e\u003c/a\u003e Bump the npm_and_yarn group across 1 directory with 2 updates (\u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/issues/239\"\u003e#239\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/commit/199179aed632a6e0993809727f9c5190cdc2aa03\"\u003e\u003ccode\u003e199179a\u003c/code\u003e\u003c/a\u003e fix(redis-strings): preserve native Redis abort handling (\u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/issues/236\"\u003e#236\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/commit/e742eaa227526ebeaefdff4f8fc4c0af017096fc\"\u003e\u003ccode\u003ee742eaa\u003c/code\u003e\u003c/a\u003e 3.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/commit/a015559345648010cb138826f868eed99d59ae7a\"\u003e\u003ccode\u003ea015559\u003c/code\u003e\u003c/a\u003e fix: use route cache revalidation (\u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/issues/232\"\u003e#232\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/commit/e6dbc68447a8d15a24c30c1ed646a200e29ac9f3\"\u003e\u003ccode\u003ee6dbc68\u003c/code\u003e\u003c/a\u003e Version bumped to 3.2.1 and packages upgraded\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/commit/74149e3db10dda71a8c29c0b99bb105069701423\"\u003e\u003ccode\u003e74149e3\u003c/code\u003e\u003c/a\u003e fix(cache-handler): persist implicit path tags for PAGES entries  (\u003ca href=\"https://redirect.github.com/fortedigital/nextjs-cache-handler/issues/227\"\u003e#227\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/fortedigital/nextjs-cache-handler/compare/3.2.0...3.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@headlessui/react` from 2.2.9 to 2.2.10\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/headlessui/releases\"\u003e@​headlessui/react's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003e@​headlessui/react\u003c/code\u003e\u003ca href=\"https://github.com/v2\"\u003e\u003ccode\u003e@​v2\u003c/code\u003e\u003c/a\u003e.2.10\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDon’t render \u003ccode\u003e\u0026lt;Portal\u0026gt;\u003c/code\u003e while hydrating (\u003ca href=\"https://redirect.github.com/tailwindlabs/headlessui/pull/3825\"\u003e#3825\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix passing props on \u003ccode\u003eFragment\u003c/code\u003e error due to \u003ccode\u003eSymbol(react.lazy)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/headlessui/pull/3873\"\u003e#3873\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/headlessui/blob/main/packages/@headlessui-react/CHANGELOG.md\"\u003e@​headlessui/react's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[2.2.10] - 2026-04-07\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDon’t render \u003ccode\u003e\u0026lt;Portal\u0026gt;\u003c/code\u003e while hydrating (\u003ca href=\"https://redirect.github.com/tailwindlabs/headlessui/pull/3825\"\u003e#3825\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix passing props on \u003ccode\u003eFragment\u003c/code\u003e error due to \u003ccode\u003eSymbol(react.lazy)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tailwindlabs/headlessui/pull/3873\"\u003e#3873\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/headlessui/commit/d13526d02a2de92c4ad7b62c15cd980636543fe2\"\u003e\u003ccode\u003ed13526d\u003c/code\u003e\u003c/a\u003e 2.2.10 - \u003ccode\u003e@​headlessui/react\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/headlessui/commit/b0dcd8fc6ce78bc80221e602c0b1aa94e304ef81\"\u003e\u003ccode\u003eb0dcd8f\u003c/code\u003e\u003c/a\u003e Handle props on Fragment error due to \u003ccode\u003eSymbol(react.lazy)\u003c/code\u003e (\u003ca href=\"https://github.com/tailwindlabs/headlessui/tree/HEAD/packages/@headlessui-react/issues/3873\"\u003e#3873\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/headlessui/commit/7baca70434e11432b4210e87558cd452801bb2f9\"\u003e\u003ccode\u003e7baca70\u003c/code\u003e\u003c/a\u003e Don’t render \u003ccode\u003e\\\u0026lt;Portal\u0026gt;\u003c/code\u003es while hydrating (\u003ca href=\"https://github.com/tailwindlabs/headlessui/tree/HEAD/packages/@headlessui-react/issues/3825\"\u003e#3825\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/headlessui/commit/5ef7395d86dc322ea056c4839bfd0910299b3808\"\u003e\u003ccode\u003e5ef7395\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003eRefProp\u003c/code\u003e to \u003ccode\u003eprops\u003c/code\u003e (\u003ca href=\"https://github.com/tailwindlabs/headlessui/tree/HEAD/packages/@headlessui-react/issues/3823\"\u003e#3823\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/tailwindlabs/headlessui/commits/@headlessui/react@v2.2.10/packages/@headlessui-react\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@sentry/nextjs` from 10.32.0 to 10.73.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/getsentry/sentry-javascript/releases\"\u003e@​sentry/nextjs's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e10.73.0\u003c/h2\u003e\n\u003ch3\u003eImportant Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003efeat(v10/nextjs): Add \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e entry point (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23766\"\u003e#23766\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003ewithSentryConfig\u003c/code\u003e is now available from \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e, the path it moves to in v11. Importing it from \u003ccode\u003e@sentry/nextjs\u003c/code\u003e still works on v10 but logs a warning once, so you can change your \u003ccode\u003enext.config\u003c/code\u003e file today and upgrade to v11 without touching it again.\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// next.config.mjs\n- import { withSentryConfig } from '@sentry/nextjs';\n+ import { withSentryConfig } from '@sentry/nextjs/config';\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(v10/node): Deprecate \u003ccode\u003eshouldHandleError\u003c/code\u003e on \u003ccode\u003esetupExpressErrorHandler\u003c/code\u003e and \u003ccode\u003esetupFasitfyErrorHandler\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23734\"\u003e#23734\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/cloudflare): Instrument Durable Object handlers installed as read-only properties (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23769\"\u003e#23769\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003etest(v10/nextjs): Drop nextjs-16-cf-workers canary variant (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23775\"\u003e#23775\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eBundle size 📦\u003c/h2\u003e\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003ePath\u003c/th\u003e\n\u003cth\u003eSize\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e27.1 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e - with treeshaking flags\u003c/td\u003e\n\u003ctd\u003e25.58 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing)\u003c/td\u003e\n\u003ctd\u003e45.54 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing + Span Streaming)\u003c/td\u003e\n\u003ctd\u003e47.28 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Profiling)\u003c/td\u003e\n\u003ctd\u003e50.17 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay)\u003c/td\u003e\n\u003ctd\u003e83.87 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay) - with treeshaking flags\u003c/td\u003e\n\u003ctd\u003e73.74 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay with Canvas)\u003c/td\u003e\n\u003ctd\u003e88.49 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Tracing, Replay, Feedback)\u003c/td\u003e\n\u003ctd\u003e100.83 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Feedback)\u003c/td\u003e\n\u003ctd\u003e43.87 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. sendFeedback)\u003c/td\u003e\n\u003ctd\u003e31.78 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. FeedbackAsync)\u003c/td\u003e\n\u003ctd\u003e36.79 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Metrics)\u003c/td\u003e\n\u003ctd\u003e28.16 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Logs)\u003c/td\u003e\n\u003ctd\u003e28.38 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/browser\u003c/code\u003e (incl. Metrics \u0026amp; Logs)\u003c/td\u003e\n\u003ctd\u003e29.06 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/react\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e28.86 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/react\u003c/code\u003e (incl. Tracing)\u003c/td\u003e\n\u003ctd\u003e47.74 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/vue\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e32.4 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/vue\u003c/code\u003e (incl. Tracing)\u003c/td\u003e\n\u003ctd\u003e47.46 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ccode\u003e@​sentry/svelte\u003c/code\u003e\u003c/td\u003e\n\u003ctd\u003e27.12 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eCDN Bundle\u003c/td\u003e\n\u003ctd\u003e29.43 KB\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/getsentry/sentry-javascript/blob/10.73.0/CHANGELOG.md\"\u003e@​sentry/nextjs's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e10.73.0\u003c/h2\u003e\n\u003ch3\u003eImportant Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003efeat(v10/nextjs): Add \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e entry point (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23766\"\u003e#23766\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003ewithSentryConfig\u003c/code\u003e is now available from \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e, the path it moves to in v11. Importing it from \u003ccode\u003e@sentry/nextjs\u003c/code\u003e still works on v10 but logs a warning once, so you can change your \u003ccode\u003enext.config\u003c/code\u003e file today and upgrade to v11 without touching it again.\u003c/p\u003e\n\u003cpre lang=\"js\"\u003e\u003ccode\u003e// next.config.mjs\n- import { withSentryConfig } from '@sentry/nextjs';\n+ import { withSentryConfig } from '@sentry/nextjs/config';\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efeat(v10/node): Deprecate \u003ccode\u003eshouldHandleError\u003c/code\u003e on \u003ccode\u003esetupExpressErrorHandler\u003c/code\u003e and \u003ccode\u003esetupFasitfyErrorHandler\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23734\"\u003e#23734\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/cloudflare): Instrument Durable Object handlers installed as read-only properties (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23769\"\u003e#23769\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003etest(v10/nextjs): Drop nextjs-16-cf-workers canary variant (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23775\"\u003e#23775\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e10.72.0\u003c/h2\u003e\n\u003ch3\u003eImportant Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eAI integrations no longer report errors that propagate to the caller (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23638\"\u003e#23638\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23639\"\u003e#23639\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23640\"\u003e#23640\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eAcross all AI integrations (OpenAI, Anthropic, Google GenAI, LangChain, and LangGraph), the SDK no longer sends an event to Sentry for errors that the AI framework propagates to your code. Previously the instrumentation reported these as unhandled (\u003ccode\u003ehandled: false\u003c/code\u003e) before your own error handling ran, so an error your code caught still showed up in Sentry as an unhandled crash. The span is still marked as errored and the error still propagates, so reporting is left to your application: if your code does not handle the error, it reaches Sentry's global error handlers and is captured as unhandled, just like any other uncaught error. Errors that a provider surfaces as data on an otherwise successful response (such as Anthropic error-shaped responses or Google GenAI blocked content) are still captured, since your code never sees them propagate.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003efeat(v10/cloudflare): Add \u003ccode\u003erpcTracePropagationBindings\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23737\"\u003e#23737\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23738\"\u003e#23738\u003c/a\u003e)\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe new \u003ccode\u003erpcTracePropagationBindings\u003c/code\u003e option names the \u003ccode\u003eenv\u003c/code\u003e bindings that outgoing RPC calls propagate trace context to. Strings match a binding name exactly, regular expressions match by pattern, and the default empty array propagates to nothing. RPC has no headers to carry trace context, so the SDK appends it as a trailing argument that only a Sentry-instrumented receiver removes again. List only the bindings whose receiver you know runs Sentry. Setting the option takes precedence over \u003ccode\u003eenableRpcTracePropagation\u003c/code\u003e, which is now deprecated. When you build with the Sentry Cloudflare Vite plugin, the bindings that resolve to this worker (its own Durable Objects and self service bindings) are derived from your wrangler config and added for you.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eOther Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003efix(v10/astro): support astro v7 route patterns properly (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23657\"\u003e#23657\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/bundler-plugins): Preserve full file path in component annotation source maps (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23595\"\u003e#23595\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/core): Store child span timeout handle in \u003ccode\u003e_childSpanTimeoutID\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23673\"\u003e#23673\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/node): Only end the process session when it is still ok (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23731\"\u003e#23731\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/react-router): Use react-router's own instrumentation types instead of a mirrored copy (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23589\"\u003e#23589\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/replay): Suppress Worker destroyed error on session expiry (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23654\"\u003e#23654\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/server-utils): Keep orchestrion registration out of tree-shaking (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23591\"\u003e#23591\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/server-utils): Stop shipping orchestrion bundler plugins as production dependencies (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23667\"\u003e#23667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/server-utils): Support openai v7 in auto-instrumentation (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23713\"\u003e#23713\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(v10/sveltekit): Detect native tracing in flattened SvelteKit 3 config (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/pull/23656\"\u003e#23656\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/f109d922f5971e2ade549b6c755524168b101818\"\u003e\u003ccode\u003ef109d92\u003c/code\u003e\u003c/a\u003e release: 10.73.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/1a3e04edc4d1c97a702861a9bddd3ed577a71de4\"\u003e\u003ccode\u003e1a3e04e\u003c/code\u003e\u003c/a\u003e meta(changelog): Update changelog for 10.73.0 (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23778\"\u003e#23778\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/da8d7696b08432cd94e78552d9f4c9322c1dc746\"\u003e\u003ccode\u003eda8d769\u003c/code\u003e\u003c/a\u003e test(v10/nextjs): Drop nextjs-16-cf-workers canary variant (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23775\"\u003e#23775\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/bea4d38bf5422ae917275d0b68ad575a2b2b475b\"\u003e\u003ccode\u003ebea4d38\u003c/code\u003e\u003c/a\u003e feat(v10/node): Deprecate \u003ccode\u003eshouldHandleError\u003c/code\u003e on \u003ccode\u003esetupExpressErrorHandler\u003c/code\u003e a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/605caaf2aa85f78ed9a180b273a335fe798bf30c\"\u003e\u003ccode\u003e605caaf\u003c/code\u003e\u003c/a\u003e feat(v10/nextjs): Add \u003ccode\u003e@sentry/nextjs/config\u003c/code\u003e entry point (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23766\"\u003e#23766\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/da17307e9e1898a48a3d4037aff96d5849f123fb\"\u003e\u003ccode\u003eda17307\u003c/code\u003e\u003c/a\u003e fix(v10/cloudflare): Instrument Durable Object handlers installed as read-onl...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/2c4ca38e52cb0e4c4ee69cbdc218c9cabd52eccf\"\u003e\u003ccode\u003e2c4ca38\u003c/code\u003e\u003c/a\u003e Merge branch 'release/10.72.0' into v10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/0d236289ba889ac8f007882726aaa62d9a83cc15\"\u003e\u003ccode\u003e0d23628\u003c/code\u003e\u003c/a\u003e release: 10.72.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/ac2094d469ace03e883abb5fc98b5dc678ccfe49\"\u003e\u003ccode\u003eac2094d\u003c/code\u003e\u003c/a\u003e meta(changelog): Update changelog for 10.72.0 (\u003ca href=\"https://redirect.github.com/getsentry/sentry-javascript/issues/23743\"\u003e#23743\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/getsentry/sentry-javascript/commit/f3254344c4b63382c12cec95b64e7c54f9e45ff9\"\u003e\u003ccode\u003ef325434\u003c/code\u003e\u003c/a\u003e feat(v10/cloudflare): Derive rpcTracePropagationBindings from the wrangler co...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/getsentry/sentry-javascript/compare/10.32.0...10.73.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@tailwindcss/forms` from 0.5.10 to 0.5.11\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/tailwindcss-forms/releases\"\u003e@​tailwindcss/forms's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.5.11\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eLimit attribute rules to input and select elements (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-forms/pull/159\"\u003e#159\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/tailwindcss-forms/blob/main/CHANGELOG.md\"\u003e@​tailwindcss/forms's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[0.5.11] - 2025-12-17\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eLimit attribute rules to input and select elements (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-forms/pull/159\"\u003e#159\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-forms/commit/e1b609d57954eb0036c4c2e7ae9c9c2ba558146b\"\u003e\u003ccode\u003ee1b609d\u003c/code\u003e\u003c/a\u003e 0.5.11\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-forms/commit/67ff8ea3dc0093d5c9f4c45cc8413e8c5bc082d6\"\u003e\u003ccode\u003e67ff8ea\u003c/code\u003e\u003c/a\u003e Limit attribute rules to input and select elements (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-forms/issues/159\"\u003e#159\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-forms/commit/fc3f7e6bce06a1985d445c53e90c3c7fac0e1d18\"\u003e\u003ccode\u003efc3f7e6\u003c/code\u003e\u003c/a\u003e docs: update installation guide to add tailwind css v4 instructions while kee...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/tailwindlabs/tailwindcss-forms/compare/v0.5.10...v0.5.11\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `@tailwindcss/typography` from 0.5.16 to 0.5.20\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/releases\"\u003e@​tailwindcss/typography's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.5.20\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport installing with stable versions of Tailwind CSS v4 (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/424\"\u003e#424\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.5.19\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed broken color styles (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/405\"\u003e#405\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.5.18\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed undefined variable error (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/403\"\u003e#403\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev0.5.17\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd modifiers for description list elements (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/357\"\u003e#357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eprose-picture\u003c/code\u003e modifier (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/367\"\u003e#367\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eInclude unit in \u003ccode\u003ehr\u003c/code\u003e border-width value (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/379\"\u003e#379\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003e\u0026lt;kbd\u0026gt;\u003c/code\u003e styles work with Tailwind CSS v4 (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/387\"\u003e#387\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove lodash dependencies (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/402\"\u003e#402\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/blob/main/CHANGELOG.md\"\u003e@​tailwindcss/typography's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[0.5.20] - 2026-06-08\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport installing with stable versions of Tailwind CSS v4 (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/424\"\u003e#424\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[0.5.19] - 2025-09-24\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed broken color styles (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/405\"\u003e#405\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[0.5.18] - 2025-09-19\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed undefined variable error (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/403\"\u003e#403\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[0.5.17] - 2025-09-19\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd modifiers for description list elements (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/357\"\u003e#357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eprose-picture\u003c/code\u003e modifier (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/367\"\u003e#367\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eInclude unit in \u003ccode\u003ehr\u003c/code\u003e border-width value (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/379\"\u003e#379\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnsure \u003ccode\u003e\u0026lt;kbd\u0026gt;\u003c/code\u003e styles work with Tailwind CSS v4 (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/387\"\u003e#387\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove lodash dependencies (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/402\"\u003e#402\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/commit/e3714a3fe55551ce9d51eec4721183ed6b1d5cd1\"\u003e\u003ccode\u003ee3714a3\u003c/code\u003e\u003c/a\u003e 0.5.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/commit/f34283d2961e18dd0dc2a849702e0dfd45fc80cb\"\u003e\u003ccode\u003ef34283d\u003c/code\u003e\u003c/a\u003e Update tailwindcss peer dependency version (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/issues/424\"\u003e#424\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/commit/543de4274390e90c4aab5d216729b46a3ba5541b\"\u003e\u003ccode\u003e543de42\u003c/code\u003e\u003c/a\u003e bump Node.js\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/commit/881b0488df9fd05e5361276b66a9ee8e7f39a3a7\"\u003e\u003ccode\u003e881b048\u003c/code\u003e\u003c/a\u003e Setup OIDC (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/issues/423\"\u003e#423\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/commit/74a3da779bb43e4e68f446395224c768704c1fb6\"\u003e\u003ccode\u003e74a3da7\u003c/code\u003e\u003c/a\u003e Fix typo in README.md (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/issues/413\"\u003e#413\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/commit/3963dfede4845f46451db1863fd5321f4cdea03b\"\u003e\u003ccode\u003e3963dfe\u003c/code\u003e\u003c/a\u003e Bump js-yaml from 3.14.1 to 3.14.2 (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/issues/410\"\u003e#410\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/commit/abf85cc6e1b4f9b914b0f66453e5a97a9899a15c\"\u003e\u003ccode\u003eabf85cc\u003c/code\u003e\u003c/a\u003e className instead of classname (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/issues/406\"\u003e#406\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/commit/e002ab89ad8f4202638249c1c300c0cf0b3739c5\"\u003e\u003ccode\u003ee002ab8\u003c/code\u003e\u003c/a\u003e 0.5.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/commit/bbb1c21099e34ff4d1d7f82f7528b85e71ed3c5a\"\u003e\u003ccode\u003ebbb1c21\u003c/code\u003e\u003c/a\u003e Fix bad RGB syntax (\u003ca href=\"https://redirect.github.com/tailwindlabs/tailwindcss-typography/issues/405\"\u003e#405\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/commit/b316f958af5bc12a981526c3091d8319626e274e\"\u003e\u003ccode\u003eb316f95\u003c/code\u003e\u003c/a\u003e 0.5.18\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tailwindlabs/tailwindcss-typography/compare/v0.5.16...v0.5.20\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for \u003ccode\u003e@​tailwindcss/typography\u003c/code\u003e since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `autoprefixer` from 10.4.21 to 10.5.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/autoprefixer/releases\"\u003eautoprefixer's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e10.5.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed resolution media query parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.5.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed prefixed rule duplication (by \u003ca href=\"https://github.com/xianjianlf2\"\u003e\u003ccode\u003e@​xianjianlf2\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.5.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed brackets and gradient parser (\u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003e-webkit-fill-available\u003c/code\u003e before \u003ccode\u003e-moz-available\u003c/code\u003e, so Firefox\nwill use \u003ccode\u003e-webkit-\u003c/code\u003e version which is closer to \u003ccode\u003estretch\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.5.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003egrid-area\u003c/code\u003e span reset for overriding areas (by \u003ca href=\"https://github.com/puneetdixit200\"\u003e\u003ccode\u003e@​puneetdixit200\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.5.0 “Each Endeavouring, All Achieving”\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003emask-position-x\u003c/code\u003e and \u003ccode\u003emask-position-y\u003c/code\u003e support (by \u003ca href=\"https://github.com/toporek\"\u003e\u003ccode\u003e@​toporek\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved development key from \u003ccode\u003epackage.json\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed broken gradients on CSS Custom Properties (by \u003ca href=\"https://github.com/serger777\"\u003e\u003ccode\u003e@​serger777\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMade Autoprefixer a little faster (by \u003ca href=\"https://github.com/Cherry\"\u003e\u003ccode\u003e@​Cherry\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced dependencies (by \u003ca href=\"https://github.com/hyperz111\"\u003e\u003ccode\u003e@​hyperz111\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003estretch\u003c/code\u003e prefixes on new Can I Use database.\u003c/li\u003e\n\u003cli\u003eUpdated \u003ccode\u003efraction.js\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md\"\u003eautoprefixer's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e10.5.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed resolution media query parsing performance (by \u003ca href=\"https://github.com/NotAFlightRisk\"\u003e\u003ccode\u003e@​NotAFlightRisk\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.5.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed prefixed rule duplication (by \u003ca href=\"https://github.com/xianjianlf2\"\u003e\u003ccode\u003e@​xianjianlf2\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.5.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed brackets and gradient parser (\u003ca href=\"https://github.com/alanturing881\"\u003e\u003ccode\u003e@​alanturing881\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.5.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003e-webkit-fill-available\u003c/code\u003e before \u003ccode\u003e-moz-available\u003c/code\u003e, so Firefox\nwill use \u003ccode\u003e-webkit-\u003c/code\u003e version which is closer to \u003ccode\u003estretch\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.5.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003egrid-area\u003c/code\u003e span reset for overriding areas (by \u003ca href=\"https://github.com/puneetdixit200\"\u003e\u003ccode\u003e@​puneetdixit200\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.5.0 “Each Endeavouring, All Achieving”\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003emask-position-x\u003c/code\u003e and \u003ccode\u003emask-position-y\u003c/code\u003e support (by \u003ca href=\"https://github.com/toporek\"\u003e\u003ccode\u003e@​toporek\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.27\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved development key from \u003ccode\u003epackage.json\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced package size.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.25\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed broken gradients on CSS Custom Properties (by \u003ca href=\"https://github.com/serger777\"\u003e\u003ccode\u003e@​serger777\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.24\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMade Autoprefixer a little faster (by \u003ca href=\"https://github.com/Cherry\"\u003e\u003ccode\u003e@​Cherry\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.23\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced dependencies (by \u003ca href=\"https://github.com/hyperz111\"\u003e\u003ccode\u003e@​hyperz111\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e10.4.22\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003estretch\u003c/code\u003e prefixes on new Can I Use database.\u003c/li\u003e\n\u003cli\u003eUpdated \u003ccode\u003efraction.js\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/autoprefixer/commit/7e81ffff9d824968394bab6f81da2e2c2511cc49\"\u003e\u003ccode\u003e7e81fff\u003c/code\u003e\u003c/a\u003e Release 10.5.5 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/autoprefixer/commit/d9e3531b4109d9e68bae23ed451c48197e67cb29\"\u003e\u003ccode\u003ed9e3531\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/autoprefixer/commit/34b3a3e275ae223642aaec7686eece008bb88803\"\u003e\u003ccode\u003e34b3a3e\u003c/code\u003e\u003c/a\u003e Fix media query parse performance\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/autoprefixer/commit/265521ee8ee3098dcb114e8259259ca614146e00\"\u003e\u003ccode\u003e265521e\u003c/code\u003e\u003c/a\u003e Remove Cult\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/autoprefixer/commit/dd80d38938055a66d2ab1694234f5ad472fb1bb5\"\u003e\u003ccode\u003edd80d38\u003c/code\u003e\u003c/a\u003e Update EM banner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/autoprefixer/commit/4cad00f0e839f3d7bbcdcc00b7df6fc448fb28f3\"\u003e\u003ccode\u003e4cad00f\u003c/code\u003e\u003c/a\u003e Release 10.5.4 version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/autoprefixer/commit/e62a4b1782f4ece51070feba79b0ff19f4305c68\"\u003e\u003ccode\u003ee62a4b1\u003c/code\u003e\u003c/a\u003e Update CI config\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/autoprefixer/commit/c8f0d0ae00f5bb28bbcc3413f70b088020007469\"\u003e\u003ccode\u003ec8f0d0a\u003c/code\u003e\u003c/a\u003e Update dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/autoprefixer/commit/cae35771dc4a4dfeda637a31dc1795ace6d9d28b\"\u003e\u003ccode\u003ecae3577\u003c/code\u003e\u003c/a\u003e Move back to latest pnpm 11\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/postcss/autoprefixer/commit/fd31eb33b56ab9663d298b5bf08ae4ff47f76878\"\u003e\u003ccode\u003efd31eb3\u003c/code\u003e\u003c/a\u003e Fix duplicated prefixed selectors on reformatted CSS (\u003ca href=\"https://redirect.github.com/postcss/autoprefixer/issues/1552\"\u003e#1552\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/postcss/autoprefixer/compare/10.4.21...10.5.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for autoprefixer since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `date-fns` from 4.1.0 to 4.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/date-fns/date-fns/releases\"\u003edate-fns's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cp\u003eThis release revisits the approach to CDN usage and introduces a new package, \u003ccode\u003e@date-fns/cdn\u003c/code\u003e and deprecates the \u003ccode\u003edate-fns\u003c/code\u003e CDN scripts. It allowed reducing the zipped package size from \u003ccode\u003e5.83 MB\u003c/code\u003e down to \u003ccode\u003e3.96 MB\u003c/code\u003e without introducing any breaking changes.\u003c/p\u003e\n\u003cp\u003eIn \u003ccode\u003ev5.0.0-alpha.0\u003c/code\u003e where CDN scripts are completely removed from \u003ccode\u003edate-fns\u003c/code\u003e the change is more significant and brings the zipped package size down to \u003ccode\u003e2.89 MB\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eIt is just the first step in optimizing the package size. Expect further size reduction in the future v4 and v5 versions.\u003c/p\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eDEPRECATED\u003c/strong\u003e: The \u003ccode\u003edate-fns\u003c/code\u003e CDN scripts are now deprecated and will be removed in the next major release. Please switch to the new \u003ccode\u003e@date-fns/cdn\u003c/code\u003e package for CDN usage.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRemoved CDN source maps to reduce the package size. If you rely on them, please switch to the new \u003ccode\u003e@date-fns/cdn\u003c/code\u003e package that still includes them.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cp\u003eKudos to \u003ca href=\"https://github.com/ImRodry\"\u003e\u003ccode\u003e@​ImRodry\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/puneetdixit200\"\u003e\u003ccode\u003e@​puneetdixit200\u003c/code\u003e\u003c/a\u003e for their contributions.\u003c/p\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFixed missing modularized optimization fallback (\u003ca href=\"https://x.com/kossnocorp/status/1731181274579325260\"\u003efor Next.js and others\u003c/a\u003e). See \u003ca href=\"https://x.com/kossnocorp/status/1731181274579325260\"\u003e#4193\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003ept\u003c/code\u003e locale first day of week to be Sunday. See \u003ca href=\"https://redirect.github.com/date-fns/date-fns/pull/4195\"\u003e#4195\u003c/a\u003e by \u003ca href=\"https://github.com/ImRodry\"\u003e\u003ccode\u003e@​ImRodry\u003c/code\u003e\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003ezh-CN\u003c/code\u003e, \u003ccode\u003ezh-HK\u003c/code\u003e, and \u003ccode\u003ezh-TW\u003c/code\u003e locale month parsing for October, November, and December. See \u003ca href=\"https://redirect.github.com/date-fns/date-fns/pull/4194\"\u003e#4194\u003c/a\u003e by \u003ca href=\"https://github.com/puneetdixit200\"\u003e\u003ccode\u003e@​puneetdixit200\u003c/code\u003e\u003c/a\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.2.1\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed type definitions missing in v4.2.0 due to TypeScript misconfiguration.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.2.0\u003c/h2\u003e\n\u003cp\u003eThis is a minor release in all senses, it only includes documentation updates (first of many) that points to the new \u003ca href=\"https://date-fns.org/you-dont-need-date-fns\"\u003eYou Don't Need date-fns*\u003c/a\u003e page.\u003c/p\u003e\n\u003cp\u003e* Not really\u003c/p\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded Temporal API references to the JSDoc annotations of \u003ccode\u003eadd\u003c/code\u003e, \u003ccode\u003eaddBusinessDays\u003c/code\u003e, and \u003ccode\u003eaddDays\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/date-fns/date-fns/commit/cd53d2538cfa318404eff7ade6449b49bf34562e\"\u003e\u003ccode\u003ecd53d25\u003c/code\u003e\u003c/a\u003e Promote to v4.4.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/date-fns/date-fns/commit/d948ec151d395096de8a45fbcd9b1e79c26fda25\"\u003e\u003ccode\u003ed948ec1\u003c/code\u003e\u003c/a\u003e Preserve but deprecate CDN versions for v4, set up v5 with polyfills\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/date-fns/date-fns/commit/ee65753cfc5d73cc9acd43aaa8012b3b233ddf32\"\u003e\u003ccode\u003eee65753\u003c/code\u003e\u003c/a\u003e Add root \u003ccode\u003emise :format\u003c/code\u003e task\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/date-fns/date-fns/commit/9f5bdf5d5a944772aa9668c4fa6567d89ca01fa9\"\u003e\u003ccode\u003e9f5bdf5\u003c/code\u003e\u003c/a\u003e Add positional argument to \u003ccode\u003etest/smoke.sh\u003c/code\u003e script\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/date-fns/date-fns/commit/651ead6faf331515814803faf457f5b9db7c9729\"\u003e\u003ccode\u003e651ead6\u003c/code\u003e\u003c/a\u003e Split CDN bundles into separate \u003ccode\u003e@​date-fns/cdn\u003c/code\u003e package\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/date-fns/date-fns/commit/224c1a209967dad359a2c2adc9a5b0ef72e4fe7b\"\u003e\u003ccode\u003e224c1a2\u003c/code\u003e\u003c/a\u003e Deprecate type tests as attw hangs on date-fns package\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/date-fns/date-fns/commit/7bb2842dac3d579f84b2de62f015335fb3ac734a\"\u003e\u003ccode\u003e7bb2842\u003c/code\u003e\u003c/a\u003e Switch \u003ccode\u003ePACKAGE_OUTPUT_PATH\u003c/code\u003e to \u003ccode\u003e--dist\u003c/code\u003e flag in the package build script\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/date-fns/date-fns/commit/b6ad5acc5ab0b40777a2695ec074c2ffcd982763\"\u003e\u003ccode\u003eb6ad5ac\u003c/code\u003e\u003c/a\u003e Add flags to control package build script\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/date-fns/date-fns/commit/424a783de1fd974bcdbe907c9c5eb5154e9db29f\"\u003e\u003ccode\u003e424a783\u003c/code\u003e\u003c/a\u003e Fix docs release after moving to monorepo setup\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/date-fns/date-fns/commit/f95bcf18b53e6832b2c575c24c98654a24f52699\"\u003e\u003ccode\u003ef95bcf1\u003c/code\u003e\u003c/a\u003e (docs): Add missing \u003ccode\u003etsx\u003c/code\u003e dependency\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/date-fns/date-fns/compare/v4.1.0...v4.4.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `fast-xml-parser` from 5.8.0 to 5.11.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/releases\"\u003efast-xml-parser's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.11.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump actions/checkout from 7.0.0 to 7.0.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/858\"\u003eNaturalIntelligence/fast-xml-parser#858\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump zizmorcore/zizmor-action from 0.5.7 to 0.6.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/856\"\u003eNaturalIntelligence/fast-xml-parser#856\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/setup-node from 6.4.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/854\"\u003eNaturalIntelligence/fast-xml-parser#854\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: fix two 404 documentation links by \u003ca href=\"https://github.com/rajanpanth\"\u003e\u003ccode\u003e@​rajanpanth\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/862\"\u003eNaturalIntelligence/fast-xml-parser#862\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rajanpanth\"\u003e\u003ccode\u003e@​rajanpanth\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/862\"\u003eNaturalIntelligence/fast-xml-parser#862\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.11.0...v5.11.1\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.11.0...v5.11.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.11.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eadd support for endIndex in node metadata (5.x edition) by \u003ca href=\"https://github.com/Wain-PC\"\u003e\u003ccode\u003e@​Wain-PC\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/850\"\u003eNaturalIntelligence/fast-xml-parser#850\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: don't crash on a closing tag with no matching opening tag by \u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/861\"\u003eNaturalIntelligence/fast-xml-parser#861\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Wain-PC\"\u003e\u003ccode\u003e@​Wain-PC\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/850\"\u003eNaturalIntelligence/fast-xml-parser#850\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hdimer\"\u003e\u003ccode\u003e@​hdimer\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/861\"\u003eNaturalIntelligence/fast-xml-parser#861\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.10.1...v5.11.0\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.10.1...v5.11.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.10.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.10.0...v5.10.1\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.10.0...v5.10.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.10.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump actions/checkout from 6.0.3 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/849\"\u003eNaturalIntelligence/fast-xml-parser#849\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump zizmorcore/zizmor-action from 0.5.6 to 0.5.7 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/848\"\u003eNaturalIntelligence/fast-xml-parser#848\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.3...v5.10.0\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.3...v5.10.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.9.3\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHarden GitHub Actions workflows by \u003ca href=\"https://github.com/martincostello\"\u003e\u003ccode\u003e@​martincostello\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/841\"\u003eNaturalIntelligence/fast-xml-parser#841\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eGitHub Actions workflow fixes by \u003ca href=\"https://github.com/martincostello\"\u003e\u003ccode\u003e@​martincostello\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/844\"\u003eNaturalIntelligence/fast-xml-parser#844\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/martincostello\"\u003e\u003ccode\u003e@​martincostello\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/pull/841\"\u003eNaturalIntelligence/fast-xml-parser#841\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.2...v5.9.3\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.2...v5.9.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.9.2\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.1...v5.9.2\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.1...v5.9.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.9.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.0...v5.9.1\"\u003ehttps://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.9.0...v5.9.1\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md\"\u003efast-xml-parser's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003eNote: If you find missing information about particular minor version, that version must have been changed without any functional change in this library.\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003cp\u003eNote: Due to some last quick changes on v4, detail of v4.5.3 \u0026amp; v4.5.4 are not updated here. v4.5.4x is the last tag of v4 in github repository. I'm extremely sorry for the confusion\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003e5.11.1 / 2026-08-27\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efix: validator; Replace regex with a single-pass scanner for attribute tokens, eliminating quadratic behavior on long whitespace runs.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e5.11.0 / 2026-08-16\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efeat: support for endIndex in node metadata (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/850\"\u003e#850\u003c/a\u003e) [By \u003ca href=\"https://github.com/Wain-PC\"\u003ePavel Dranichnikov\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003efix: don't crash on a closing tag with no matching opening tag (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/861\"\u003e#861\u003c/a\u003e) [By \u003ca href=\"https://github.com/hdimer\"\u003eHaïm Dimer\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003efix: DOCTYPE to read SYSTEM/PUBLIC\u003c/li\u003e\n\u003cli\u003edeps: strnum v2.4.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e5.10.1 / 2026-07-17\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efix: multiple DOCTYPE declarations.\u003c/li\u003e\n\u003cli\u003edeps: \u003ccode\u003e@nodable/entities\u003c/code\u003e for treeshaking\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e5.10.0 / 2026-07-11\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eupgrade:\n\u003cul\u003e\n\u003cli\u003exml-naming v0.3.0: cache support\u003c/li\u003e\n\u003cli\u003ePEM v1.6.2: sibling bug fix\u003c/li\u003e\n\u003cli\u003eis-unsafe v2.0.0: tree shaking\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e*\u003cem\u003e5.9.3 / 2026-06-19\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eupdate strnum\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e*\u003cem\u003e5.9.2 / 2026-06-17\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003edummy release to test changes in github action\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e*\u003cem\u003e5.9.1 / 2026-06-17\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003edummy release to test release from github action\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e*\u003cem\u003e5.9.0 / 2026-06-15\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eupdate strnum to 2.3.0\n\u003cul\u003e\n\u003cli\u003eyou can set hex, binary, enotation, infinity, unicode\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003evalidate unsafe HTML or XML data in doctype entities unsing 'is-unsafe' library.\nUser can override rules by overriding EntityDecoder.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e*\u003cem\u003e5.8.0 / 2026-05-12\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eintegrate xml-naming to validate DOCTYPE entity name and notation name (using qname becaue of backward compatibility)\n\u003cul\u003e\n\u003cli\u003eThis will consider xml-version as well. '1.0' is default\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eupdate strnum to 2.3.0\n\u003cul\u003e\n\u003cli\u003eYou can set octal and binary parsing which is bydeault off\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eupdate fast-xml-builder to 1.2.0\n\u003cul\u003e\n\u003cli\u003ecan sanitize tag names if found invalid\u003c/li\u003e\n\u003cli\u003efix format output\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e5.7.3 / 2006-05-05\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efix: alwaysCreateTextNode should create text node when attributes are present for self closing node\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/3617550adfb280989f482d662b7e9ece55a32a34\"\u003e\u003ccode\u003e3617550\u003c/code\u003e\u003c/a\u003e 5.11.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/6021128c3251d4c1456d2c6cd8442a5005a1f39a\"\u003e\u003ccode\u003e6021128\u003c/code\u003e\u003c/a\u003e update for release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/6ddcb65f240005988457af6af6dd68fa0947acf5\"\u003e\u003ccode\u003e6ddcb65\u003c/code\u003e\u003c/a\u003e remove regex from validator\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/7d608151078d47040841e9804d490feb5c07dfe7\"\u003e\u003ccode\u003e7d60815\u003c/code\u003e\u003c/a\u003e docs: fix two 404 documentation links (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/862\"\u003e#862\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/4e3857b3ab78f0b8e37e70e5cd08f2bc1ac726a8\"\u003e\u003ccode\u003e4e3857b\u003c/code\u003e\u003c/a\u003e Bump actions/setup-node from 6.4.0 to 7.0.0 (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/854\"\u003e#854\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/fcc62fb8f6f620c95dd1c9ab7aac3061f0905592\"\u003e\u003ccode\u003efcc62fb\u003c/code\u003e\u003c/a\u003e Bump zizmorcore/zizmor-action from 0.5.7 to 0.6.1 (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/856\"\u003e#856\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/23a9019d1e481ad3d1b9aef5266194f4e366f14e\"\u003e\u003ccode\u003e23a9019\u003c/code\u003e\u003c/a\u003e Bump actions/checkout from 7.0.0 to 7.0.1 (\u003ca href=\"https://redirect.github.com/NaturalIntelligence/fast-xml-parser/issues/858\"\u003e#858\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/f3c69ae2a9a1a1df4e4be9ca954ddcdf6563d16a\"\u003e\u003ccode\u003ef3c69ae\u003c/code\u003e\u003c/a\u003e 5.11.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/fdbd072e23fcc6ea1a4779aecdd7196620f432d7\"\u003e\u003ccode\u003efdbd072\u003c/code\u003e\u003c/a\u003e update for release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/commit/c5fcb5b1f9178ed07a078b08f53382ee49268ba3\"\u003e\u003ccode\u003ec5fcb5b\u003c/code\u003e\u003c/a\u003e update lock files\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.8.0...v5.11.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eMaintainer changes\u003c/summary\u003e\n\u003cp\u003eThis version was pushed to npm by \u003ca href=\"https://www.npmjs.com/~GitHub%20Actions\"\u003eGitHub Actions\u003c/a\u003e, a new releaser for fast-xml-parser since your current version.\u003c/p\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `next` from 16.2.6 to 16.3.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/vercel/next.js/releases\"\u003enext's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev16.3.4\u003c/h2\u003e\n\u003cp\u003eFollow-up release to \u003ca href=\"https://github.com/vercel/next.js/releases/tag/v16.3.3\"\u003ev16.3.3\u003c/a\u003e re-enabling AVIF Image Optimization (\u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97949\"\u003e#97949\u003c/a\u003e).\u003c/p\u003e\n\u003cp\u003eThe following bug fixes have been backported. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003etestmode: Fix infinite recursion in testmode passthrough fetch (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97691\"\u003e#97691\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix build error when aliasing typescript to \u003ccode\u003e@​typescript/typescript6\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97997\"\u003e#97997\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix unset crossOrigin in Turbopack manifests (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97930\"\u003e#97930\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.3\u003c/h2\u003e\n\u003cp\u003eThis release contains security fixes for the following advisories:\u003c/p\u003e\n\u003cp\u003eCritical:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36\"\u003eUnauthenticated Remote Code Execution on windows-hosted servers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4\"\u003eUnauthenticated Remote Code Execution in Image Optimization API when AVIF files are used\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev16.3.2\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\nThis release is backporting bug fixes. It does \u003cstrong\u003enot\u003c/strong\u003e include all pending features/changes on canary.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCore Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e[backport] Scope app-entry export validation to files inside the app directory (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97357\"\u003e#97357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[backport] Fix catch-all index page being served for every other slug (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97416\"\u003e#97416\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: don't trace embedded WASM loader helpers (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97353\"\u003e#97353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97463\"\u003e#97463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3] Turbopack: retain conditions when replacing resolve request keys (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97453\"\u003e#97453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Fix Turbopack worker chunk loading with asset prefix (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97419\"\u003e#97419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97603\"\u003e#97603\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCredits\u003c/h3\u003e\n\u003cp\u003eHuge thanks to \u003ca href=\"https://github.com/lubieowoce\"\u003e\u003ccode\u003e@​lubieowoce\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/timneutkens\"\u003e\u003ccode\u003e@​timneutkens\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e for helping!\u003c/p\u003e\n\u003ch2\u003ev16.3.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[16.x] Turbopack: don't strip async-module runtime from shared runtime chunks by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96653\"\u003evercel/next.js#96653\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] [turbopack] Add \u003ccode\u003eturbopack_ecmascript\u003c/code\u003e and \u003ccode\u003eturbopack_wasm\u003c/code\u003e's embeded FS to \u003ccode\u003einternal_assets_conditions\u003c/code\u003e by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96655\"\u003evercel/next.js#96655\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] [turbopack] Collapse nested promises in the analyzer by \u003ca href=\"https://github.com/sampoder\"\u003e\u003ccode\u003e@​sampoder\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96675\"\u003evercel/next.js#96675\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.x] fix(next/image): preserve image response after optimization by \u003ca href=\"https://github.com/styfle\"\u003e\u003ccode\u003e@​styfle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96733\"\u003evercel/next.js#96733\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[16.3.x] Default deploy e2e tests to the repo next version by \u003ca href=\"https://github.com/eps1lon\"\u003e\u003ccode\u003e@​eps1lon\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96900\"\u003evercel/next.js#96900\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Bump \u003ccode\u003e@​swc/helpers\u003c/code\u003e by \u003ca href=\"https://github.com/mischnic\"\u003e\u003ccode\u003e@​mischnic\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/96885\"\u003evercel/next.js#96885\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [turbopack] Raise registration calls in hoisted modules to the top by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97308\"\u003evercel/next.js#97308\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Fix missing styled-jsx styles in Pages Router SSR on adapter builds by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97302\"\u003evercel/next.js#97302\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] [turbopack] Fix HMR for dynamic imports evaluated from layouts by \u003ca href=\"https://github.com/lukesandberg\"\u003e\u003ccode\u003e@​lukesandberg\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97317\"\u003evercel/next.js#97317\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[backport] Restore the live \u003ccode\u003eheaders()\u003c/code\u003e view of the incoming request by \u003ca href=\"https://github.com/unstubbable\"\u003e\u003ccode\u003e@​unstubbable\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/vercel/next.js/pull/97311\"\u003evercel/next.js#97311\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/299180d3315c7ebd7b199d2b1a265b5986c5fc7d\"\u003e\u003ccode\u003e299180d\u003c/code\u003e\u003c/a\u003e v16.3.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/12e173dd73ed6c39622281c7282c8364234ad94f\"\u003e\u003ccode\u003e12e173d\u003c/code\u003e\u003c/a\u003e [16.3.x] Re-enable AVIF image optimization and require sharp 0.35.4 (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97949\"\u003e#97949\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/5d9022edd29e32d7061bc56cf713ffe8769cd900\"\u003e\u003ccode\u003e5d9022e\u003c/code\u003e\u003c/a\u003e [backport] Fix unset crossOrigin in Turbopack manifests (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97930\"\u003e#97930\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/d8f45609fa74e56f24958d45d93d3426511f957f\"\u003e\u003ccode\u003ed8f4560\u003c/code\u003e\u003c/a\u003e [16.3.x] Fix build error when aliasing typescript to \u003ccode\u003e@​typescript/typescript6\u003c/code\u003e ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/656aebfb58ce194fb603f18942dad6e94d15b21c\"\u003e\u003ccode\u003e656aebf\u003c/code\u003e\u003c/a\u003e [16.3] testmode: Fix infinite recursion in testmode passthrough fetch (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97691\"\u003e#97691\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/f37c1d656553b8950330b6683ab242a5c610135c\"\u003e\u003ccode\u003ef37c1d6\u003c/code\u003e\u003c/a\u003e [16.3.x] ci: remove pull_request_stats workflow (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97975\"\u003e#97975\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/a9a1cb7859f178f830ad3773b303130c21b19586\"\u003e\u003ccode\u003ea9a1cb7\u003c/code\u003e\u003c/a\u003e v16.3.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/968b9fcb26bdeb8e0a861a9df05361474666d51b\"\u003e\u003ccode\u003e968b9fc\u003c/code\u003e\u003c/a\u003e [16.3.x] Fix ISR misses with backslashes in segments when deployed on Windows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/3a15b4ac6ac8e70b1a9b18ecc18e8434462899b3\"\u003e\u003ccode\u003e3a15b4a\u003c/code\u003e\u003c/a\u003e [16.3.x] [next/image]: disable avif image optimization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vercel/next.js/commit/7378b51ea05a6745d3676bee00cb4c63aac3dd16\"\u003e\u003ccode\u003e7378b51\u003c/code\u003e\u003c/a\u003e Backport/docs fixes 16.3 (\u003ca href=\"https://redirect.github.com/vercel/next.js/issues/97649\"\u003e#97649\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/vercel/next.js/compare/v16.2.6...v16.3.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `next-intl` from 4.12.0 to 4.14.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/amannn/next-intl/releases\"\u003enext-intl's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.14.2\u003c/h2\u003e\n\u003ch2\u003e4.14.2 (2026-09-01)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAllow \u003ccode\u003e@eloqnt/*\u003c/code\u003e patches to resolve by moving to \u003ccode\u003e^0.1.0\u003c/code\u003e ranges (\u003ca href=\"https://redirect.github.com/amannn/next-intl/issues/2398\"\u003e#2398\u003c/a\u003e) (\u003ca href=\"https://github.com/amannn/next-intl/commit/4d18120bf3c14ad2beda836659c6854a03c4f368\"\u003e4d18120\u003c/a\u003e) – by \u003ca href=\"https://github.com/amannn\"\u003e\u003ccode\u003e@​amannn\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.14.1\u003c/h2\u003e\n\u003ch2\u003e4.14.1 (2026-08-28)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUnbreak \u003ccode\u003eexperimental.messages\u003c/code\u003e without a \u003ccode\u003emessages.sourceLocale\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/amannn/next-intl/issues/2395\"\u003e#2395\u003c/a\u003e) (\u003ca href=\"https://github.com/amannn/next-intl/commit/67fca941e943e8fa273fbc8a7f362354f6804d35\"\u003e67fca94\u003c/a\u003e) – by \u003ca href=\"https://github.com/amannn\"\u003e\u003ccode\u003e@​amannn\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.14.0\u003c/h2\u003e\n\u003ch2\u003e4.14.0 (2026-08-27)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003euseExtracted\u003c/code\u003e improvements (\u003ca href=\"https://redirect.github.com/amannn/next-intl/issues/2346\"\u003e#2346\u003c/a\u003e) (\u003ca href=\"https://github.com/amannn/next-intl/commit/4ccf3b80a143c192ccfbe576817e2e7fe98aec24\"\u003e4ccf3b8\u003c/a\u003e) – by \u003ca href=\"https://github.com/amannn\"\u003e\u003ccode\u003e@​amannn\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e⚠️ If you're using \u003ccode\u003euseExtracted\u003c/code\u003e and the \u003ccode\u003epo\u003c/code\u003e format, this requires an update to your messages.\u003c/p\u003e\n\u003cp\u003ePlease see \u003ca href=\"https://redirect.github.com/amannn/next-intl/pull/2393\"\u003eamannn/next-intl#2393\u003c/a\u003e for details and an upgrade prompt.\u003c/p\u003e\n\u003ch2\u003ev4.13.7\u003c/h2\u003e\n\u003ch2\u003e4.13.7 (2026-08-17)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePin \u003ccode\u003e@swc/core\u003c/code\u003e to a range that is compatible with the extractor plugin (\u003ca href=\"https://redirect.github.com/amannn/next-intl/issues/2389\"\u003e#2389\u003c/a\u003e) (\u003ca href=\"https://github.com/amannn/next-intl/commit/a37d8aaec094620cc1f8c345023db833eeebbbed\"\u003ea37d8aa\u003c/a\u003e) – by \u003ca href=\"https://github.com/amannn\"\u003e\u003ccode\u003e@​amannn\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.13.6\u003c/h2\u003e\n\u003ch2\u003e4.13.6 (2026-08-10)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDeprecate \u003ccode\u003erequestLocale\u003c/code\u003e param of \u003ccode\u003egetRequestConfig\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/amannn/next-intl/issues/2380\"\u003e#2380\u003c/a\u003e) (\u003ca href=\"https://github.com/amannn/next-intl/commit/ae770af84983fdd2ed8f9a3d9acca5a7275b2b0f\"\u003eae770af\u003c/a\u003e) – by \u003ca href=\"https://github.com/amannn\"\u003e\u003ccode\u003e@​amannn\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSee the \u003ca href=\"https://next-intl.dev/blog/nextjs-root-params\"\u003eblog post on \u003ccode\u003enext/root-params\u003c/code\u003e\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003ev4.13.5\u003c/h2\u003e\n\u003ch2\u003e4.13.5 (2026-08-04)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDeprecate \u003ccode\u003esetRequestLocale\u003c/code\u003e and add \u003ca href=\"https://next-intl.dev/blog/nextjs-root-params\"\u003eblog post on \u003ccode\u003enext/root-params\u003c/code\u003e\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/amannn/next-intl/issues/1632\"\u003e#1632\u003c/a\u003e) – by \u003ca href=\"https://github.com/amannn\"\u003e\u003ccode\u003e@​amannn\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.13.4\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/amannn/next-intl/blob/main/CHANGELOG.md\"\u003enext-intl's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.14.2 (2026-09-01)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAllow \u003ccode\u003e@eloqnt/*\u003c/code\u003e patches to resolve by moving to \u003ccode\u003e^0.1.0\u003c/code\u003e ranges (\u003ca href=\"https://redirect.github.com/amannn/next-intl/issues/2398\"\u003e#2398\u003c/a\u003e) (\u003ca href=\"https://github.com/amannn/next-intl/commit/4d18120bf3c14ad2beda836659c6854a03c4f368\"\u003e4d18120\u003c/a\u003e) – by \u003ca href=\"https://github.com/amannn\"\u003e\u003ccode\u003e@​amannn\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.14.1 (2026-08-28)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUnbreak \u003ccode\u003eexperimental.messages\u003c/code\u003e without a \u003ccode\u003emessages.sourceLocale\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/amannn/next-intl/issues/2395\"\u003e#2395\u003c/a\u003e) (\u003ca href=\"https://github.com/amannn/next-intl/commit/67fca941e943e8fa273fbc8a7f362354f6804d35\"\u003e67fca94\u003c/a\u003e) – by \u003ca href=\"https://github.com/amannn\"\u003e\u003ccode\u003e@​amannn\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.14.0 (2026-08-27)\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003euseExtracted\u003c/code\u003e improvements (\u003ca href=\"https://redirect.github.com/amannn/next-intl/issues/2346\"\u003e#2346\u003c/a\u003e) (\u003ca href=\"https://github.com/amannn/next-intl/commit/4ccf3b80a143c192ccfbe576817e2e7fe98aec24\"\u003e4ccf3b8\u003c/a\u003e) – by \u003ca href=\"https://github.com/amannn\"\u003e\u003ccode\u003e@​amannn\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.13.7 (2026-08-17)\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePin \u003ccode\u003e@swc/core\u003c/code\u003e to a range that is compatible with the extractor plugin (\u003ca href=\"ht...\n\n_Description has been truncated_\n\n\u003c!-- This is an auto-generated description by cubic. --\u003e\n---\n## Summary by cubic\nBumps 20 production dependencies, most notably `next` with critical security fixes, plus `react`, `@sentry/nextjs`, and `zod`.\n\n**Key Notes**\n- `next` 16.3.4 includes critical unauthenticated RCE security fixes for Windows-hosted servers and the Image Optimization API.\n- `@fortedigital/nextjs-cache-handler` 3.3.0 is required for `next` 16.3.0+ to fix the `/ _tree` prefetch regression when restoring cache from disk.\n- `@sentry/nextjs` 10.73.0 deprecates importing `withSentryConfig` from `@sentry/nextjs`; migrate the import to `@sentry/nextjs/config`.\n- `zod` jumps from 3.24.3 to 3.25.76; verify schema validation still works as expected.\n\n\u003csup\u003eWritten for commit d7c6abc6e7bd9b17c2ab21fa745b0d06c6810eb1. Summary will update on new commits.\u003c/sup\u003e\n\n\u003ca href=\"https://cubic.dev/pr/Esdeveniments/esdeveniments-frontend/pull/473?utm_source=github\" target=\"_blank\" rel=\"noopener noreferrer\" data-no-image-dialog=\"true\"\u003e\u003cpicture\u003e\u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-light.svg\"\u003e\u003cimg alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003c/picture\u003e\u003c/a\u003e\n\n\u003c!-- End of auto-generated description by cubic. --\u003e\n\n","html_url":"https://github.com/Esdeveniments/esdeveniments-frontend/pull/473","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Esdeveniments%2Fesdeveniments-frontend/issues/473","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/473/packages"}}]}